Associate, Third-Party Risk Management
Job in
Clearwater, Pinellas County, Florida, 34623, USA
Listed on 2026-07-18
Listing for:
Amerilife Group, LLC
Full Time
position Listed on 2026-07-18
Job specializations:
-
IT/Tech
Job Description & How to Apply Below
Job Summary
Reporting to the Director of Third‑Party Risk Management, the Third‑Party Risk Management Associate supports the execution and continuous improvement of the organization’s Third‑Party Risk Management (TPRM) program. This role is responsible for conducting vendor risk assessments, managing day‑to‑day third‑party risk processes, maintaining thorough documentation, and monitoring key risk indicators (KRIs). The Associate partners closely with cross‑functional teams and leverages technology to help ensure that all vendors and third‑party service providers meet the organization’s security, compliance, operational and risk management requirements.
Key Responsibilities- Vendor Risk Assessments: Conduct risk assessments and due diligence for new and existing third‑party vendors. Collect and analyze vendor responses (such as security questionnaires, audit reports, SOC reports), identify potential risk areas, recommend appropriate mitigation strategies, and summarize findings for management review.
- Third‑Party Lifecycle Support: Help coordinate the end‑to‑end third‑party lifecycle, including vendor onboarding, ongoing performance management and risk monitoring, contract reviews, issue management, and offboarding. Ensure all required risk checks and approvals are completed and documented at appropriate lifecycle stages.
- Documentation & Reporting: Maintain accurate TPRM documentation and records, including risk assessment results, remediation plans, and risk acceptance decisions. Prepare regular reports and dashboards on third‑party risk metrics and Key Risk Indicators (KRIs) for review by senior risk management.
- Tool Management: Use approved technology to support automation of TPRM workflows. This includes managing vendor inventories, issuing and tracking risk assessment questionnaires, monitoring vendor compliance status, and generating risk reports.
- Risk Monitoring & Issue Tracking: Continuously monitor third‑party risk profiles and compliance status. Track open risk issues or remediation plans in the TPRM system and follow up with vendors or internal stakeholders to ensure timely completion of mitigation actions. Escalate significant findings or delays to the Director, as needed.
- Stakeholder
Collaboration:
Work closely with internal teams such as IT Security, Compliance, Legal, Procurement, and business units to gather necessary information for vendor evaluations. Support communication with stakeholders and vendors to clarify requirements, obtain documentation, and resolve any identified risk or compliance issues. - Program Administration: Assist in the development, maintenance, and enhancement of TPRM policies, procedures, standards and templates. Support audits, regulatory examinations, and compliance reviews related to third‑party risk management activities. Contribute to ongoing process improvements and program maturity initiatives.
- Bachelor’s degree in Business, Information Systems, Cybersecurity, or related field.
- 3‑5 years of experience in risk management, vendor management, compliance, or information security, with exposure to third‑party risk management or vendor due diligence processes.
- Familiarity with key compliance and security frameworks and regulations (CPRA, HIPAA, SOX, ISO 27001, NIST) and an understanding of how they apply to third‑party/vendor risk.
- Professional
Certifications:
Certified Third‑Party Risk Professional (CTPRP), Certified Risk and Compliance Management Professional (CRCMP) or Certified Regulatory Vendor Program Manager (CRVPM). - Experience using vendor risk management technology to manage risk assessments, workflows, and reporting. Proficient with standard business software (Excel, PowerPoint, Word) for data analysis and presentation.
- Strong analytical and problem‑solving skills with keen attention to detail. Ability to interpret risk assessment data, identify trends or red flags in vendor responses, and assist in developing mitigation steps.
- Excellent written and verbal communication skills. Capable of preparing clear reports and effectively communicating findings and requirements to internal stakeholders and vendors.
- Demonstrated ability to work…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×