Third Party Risk Management Specialist
Banking hasn't changed much in decades. We're changing that. One product at a time.
Lunar is a Nordic challenger bank building the future of financial life with AI at the core. Our engineers, designers, and product people work on problems that actually matter. Making money simpler, smarter, and more rewarding for over a million registered users across the Nordics.
Fully licensed and founded in 2015, with offices in Copenhagen, Aarhus and Stockholm.
We move fast, we build with purpose, and we're just getting started.
As our new Third Party Risk Management Specialist you'll join Legal & First Line Risk in Aarhus, reporting to our Director of Legal & First Line Risk. You'll own third party risk across the vendor lifecycle, working closely with procurement, with ICT third party risk under DORA at the centre of the job. Most of what Lunar buys is technology, so DORA's rules are the rulebook for most of this role, with the EBA guidelines covering the rest.
Procurement owns sourcing, price and negotiation. You own the risk and sit alongside procurement rather than inside it, so the risk view stays independent of the deal: assessing what the risk is and what the contract needs to say before we sign, then tracking whether the vendor delivers, whether the risk has changed, and whether we could exit if we had to.
What will you do?
Assess before we sign. Run risk-based classification, due diligence and risk assessments as part of procurement, with a sharp eye for ICT services that support critical or important functions, including cloud, subcontracting chains and where our data sits.
Set the contract requirements. Turn the risk picture into contract requirements together with Legal, including DORA Article 30 terms, SLAs, audit rights and exit rights, and support the business in negotiations.
Follow up after we sign. Track performance against SLAs, run vendor reviews with business owners, follow ICT incidents, assurance reports such as ISAE 3402 and SOC 2, and security test results, and reassess when something changes.
Keep the register and exit plans right. Own the DORA register of information and our ICT concentration risk input, and make sure ICT services supporting critical or important functions have exit strategies that would actually work.
Be the go-to person for third party risk. Report to management, answer to 2nd line, internal audit and the Danish FSA, and improve the process while you run it.
What are we looking for in you?
3-5 years of experience in vendor management, contract management, outsourcing, procurement or third party risk, with a large share of it on ICT or technology vendors, ideally in a bank, payment institution or other regulated company.
A background in law, business, contract management or vendor management, for example cand.merc.jur. or a similar combination, or equivalent practical experience.
A working knowledge of DORA's ICT third party risk requirements and the EBA outsourcing guidelines, or solid experience from another regulated sector and the drive to master them quickly.
You read a contract and spot what's missing, you've managed vendors after the signature as well as before it, and you have enough technical understanding to talk to engineers about cloud, SaaS, subcontracting and data location, including judging what an assurance report does and does not cover.
A strong writer who's comfortable challenging vendors, business owners and senior stakeholders. Fluent in English; Danish or another Scandinavian language is a strong plus.
Benefits and perks
4 days in the office. We're a team that builds together, thinks together, and moves together. Showing up is part of how we work.
State of the art equipment. The newest computer, monitor, mouse, and keyboard. We want you to do your best work without anything slowing you down.
Pension, health insurance, and enhanced parental leave. From your financial future to your family moments. We've got you covered.
Are you ready to join the journey? Apply now and let's find out more!
While you hold on tight for us to get back to you, curious to see what we’re up to? Follow us on LinkedIn for business announcements and releases 📢, check out our Instagram for an inside scoop on what it’s like to work here .
Depending on the regulations in the country where you will be employed, we will ask to see or obtain information about your criminal record. Please note that our employment is conditional upon you not being registered in RKI (Ribers Kredit Information).
We welcome applications from candidates of all backgrounds. If you need any adjustments during the recruitment process, please let us know
- Department
- Legal
- Location
- Aarhus, Denmark
Aarhus, Denmark
About Lunar
Lunar is a fully licensed digital bank founded in 2015, with offices in Copenhagen, Aarhus and Stockholm. We're 400+ people building cloud-native, real-time financial services for millions of users across Denmark, Sweden, and Norway.
Our mission is to pioneer financial empowerment. A world where money works for you, enabling you to live your best life, free from worry. That's what gets us out of bed every day.
We build on cloud-native infrastructure with modern technologies across our full stack. We hire across Tech, Design, Product, Finance, Marketing, Compliance, and Customer Excellence. No legacy systems. No old habits. Just a better way to build banking across the Nordics.
It's time to make your move.