Third Party Risk Control Manager - Vice President
Listed on 2026-08-17
-
Finance & Banking
-
IT/Tech
Join our Commercial & Investment Bank (CIB) Controls team, where you'll help shape how we identify, govern, and manage risk from a complex third-party ecosystem. You'll play a key role in transforming risk assessments into actionable insights that protect our clients, data, and operations.
As a Third Party Risk & Controls Insights Vice President in CIB Controls, you will drive the insights agenda across the third-party lifecycle. You'll turn assessment and monitoring outputs into meaningful narratives, themes, and recommendations. Your work will support risk acceptance and remediation prioritization, helping us maintain a strong risk posture and safeguard our reputation. You'll collaborate with diverse teams and use your judgment and communication skills to ensure risk conclusions are clear and actionable.
Job ResponsibilitiesCompile and analyze third-party risk information, summarizing key impacts for business and Finance & Business Management (F&BM) partners.
Produce executive governance updates and materials for CIB controls and third-party risk forums.
Support third-party lifecycle reporting by following established standards for risk statements, residual risk language, materiality thresholds, and issue categorization.
Perform quality checks on risk assessments and monitoring outputs; flag gaps and coordinate updates with partner teams.
Identify recurring themes and emerging risks across the vendor portfolio and elevate items that meet defined thresholds.
Create residual risk summaries and remediation options to support risk acceptance and prioritization discussions.
Review and provide input on business cases for new or expanded vendor engagements, identifying opportunities to leverage existing vendors.
Maintain and refresh tracking for key third-party risk and control metrics (KRIs/KPIs), thresholds, and trend summaries; contribute content for dashboards and routine reporting.
Track third-party control issues through testing, monitoring, and closure, ensuring documentation and evidence meet standards.
Coordinate with Controls, Technology, Procurement, Legal, Compliance, Operational Risk, and business stakeholders to collect inputs and support a consistent view of third-party risk posture.
Demonstrated expertise in control management within financial services, focusing on compliance and operational risk mitigation.
Hands‑on experience supporting third‑party risk activities across the vendor lifecycle, with ability to document clear risk conclusions and support decision materials.
Ability to summarize assessment and monitoring results into executive‑ready updates, including key themes, emerging risks, and recommended next steps.
Ability to translate technical risk topics into business‑friendly language, including concise risk statements and practical mitigations.
Strong analytical and technical literacy, including interpreting process flows, supporting KRI/KPI definition and tracking, and communicating insights.
Effective stakeholder management skills, partnering across controls, procurement, legal, compliance, technology, and business teams.
Strong written and verbal communication skills, including drafting governance materials and briefing leaders with clear messaging.
Experience supporting third‑party risk portfolio reporting and governance routines, including maintaining taxonomies and producing management information.
Ability to partner with analytics/automation teams to improve monitoring and insights for third‑party risk and controls.
Working knowledge of operational resilience concepts, including business service mapping, recovery expectations, and dependency analysis.
Strong collaboration and influencing skills to reinforce standards, raise credible challenge, and support alignment on remediation priorities.
Understanding of the CIB business context to support third‑party risk discussions and align recommendations with client, regulatory, and operational expectations.
To be eligible for this role, you must be authorized to work in the United States. We do not offer any type of employment‑based…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).