JobRaahGet matched free

Jobs

Third Party Risk Management Lead

cboe · London, United Kingdom · On-site

Posted Oct 8, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Job Description Cboe Europe is seeking an experienced Outsourcing and Third Party Risk Management Lead to take first-line ownership of how Cboe Europe identifies, assesses, and manages the risks arising from its use of outsourcing, ICT, and other third party providers, as part of a global Infrastructure team You will own the third party risk lifecycle in the first line of defence – inventory and classification, risk-based due diligence, contracting, ongoing monitoring, exit planning, and regulatory reporting – and lead implementation of the ICT third party requirements of the Digital Operational Resilience Act (DORA) and the FCA’s new operational incident and material third party reporting regime under PS26/2. Working with technology, operations, procurement, legal, compliance, and audit teams, you will strengthen the resilience of trading services used by hundreds of financial services firms across the UK and EU. The role takes an AI-first approach, automating due diligence, register maintenance, evidence gathering, monitoring, and regulatory reporting. The successful candidate will establish and enhance governance frameworks, risk oversight processes, and control environments relating to outsourced, delegated, and third party arrangements. They will also support senior management in meeting their responsibilities while driving operational excellence, regulatory compliance, and continuous improvement across the organisation. Location: London, UK In this role, you will be responsible for: Owning the third party and ICT third party inventory, including: • Cboe Europe’s outsourcing register and DORA register of information, ensuring ICT services supporting critical or important functions are correctly identified, classified, and recorded. • The register of material third party arrangements required under FCA PS26/2 and FG26/4, kept submission-ready for return to the FCA. • Mapping of third parties to the business services, functions, processes, assets, and controls they support, including impact tolerances, RTOs, and RPOs. • Subcontracting and nth-party chains for ICT services supporting critical or important functions, with concentration, substitutability, and geographic risk recorded. • Automated data quality, reconciliation, and evidence-gathering controls so register data stays accurate, complete, and examination-ready. • Strengthening our First Line of Defence (1LOD) through robust policies, procedures, controls, and a culture of continuous improvement Running first-line third party risk assessment, due diligence, and contracting by: • Acting as the first point of contact for business owners on third party or outsourcing matters, guiding them through onboarding, including: risk assessment, contract review, and approval. • Running proportionate, risk-based due diligence across information security, resilience, data protection, financial crime, financial soundness, and concentration risk, coordinating with subject matter experts…