EU remote
Senior Third-Party Risk Specialist
About this role
About Mistral Mistral provides full-stack AI solutions: from frontier models to developer tools, applications, and compute. We partner with enterprises tackling the hardest problems—across high-stakes industries like finance, manufacturing, defense, healthcare, and the public sector—co-creating customized AI systems that they can run on their terms. We are a dynamic, collaborative team passionate about AI and its potential to transform society.
Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between Europe, North America, Asia and the Middle East. We are creative, low-ego and team-spirited. Role summary As a Senior Third-Party Risk Specialist , you will be responsible for identifying, assessing, and mitigating risks associated with third parties (vendors, partners, subcontractors, etc.) at Mistral.
You will play a pivotal role in safeguarding our assets, data, and reputation by ensuring that our third-party relationships adhere to the highest standards of security, compliance, and resilience. You will work closely with Legal, Procurement, Security, and Operational teams to embed a proactive third-party risk management approach into our business processes. What you will do Develop and manage the third-party risk management program : Design, implement, and maintain a structured framework for identifying, assessing, and monitoring risks associated with third parties (vendors, partners, service providers, etc.).
Conduct third-party assessments and audits : Perform due diligence, compliance assessments, security audits, and contractual reviews to ensure third parties meet our requirements and regulatory obligations (e.g., GDPR, NIS2, DORA). Collaborate with internal teams : Work with Procurement, Legal, Security, and Operations teams to integrate third-party risk requirements into vendor selection, negotiation, and monitoring processes.
Manage incidents and non-compliance : Identify and address gaps or incidents related to third parties, coordinating corrective actions and ensuring follow-up until resolution. Raise awareness and train stakeholders : Develop and deliver training and guidance to educate internal teams on third-party risk issues and their responsibilities. Maintain robust documentation : Document assessments, decisions, and actions related to third-party risk management, ensuring traceability for internal and external audits.