Jobs · Utah

Director- Third Party Risk and Business Continuity

Mountain America Credit Union · Sandy, UT · Yesterday
Full-time

About the role

The Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union's Enterprise and Operational Risk function, reporting to the Vice President of Enterprise and Operational Risk.

Responsibilities

  • Lead the design, implementation, testing, and continued maturity of the enterprise business continuity and operational resilience program, including business impact analyses, risk assessments, operational scenario analysis, tabletop exercises, and crisis management simulations.
  • Partner with IT and Information Security to align business continuity planning with technology recovery capabilities, disaster recovery dependencies, and business response requirements.
  • Coordinate crisis response governance, escalation protocols, decision rights, leadership communications, situational risk reporting, lessons learned, and prioritized remediation for significant operational events.
  • Monitor emerging threats and trends, including cyber, technology, supply chain, regulatory, physical security, climate, and geopolitical events; maintain related program documentation, reporting, and remediation visibility for operational continuity risks.
  • Direct the continued maturity of a scalable third-party risk management program aligned to the credit union’s vendor ecosystem, operational complexity, internal governance standards, and regulatory expectations.
  • Oversee the third-party risk lifecycle, including due diligence, risk assessments, contract risk reviews, ongoing monitoring, issue escalation, remediation tracking, exit planning, and senior-level credible challenge of evidence-based risk conclusions.
  • Partner with business units, Vendor Relationship Owners, Subject Matter Experts, Legal, Procurement, Information Security, Compliance, and other stakeholders to identify, assess, mitigate, monitor, and document third-party risks, contract provisions, controls, and risk mitigation strategies.
  • Monitor third-party performance, control effectiveness, key risk indicators, critical vendor exposure, concentration risk, fourth-party risk, and emerging risk themes, escalating issues when risk exposure exceeds defined thresholds.
  • Drive the TPRM program maturity roadmap, including process improvements, automation, data quality, GRC optimization, regulatory alignment, and adoption of sound industry practices.
  • Provide executive, committee, and Board-level reporting and recommendations on third-party risk exposure, trends, issues, concentrations, emerging risks, program maturity, remediation priorities, and related governance documentation.

Requirements

  • Bachelor’s degree in finance, risk management, business administration, economics, or related field required; advanced degree preferred.
  • Minimum of 8 years of experience in enterprise risk, operational risk, business continuity, third-party risk management, contract management, or related risk disciplines.
  • Minimum of 3 years of experience leading teams, business processes, or cross-functional initiatives with notable risk and complexity.
  • Experience developing or maturing risk, resilience, third-party, or contract management programs in a regulated financial institution preferred.
  • Understanding of ERM frameworks, operational resilience expectations, third-party risk lifecycle practices, contract risk considerations, and regulatory expectations for financial institutions.
  • Understanding of SOC 2, SSAE-18, financial statements, business impact analysis, recovery planning, operational scenario analysis, and crisis response practices.

Qualifications

  • Preferred certifications: CTPRP, ORCE, CRCMP, or similar risk-related credentials.

Skills

  • Strategic thinking with strong analytical, problem-solving, and risk data interpretation capabilities, including the ability to aggregate, interpret, and visualize complex risk information.
  • Demonstrated ability to apply credible challenge, respectfully question assumptions, escalate risks, and influence outcomes using facts, regulatory knowledge, and clear communication.
  • Excellent written and verbal communication skills, with the ability to synthesize risk information, prepare executive-ready materials, and collaborate effectively with cross-functional teams, including Compliance, Internal Audit, and senior leadership.
  • Familiarity with GRC platforms and risk analytics tools, such as Tableau, Power BI, or similar.

Leadership and Organization Development

  • Demonstrates ownership and accountability in delivering high-quality risk governance and reporting outcomes.
  • Fosters a culture of collaboration, transparency, and continuous improvement within the Risk function.
  • Provides mentorship and guidance to junior team members and peers, supporting professional development and knowledge sharing.
  • Aligns team activities and deliverables with operational risk strategy and organizational goals.
  • Effectively manages change and adapts to evolving regulatory, strategic, and operational priorities.
  • Builds strong cross-functional relationships to influence outcomes and promote a unified risk culture.
  • Contributes to succession planning by developing documentation, tools, and processes that support long-term team capability and resilience.

Pay

Competitive compensation package, including base salary and benefits.

Schedule

Full Time; this is a hybrid schedule with some weekly in-office expectation, based on business need.

Similar jobs

Third-Party Risk Manager

Sumitomo Mitsui Trust Bank Limited New York BranchNew York, NY· 4 wk ago
Management$50/hrapply on workforcenow.adp.com