Internal Audit Subject Matter Expert (Third-Party Risk Management and Vendor Assurance)
Darbo aprašymas:
We are looking for an Internal Audit Subject Matter Expert (Third-Party Risk Management and Vendor Assurance) to join our Internal Audit team. You will provide independent assurance over the Group's end-to-end management of third parties, outsourcing arrangements, ICT service providers and providers supporting critical or important functions.
You will work across business, technology, procurement, risk, legal and compliance topics while maintaining Internal Audit independence. The role requires confidence in challenging both internal stakeholders and evidence received from external providers. You will assess the effectiveness of third-party governance and assurance without taking ownership of vendor selection, contracting or ongoing supplier management.
Every day, you’ll be #closer and:
- Lead and deliver complex internal audits covering third-party risk management, outsourcing and vendor assurance.
- Assess governance and controls across the full third-party lifecycle, including initiation, due diligence, risk assessment, contracting, onboarding, monitoring, renewal and exit.
- Evaluate compliance with DORA and applicable EBA expectations for outsourcing and ICT third-party risk management.
- Review the identification, classification and oversight of providers supporting critical or important functions.
- Assess provider-level controls and assurance evidence, including contractual protections, service performance, security, resilience, concentration risk and exit arrangements.
- Contribute specialist expertise to the Internal Audit methodology development, risk assessment, audit planning, thematic reviews and follow-up of significant third-party risk findings.
Reikalavimai:
- At least 7 years of relevant experience in internal audit, TPRM, outsourcing, technology risk, operational resilience, procurement risk, vendor assurance, compliance or supervision.
- Practical experience across the third-party lifecycle, from initiation and due diligence through contracting, monitoring, renewal and exit.
- Working knowledge of DORA and applicable EBA outsourcing and ICT risk-management expectations.
- Experience evaluating critical or important service providers.
- Ability to assess both governance frameworks and provider-level controls.
- Excellent English communication skills – written and verbal.
Privalumai
- University degree in business, technology, risk, law, finance or a related discipline.
- CIA, CISA, CRISC, CISSP, CTPRP or equivalent qualification.
- Experience with cloud, financial technology or core banking service providers.
- Experience with SOC 1, SOC 2, ISAE 3402, ISO 27001 or comparable assurance frameworks.
- Experience supporting or responding to supervisory inspections.
Įmonė siūlo:
- The green light for your ideas. Your suggestions will be heard - we value independence, curiosity and initiative.
- A manager who helps you grow. You’ll get clear direction and support, while having plenty of freedom to act, learn and develop.
- An organisation that is changing. Joining Artea means more than just a new name - it means new ideas, perspectives and opportunities to shape our culture from within.
- Achievements rooted in Lithuania. We’re especially proud to be a Lithuanian bank. We believe our country and our people are unique, and we do everything we can every day to help them realise their potential.
- A personal benefits package. Health insurance, a pension savings programme, additional days off, flexible working hours, modern infrastructure - and that’s far from the complete list of benefits!
- Performance bonuses. Our employees can earn bonuses based on the results of the bank, their team and their own performance.