Third Party Risk Management Lead
Listed on 2026-01-07
-
IT/Tech
-
Finance & Banking
THIRD PARTY RISK MANAGEMENT LEAD
WHAT IS THE OPPORTUNITY?
Third Party Risk Management (TPRM) Lead is responsible for providing Enterprise wide third party risk management services, including taking a lead role to define, implement, and maintain a risk framework, operating model, policies, procedures, governance and oversight programs for all lines of business and subsidiaries. CNB established the TPRM program as a second line function, enabling CNB to manage third party risk effectively and efficiently, relative to its size and complexity.
The lead is responsible for ensuring the program meets regulatory guidance, aligns with CNB's parent company, and incorporate changes as necessary.
WHAT WILL YOU DO?
- In partnership with the TPRM Program Manager, develop a successful implementation plan consisting of:
- Assist with the development and execution of an TPRM risk framework, policies and procedures
- Direct assessments on key controls and overall compliance with the TPRM program, including the timeliness, completeness, and accuracy of risk assessments.
- Provide risk-consulting serves to first line third party risk managers for complex arrangements.
- Develop risk analysis and reporting, including risk metrics, for dissemination to both first line of defense (technology) leadership, risk management committees, CNB's parent holding company, and CNB's regulators.
- Streamline processes for risk identification and assessment, control assessment, testing and issue management.
- Lead continuous improvement activities and initiatives for TPRM, working with stakeholders, subject matter experts, and analysis of exception reports to define issues, determine root cause, and determine appropriate changes.
- Identify and assess requirements for CNB's GRC system to increase automation, and process effectiveness and efficiency.
- Responsible for reviewing SSAE 18 reports for CNB's third parties and evaluate for completeness, appropriateness, and assess impact to CNB on findings and exceptions to support CNB's Sarbanes Oxley, FDICA, and SOC programs.
- Manage coordination of assignment of resources based on demand and capacity, and required subject matter expertise, including augmenting internal staff with external resources as necessary.
- Ensure appropriate escalate of issues to first line and senior management as required.
WHAT DO YOU NEED TO SUCCEED?
Required Qualifications*
- Minimum of 7 years of third party risk management, assurance and / or oversight or relevant supplier or third party audit or compliance experience
- Minimum of 4 years of experience in risk and controls for information technology and cybersecurity, appropriately scoping assessments, providing credible challenges, and performing assurance testing.
- Minimum of 4 years working with a GRC system, incorporating continuous improvement for the system and process.
Additional Qualifications
- Comprehensive knowledge of third party and information technology risk management processes and methodologies
- Experience using third party risk management /Governance, Risk and Compliance (GRC) systems
- Experience assessing contracts, including master service agreements, statements of work, and license agreements.
- Experience assessing cloud servicing arrangements
- Knowledge of and experience in designing and operating governance, frameworks and processes to comply with vendor management / third party risk management related regulatory requirements, guidance and oversight (OCC , Fed SR 13-19 or other relevant third party risk management / vendor management regulation applicable to the financial services industry)
- Currently hold or quickly obtain industry recognized third party risk management or vendor management certification
- Excellent oral and written communication skills; experience performing both detailed and executive-level documentation
- Advanced knowledge of Microsoft Office tools; specifically, Excel, PowerPoint and Share Point
- Experience with reporting platforms such as Tableau, SQL scripts, and Microsoft SSRS desirable
WHAT'S IN IT FOR YOU?
Compensation
Starting base salary: $99,000 - $176,000 per year. Exact compensation may vary based on skills, experience, and location. This job is eligible for…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).