SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Third-Party Risk Specialist

Mistral - Paris, Île-de-France, France - In-office

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Mistral is a full-stack AI company providing frontier models, developer tools, applications, and compute infrastructure. They partner with enterprises across finance, manufacturing, defense, healthcare, and the public sector to co-create customized AI systems. As Senior Third-Party Risk Specialist, you will design, implement, and manage Mistral's third-party risk management program. This role is central to safeguarding the company's assets, data, and reputation by ensuring vendors, partners, and subcontractors meet the highest standards of security, compliance, and operational resilience. Key responsibilities include: - Developing and maintaining a structured third-party risk management framework - Conducting due diligence, compliance assessments, security audits, and contractual reviews against standards like ISO 27001, SOC 2, and regulations including GDPR, NIS2, and DORA - Collaborating with Procurement, Legal, Security, and Operations teams to embed risk requirements into vendor selection and monitoring - Managing incidents and non-compliance, coordinating corrective actions - Delivering training and awareness programs to internal stakeholders - Maintaining comprehensive documentation for internal and external audits - Monitoring regulatory and standards evolution, proposing framework adjustments - Contributing to continuous improvement of risk management tools and methodologies - Performing contract redlining and negotiation to align terms with security and compliance requirements You bring 7+ years of experience in third-party risk management, cybersecurity compliance, or information security governance. You have practical knowledge of ISO 27001, SOC 2, NIST SP 800-53, and familiarity with NIS2, DORA, GDPR, and the Cyber Resilience Act. You are proficient in risk assessment methodologies such as EBIOS RM and ISO 27005. Strong organizational skills, attention to detail, analytical thinking, and cross-functional collaboration are essential. Professional English proficiency required; French is a plus.

Similar roles