Jobs › Counsel - Third Party Risk Management
Counsel - Third Party Risk Management
Job at a glance
- Category
- GRC
- Work arrangement
- On-site
- Location
- London, UK
- Posted
- Aug 31, 2026
Free. One click to unsubscribe. We never share your address.
Everest Re Group is hiring a Counsel - Third Party Risk Management in London, UK. This is a GRC job in the governance, risk, and compliance field. Review the full details below and apply directly with Everest Re Group.
Title: Counsel – Third Party Risk Management (TPRM) Company: Everest Advisors (Uk) Ltd. Job Category: Law Job Description: About Everest: Everest is a global leader in risk management rooted in a rich 50+ year heritage of enabling businesses to survive and thrive and economies to function and flourish. We are underwriters of risk growth progress and opportunity. We are a global team focused on disciplined capital allocation and long-term value creation for all stakeholders who care deeply about our impact on communities and the wider world. About the Role: This role will support the Legal function in managing legal risk arising from the organisation's engagement of vendors consultants and outsourced service providers. The role combines contract review and negotiation with regulatory horizon scanning and ownership of legal template and playbook management ensuring the business contracts on appropriately risk-calibrated terms and remains ahead of regulatory developments affecting third party risk. Key Responsibilities Contract Review and Negotiation Review draft and negotiate vendor consultant outsourcing TOBAS and non-disclosure agreements applying the organisation's risk appetite and standard positions Apply proportionate legal review calibrated to contract risk tier (e.g. material outsourcing vs. low-risk vendor arrangements) including under applicable outsourcing/operational resilience regulatory frameworks (e.g. PRA/FCA outsourcing rules EIOPA/Solvency II outsourcing requirements DORA where relevant) Liaise with procurement information security data protection and business stakeholders to ensure contracts reflect operational security and regulatory requirements Identify and escalate contracts raising material legal regulatory or reputational risk Support due diligence and contractual remediation for existing third-party arrangements Regulatory Horizon Scanning Monitor and summarise regulatory developments relevant to third party risk management outsourcing and operational resilience (UK and Ireland) including PRA FCA Central Bank of Ireland EIOPA and Lloyd's requirements Produce concise business-facing briefings on incoming regulatory change and its practical impact on contracting and vendor oversight practices Track implementation deadlines and support the legal team in embedding regulatory changes into templates playbooks and processes Template and Playbook Management Own and maintain the suite of TPRM-related legal templates (vendor agreements
Full responsibilities and requirements are on Everest Re Group's application page.
Apply for this job →Location and market context
This job is based in London, UK on-site. Local candidates benefit from being close to Everest Re Group's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About third-party risk jobs
Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Jobs like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.
How to position yourself for this third-party risk job
Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Everest Re Group would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
More GRC jobs: All GRC jobs · Search by category & location