×
Register Here to Apply for Jobs or Post Jobs. X

Third Party Due Diligence – Monitoring

Job in New York, New York County, New York, 10261, USA
Listing for: Mizuho Financial Group Inc.
Full Time position
Listed on 2026-08-06
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 103000 - 135000 USD Yearly USD 103000.00 135000.00 YEAR
Job Description & How to Apply Below
Location: New York

Overview

The Mizuho Americas Enterprise Controls Department (ECD) is a 1st Line of Defense risk and control function that delivers enterprise control services across Third Party Services, Business Continuity Planning, and Business Risk and Control Services. The ECD serves as the single point of accountability for enterprise control services within Mizuho Americas and falls under the Mizuho Americas Enterprise Services Division.

The Third Party Risk Management (TPRM) Unit is a 1

LoD risk function that provides white‑glove service to business lines and corporate functions, shepherding them through the Third Party Risk Management lifecycle, conducting due diligence directly with third parties, and providing oversight of the TPRM function.

The Third Party Due Diligence (TPDD) Team performs risk‑based evaluations of third‑party service providers across Information Security, Information Technology, Business Continuity Planning, and adjacent domains, and is responsible for ongoing monitoring of third and fourth parties across Cybersecurity, Financial, Compliance, Operational, Geographic, and ESG events using tools including Bit Sight, Supply Wisdom, and NCFTA intelligence feeds.

Role Summary

The Assistant Vice President of TPDD – Ongoing Monitoring is accountable for the end‑to‑end execution and quality of TPDD's continuous monitoring program for Critical, High, Moderate, Low, and Nominal third and fourth parties. The AVP owns timely identification, triage, escalation, and resolution of monitoring alerts; partners with Third Party Managers (TPMs), Business Approvers, SMEs, Legal, and Compliance to drive remediation; and ensures all monitoring activity is documented in an audit‑ready, regulator‑defensible manner consistent with the MUSO TPRM Policy, Standard, and Procedure.

Responsibilities
  • Own end‑to‑end ongoing monitoring of third and fourth party risks across cybersecurity (Bit Sight) and enterprise risk domains (Supply Wisdom); review weekly alerts, conduct trend and impact analysis, ransomware and vulnerability assessments, fourth‑party incident reporting, and monthly third‑party and location license and data reconciliation with heat‑map analysis.
  • Perform composite risk‑rating evaluations across Macro‑Economic, Financial, Geo‑Political, Infrastructure, Business, Legal, Security & Compliance, Scalability, and ESG domains; coordinate with Cyber Defense to review NCFTA alerts and identify, assess, and respond to emerging high‑risk cyber threats affecting Mizuho third parties.
  • Serve as the primary point of contact for TPMs, Business Approvers, Legal, Compliance, CISO/Cyber Defense, Data Loss Prevention (DLP), and SME teams to assess the business impact of third and fourth party risk events; document material incidents in Archer; identify and analyze risk issues; drive and track remediation to closure; and Escalate Critical or High‑risk issues to TPDD leadership and TPRM Management.
  • Support monthly concentration and portfolio risk monitoring across third parties (e.g., engagement volume, service locations, contingent workers, and sole‑provider exposure); contribute to quarterly reporting; maintain accurate Bit Sight portfolios and Supply Wisdom license assignments to ensure all concentration‑risk third parties are continuously monitored as Critical under appropriate license types.
  • Lead and perform due diligence reviews, reassessments, and significant change evaluations in accordance with TPRM policies and procedures; assess inherent risk and control effectiveness across key domains; identify and document due diligence gaps; recommend remediation, risk acceptance, or escalation actions; coordinate Certificate of Insurance validation; and document any gaps.
  • Review Archer KRI reports to identify threshold breaches and overdue activities; assess risk impact; drive remediation with stakeholders; ensure risk acceptances are recorded and tracked; support internal and external audits, regulatory exams, and Federal Banking Agency Report of Examination (ROE) reviews through timely documentation; maintain audit‑ready records, including QA reviews of 10% of Moderate/Low and 100% of Critical/High assessments.
  • Contribute to…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary