Supplier Risk Specialist

Pandora Group
Warsaw
Workplace: HybridFull timeFunction: Legal, Risk & ComplianceExperience: 2+ yearsEducation: bachelorsSkills: ["Communication","Negotiation","Stakeholder management","Organization","Detail-oriented"]

Assess, monitor, and manage information security risks from Pandora’s third-party vendors. Conduct vendor security risk assessments, provide recommendations based on risk posture, and maintain audit-ready records. Lead vendor risk management initiatives by educating vendors, tracking and reporting risk trends and remediation, and enhancing VRM methodologies and tools while staying current on emerging threats, vulnerabilities, and regulatory changes.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Pandora Group
Pandora Group
1 day ago

Supplier Risk Specialist

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 9 hours agoStatus: Live

Job Summary

Assess, monitor, and manage information security risks from Pandora’s third-party vendors. Conduct vendor security risk assessments, provide recommendations based on risk posture, and maintain audit-ready records. Lead vendor risk management initiatives by educating vendors, tracking and reporting risk trends and remediation, and enhancing VRM methodologies and tools while staying current on emerging threats, vulnerabilities, and regulatory changes.
Location: Warsaw
Workplace: Hybrid
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Perform information security risk assessments for third-party vendors, identifying threats, vulnerabilities, control and compliance gaps.
  • •Recommend vendor selection based on risk analysis and security posture, and continuously monitor vendor security posture through reassessments and audits.
  • •Maintain detailed vendor assessment records and ensure audit readiness.
  • •Educate vendors on security best practices and track, analyze, and report vendor security risks, trends, and remediation efforts.
  • •Develop and enhance vendor risk management (VRM) methodologies, processes, and tools while staying current on emerging threats and regulatory changes.

Pay and Benefits

Perks:Medical CareDental CareLife InsurancePension PlansHome OfficeMedical CardParking

Key Requirements

  • •2+ years of experience in vendor risk management, information security, or a related area.
  • •Bachelor’s degree in cyber security, information technology, risk management, or a related field.
  • •Professional English and Polish proficiency (verbal and written).
  • •Knowledge of cyber security frameworks, risk assessment methodologies, and/or regulatory requirements (beneficial).
  • •Experience with vendor risk management tools such as BitSight, OneTrust, CyberVadis, or CyberGRX (plus).
Experience:2+ years
Education:Bachelor's in cyber security, information technology, risk management, or a related field
Skills:CommunicationNegotiationStakeholder managementOrganizationDetail-oriented
Certifications:CISSPCISMCRISCCTPRP
Languages:EnglishPolish
Tech Stack:BitSightOneTrustCyberVadisCyberGRX

Company Brief

Pandora Group
The Pandora Group (Pandora A/S) is the world's largest jewelry brand, headquartered in Copenhagen, Denmark.
Industry: Luxury Goods
Headquarters: Copenhagen, Denmark
Website