Third Party Risk Management Specialist

Lunar Group A/S is the Danish parent company of Lunar’s active Nordic digital-banking and financial-services businesses.

Series D0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/25/2026

Aarhus, Denmark
About Lunar Group A/S

Lunar Group A/S is headquartered in Aarhus and is the parent company of Lunar Bank A/S, Lunar Block A/S, Moonrise Banking Services A/S, and Lunar Journey AB. Its group businesses provide regulated digital banking, business banking, Nordic banking-services/payment connectivity, and crypto-asset trading across Denmark, Sweden, and Norway.

View jobs by Lunar Group A/S

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will own third-party risk across the vendor lifecycle. You will classify and assess vendor risk, define contract requirements, monitor vendor performance and incidents, and maintain the DORA register of information and exit plans. You will report to management and oversight bodies while improving third-party risk processes.

Requirements

  • 3–5 years of experience in vendor management, contract management, outsourcing, procurement, or third-party risk, with substantial ICT or technology vendor experience
  • Background in law, business, contract management, or vendor management, or equivalent practical experience
  • Working knowledge of DORA ICT third-party risk requirements and EBA outsourcing guidelines, or experience in another regulated sector with willingness to learn them
  • Ability to identify contractual gaps and manage vendors before and after contract signature
  • Technical understanding of cloud, SaaS, subcontracting, data location, and assurance reports
  • Strong writing skills
  • Fluency in English
  • Danish or another Scandinavian language is a strong plus

Responsibilities

  • Run risk-based vendor classification, due diligence, and risk assessments
  • Define contract requirements, including DORA Article 30 terms, SLAs, audit rights, and exit rights
  • Track vendor performance, ICT incidents, assurance reports, security test results, and changed risks
  • Own the DORA register of information and ICT concentration-risk input
  • Ensure critical or important ICT services have workable exit strategies
  • Report on third-party risk and improve the risk-management process

Benefits

  • State-of-the-art computer equipment, monitor, mouse, and keyboard
  • Pension
  • Health insurance
  • Enhanced parental leave