Jobs · Finance · New York

GRC Vendor Risk Analyst

Community Bank, N.A. · Syracuse, NY · 1 wk ago
FinanceFull-time

About the role

Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.

Responsibilities

  • Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
  • Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
  • Partner with stakeholders across various business lines to gather responses and supporting evidence.
  • Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
  • Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
  • Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
  • Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
  • Support identity and access management governance, review, and related coordination activities as assigned.
  • Track remediation items, follow-up actions, and review outcomes to support timely resolution.
  • Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
  • Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
  • Perform other Information Security, third-party risk, and related governance duties as assigned by management.
  • Provide assistance to branches and the bank to help achieve annual goals, including traveling to other branches in the area to provide support as needed.

Requirements

  • Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered.
  • 4+ years of experience in Information Security; OR 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
  • Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
  • Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
  • All applicants must be 18 years of age or older.

Skills

  • Strong analytical and communication skills.
  • Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires.
  • Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines.
  • Ability to work independently and collaboratively to identify, document, and communicate security risks.

Benefits

  • 11 paid holidays
  • Paid vacation
  • Medical, Vision & Dental insurance
  • 401K with generous match
  • Pension
  • Tuition Reimbursement
  • Banking discounts

Pay

Minimum USD $28.85/Yr. Maximum USD $47.54/Yr.

Schedule

40 hours per week

Physical Requirements

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • While performing the duties of this job, the employee may be required to stand, walk, sit, use hands to finger, handle, or feel, reach with hands or arms, and speak and hear.
  • The employee may occasionally be required to lift and or move up to 25 pounds.
  • Specific vision abilities required by this job include close vision, and the ability to focus.

Similar jobs

Vendor Risk Analyst

Hilltop HoldingsDallas, TX· 1 mo ago
Financeapply on ejlu.fa.us2.oraclecloud.com

GRC Analyst

LaddersUnited States· 3 wk ago
RemoteBusiness Development$134k–$202k/yrapply on theladders.com

GRC Analyst

University of OklahomaNorman, OK· 3 wk ago
Business Development$46k–$60k/yrapply on jobs.ou.edu

GRC Analyst

UplightBoulder, CO· 1 mo ago
RemoteBusiness Developmentapply on jobs.jobvite.com

GRC Analyst

BuseyLeawood, KS· 1 mo ago
Analyst$68k–$95k/yrapply on careers.busey.com