Kering Third Party Risk Management Officer
- Location
- ParisÎle-de-FranceFrance
- Employment
- Full-Time
- Seniority
- Mid-Level
- Department
- Legal & Compliance
- Industry
- Luxury Automotive
- Posted
- Aug 28, 2026
About Kering
Kering is a global luxury group renowned for nurturing some of the world’s most influential Houses in fashion, leather goods, jewelry, and eyewear, including Gucci, Saint Laurent, Bottega Veneta, Balenciaga, and Boucheron. As an employer, Kering offers a distinctive environment where creative excellence, entrepreneurial spirit, and long-term sustainability converge. The Group empowers its talents to shape the future of luxury through innovation, craftsmanship, and responsible business practices. With an international culture grounded in diversity, inclusion, and shared ambition, Kering provides meaningful career opportunities for professionals seeking to contribute to exceptional brands while advancing a more sustainable and imaginative luxury industry.
Kering seeks a Third-Party Risk Management Officer in Paris to lead vendor security assessments, risk monitoring, and compliance across its luxury group operations.
Role & Responsibilities
- Conduct cybersecurity due diligence and risk assessments on third-party suppliers and service providers prior to engagement, prioritizing vendors associated with critical enterprise assets
- Analyze vendor assessment results and perform risk classification of assets according to DICP (Availability, Integrity, Confidentiality, Proof) requirements
- Execute dedicated risk analyses on the Group's critical assets and their associated suppliers in collaboration with relevant business and technical stakeholders
- Define, monitor, and oversee remediation and action plans with suppliers through to closure
- Review and contribute to the integration of security clauses into supplier contracts in partnership with Procurement and Legal teams
- Implement continuous third-party risk monitoring and trigger supplementary due diligence activities in response to alerts or security incidents
- Collaborate cross-functionally with business domains, ISP teams, CERT/CTI, and GRC functions to integrate third-party security considerations into project planning and requirement definitions
- Develop and track key performance indicators (KPIs) related to vendor assessment, monitoring, and remediation for executive reporting
- Contribute to the continuous improvement of cybersecurity processes and tools, particularly across the Prevent and Comply pillars, including assessment methodologies and security frameworks
Qualifications
- Master's degree from a business school, engineering school, or in information systems
- Certification in Third-Party Risk Management or information security such as CTPRP, CTPRA, CISSP, CISA, CISM, or CRISC
- 4–5 years of professional experience in Third-Party Risk Management, information security, audit, or GRC functions
- Demonstrated expertise in conducting vendor assessments and due diligence reviews, including questionnaire administration, evidence reviews, and SOC 2/ISAE 3402 report analysis
- Proficiency with risk scoring tools, continuous risk monitoring platforms, and relevant security frameworks (ISO 27001, NIST, PCI DSS, SIG questionnaire)
- Proven experience managing action and remediation plans with external suppliers and reviewing contractual security requirements
- Advanced capability in asset risk classification methodologies and risk analysis (criticality, impact, likelihood assessment)
- Competence in developing, analyzing, and interpreting KPIs for governance and reporting purposes
- Strong command of DICP principles and their application to third-party risk governance
- Ability to interpret technical security documentation including audit reports, penetration test results, and SOC 2 attestations
- Understanding of Cloud security risks and digital supply chain security considerations
Skills
Experience
Candidates should have 4–5 years of professional experience in Third-Party Risk Management, information security, or audit and GRC environments. Significant hands-on experience is required in executing vendor security assessments, performing due diligence reviews, analyzing technical security evidence (questionnaires, audit reports, SOC 2/ISAE 3402 documents), managing vendor remediation efforts, and engaging with Procurement and Legal functions on contract security provisions. Familiarity with risk scoring methodologies, continuous monitoring practices, and a working knowledge of Cloud and digital supply chain security challenges are essential.
Education
Master's degree (Bac+5) from a business school, engineering school, or program in information systems. Relevant professional certifications in Third-Party Risk Management or information security (CTPRP, CTPRA, CISSP, CISA, CISM, CRISC) are strongly preferred and may substitute for or complement formal educational requirements.
Workplace
The successful candidate will be located in Paris, Île-de-France, France.
Culture
Kering fosters a dynamic, purpose-driven culture where creativity, entrepreneurship, and collaboration support the distinct identities of its luxury Houses. As an employer, the Group places strong emphasis on sustainability, diversity, and talent development, encouraging people to innovate responsibly while contributing to the future of modern luxury.
About Cerulean
Cerulean is the definitive career portal for the global luxury industry. We match exceptional professionals with exclusive opportunities at the world's most prestigious brands. From haute couture and fine watchmaking to prestige beauty, hospitality, and boutique retail, Cerulean centralises luxury employment to help you find the career for which you were destined.
Frequently Asked Questions
The luxury industry is characterised by a diverse and nuanced nomenclature. Esteemed houses frequently employ proprietary terminology, and even within a single organisation like Kering, titles may vary across global markets to reflect local conventions. To ensure absolute clarity, Cerulean assigns a standardised, industry-coherent canonical title to every listing. However, it is worth noting that this role is functionally synonymous with «TPRM Officer», «Third-Party Risk Analyst», «Vendor Risk Management Specialist», «Third-Party Security Assessment Manager», and other variations. Our sophisticated search architecture anticipates these variations, ensuring that inquiries using related terms will seamlessly yield the exact roles you desire.