Jobs › Paris › Senior Third-Party Risk Specialist
Senior Third-Party Risk Specialist
Mistral AI is hiring for the job of Senior Third-Party Risk Specialist, Paris (On-site). This is a Risk job in the governance, risk, and compliance field. Review the full details below and apply directly with Mistral AI.
About Mistral Mistral provides full-stack AI solutions: from frontier models to developer tools, applications, and compute. We partner with enterprises tackling the hardest problems, across high-stakes industries like finance, manufacturing, defense, healthcare, and the public sector, co-creating customized AI systems that they can run on their terms. We are a dynamic, collaborative team passionate about AI and its potential to transform society. Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between Europe, North America, Asia and the Middle East. We are creative, low-ego and team-spirited. Role summary As a Senior Third-Party Risk Specialist , you will be responsible for identifying, assessing, and mitigating risks associated with third parties (vendors, partners, subcontractors, etc.) at Mistral. You will play a pivotal role in safeguarding our assets, data, and reputation by ensuring that our third-party relationships adhere to the highest standards of security, compliance, and resilience. You will work closely with Legal, Procurement, Security, and Operational teams to embed a proactive third-party risk management approach into our business processes. What you will do Develop and manage the third-party risk management program : Design, implement, and maintain a structured framework for identifying, assessing, and monitoring risks associated with third parties (vendors, partners, service providers, etc.). Conduct third-party assessments and audits : Perform due diligence, compliance assessments, security audits, and contractual reviews to ensure third parties meet our requirements and regulatory obligations (e.g., GDPR, NIS2, DORA). Collaborate with internal teams : Work with Procurement, Legal, Security, and Operations teams to integrate third-party risk requirements into vendor selection, negotiation, and monitoring processes. Manage incidents and non-compliance : Identify and address gaps or incidents related to third parties, coordinating corrective actions and ensuring follow-up until resolution. Raise awareness and train stakeholders : Develop and deliver training and guidance to educate internal teams on third-party risk issues and their responsibilities. Maintain robust documentation : Document assessments, decisions, and actions related to third-party risk management, ensuring traceability for internal and external audits. Monitor regulatory and standards evolution : Stay updated on changes in regulations (e.g., NIS2, Cyber Resilience Act, GDPR) and standards (e.g., ISO 27001, SOC 2, ISO 27036) impacting third-party risk management, and propose adjustments to the internal framework. Optimize tools and processes : Contribute to the continuous improvement of tools (e.g., third-party risk management platforms) and methodologies to enhance the program's effectiveness. Align with broader resilience strategy : Ensure the third-party risk management program supports the company's overall cybersecurity and compliance objectives. Contract redlining and negotiation skills : Ability to review, edit, and negotiate contractual terms to align with security and compliance requirements. About you 7+ years in third-party risk management, cybersecurity compliance, information security governance, or a related field. Experience supporting cybersecurity compliance programs, certification processes, or external audits. Practical knowledge of standards and frameworks such as ISO 27001, SOC 2, NIST SP 800-53, or regulations like NIS2, DORA, GDPR. Proficiency in risk assessment methodologies (e.g., EBIOS RM, ISO 27005). Familiarity with cybersecurity regulations such as NIS2, the Cyber Resilience Act, LPM, or DORA. Strong organizational skills and attention to detail, with the ability to manage documentation and coordinate multiple stakeholders. Excellent written and verbal communication skills. Strong analytical and problem-solving abilities. Ability to work collaboratively across technical, legal, commercial, and operational teams. Professional proficiency in English; French proficiency is a plus. What We Offer We offer a comprehensive benefits package designed to support your well-being, growth, and work-life balance. Benefits vary by country and may include healthcare coverage, parental leave, retirement plans, relocation support, wellness programs, meal and transportation allowances, and other location-specific perks. For the most up-to-date details on benefits available in your location, please refer to our Benefits page . Privacy Policy Your privacy matters to us. You can learn more about how we handle your personal data in our Applicant Privacy Policy .
Location and market context
This job is based in Paris on-site. Local candidates benefit from being close to Mistral AI's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.
About risk management jobs
Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.
How to position yourself for this risk management job
Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how Mistral AI would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.
Similar GRC jobs
- Alternance - Data Analyst Credit Risk (F/H) · Younited · Paris
- Third-Party Security Risk Management (TPRM) Lead · Workday · .VA.Reston
- Principal Consultant (Senior Manager) - Non-Financial / Operational Risk · Capco · London, UK
- Financial Risk Principal Consultant (Senior Manager) · Capco · London, UK
- Management Consultant - Financial Risk · Capco · London, UK
- Management Consultant - Non-Financial / Operational Risk · Capco · Edinburgh, UK
- Counterintelligence & Security Risk Analyst · Anduril Industries · Costa Mesa, California
- Head of Financial Risk Management - Bitnomial · Kraken · United States
More jobs at Mistral AI
- Security Compliance, GRC Engineer · Mistral AI · Paris
- Privacy Legal Counsel · Mistral AI · Paris
- Director of Internal Control · Mistral AI · Paris
- Security Compliance Specialist · Mistral AI · Paris
More GRC jobs in Paris
- Data Privacy and Security Counsel (US Federal) · Workday · .VA.Reston
- Subject Matter Expert, GTM GRC - Revenue · Vanta · . · Remote
- Senior Compliance Manager · Backbase · Amsterdam
- Head of AML & CTF (PCF-52), Payward Europe Solutions Ltd · Kraken · Ireland
- Vice President, BSA/AML Operations – Cases · Pathward · Remote
- Information Security Controls Manager - Cloud & AI Governance · N26 · Berlin
Hiring for Risk?
Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
Post a job Pricing from $99 · About GRC Careers · Hiring toolkit
Want to be next in a job like this?
Jobs like Senior Third-Party Risk Specialist in Paris open regularly. Be first to know, privately. No current employer ever sees you looking.
Employer, or see something wrong with this posting? Report this posting and we will review it promptly.