Senior Event Analyst, Third Party Risk Management (TPRM)
Ally · Charlotte, NC · 4 wk ago
Finance$85k–$150k/yrFull-time
About the role
The Third Party Risk Management (TPRM) Senior Event Analyst is part of the TPRM Resilience and Response team and plays a key role in the intake, interpretation, analysis, and coordination of third-party cybersecurity and operational events.
Responsibilities
- Support end-to-end management of third-party cyber events, including intake, escalation, impact analysis, vendor engagement, and closure activities.
- Participate in cybersecurity incident response activities as a risk and coordination partner.
- Help coordinate post-event reviews to identify issues, gaps, trends, and opportunities for improvement.
- Support remediation planning and follow-up activities for identified issues and process improvements.
- Provide occasional on-call support, as needed, for significant incident response activities.
- Build and maintain strong working relationships with internal stakeholders to support event coordination and follow-up activities.
- Partner with cybersecurity, risk, and business teams to support effective and well-coordinated event response.
- Support external engagement routines and stakeholder reporting tied to event management activities.
- Serve as a second-line challenge partner and support issue identification, escalation, and follow-up where appropriate.
- Document, standardize, and enhance processes within established organizational frameworks and procedures.
- Aid in audit and regulatory exam preparation, as needed.
- Support the design, coordination, and execution of training exercises for third-party response activities.
- Help build and enhance reporting and analytical capabilities that support data-informed decisions.
- Provide broad support to the Third Party Risk Management team and contribute risk and cybersecurity perspective where needed.
- Assist with additional Third Party Resilience and Response activities as priorities evolve.
- Develop and deliver regular and ad hoc reporting to support team priorities and management insights.
- Establish and maintain metrics that support program objectives and ongoing performance monitoring.
- Support executive reporting, event analytics, and presentation materials.
Qualifications
- Minimum of 3+ years of experience in cybersecurity, information security, incident response, or a related field.
- High school Diploma or GED equivalent.
- Bachelor's Degree in Cybersecurity, Information Systems, or a related field preferred.
- Working knowledge of cybersecurity controls, incident response, or related technology control environments.
- Security+, CISSP, CISM, CISA, or similar certifications are a plus, but not required.
- Background in incident management, or cyber incident management, related program support is beneficial.
- Experience managing third-party and supply chain cyber incidents; strong problem-solving and decision-making skills.
- Familiarity with frameworks such as NIST, FFIEC, or other relevant industry guidance is preferred.
- Experience with tools such as ServiceNow, Excel, PowerPoint, Power BI, or similar reporting platforms is helpful.
- Familiarity with third-party risk and cybersecurity laws, regulations, or oversight expectations is preferred.
- Ability to self-prioritize tasks, work collaboratively, and support multiple assignments in a fast-paced environment.
- Strong organizational skills with the ability to manage competing priorities in a fast-paced and high pressure environment.
- Personal integrity with the ability to handle confidential and sensitive matters professionally and with the appropriate level of judgement and maturity.
Skills
- Experience in third-party risk, cybersecurity, operational risk, incident response, threat intelligence, information security, or related control functions.
- Familiarity with financial services regulatory expectations, cybersecurity frameworks, incident response practices, and risk analysis methods.
- Strong note-taking, writing, analysis, critical thinking, and presentation skills.
Benefits
Ally offers a comprehensive benefits package including:
- Time Away: 20 paid time off days in addition to 11 paid holidays and 8 hours of volunteer time off yearly.
- Planning for the Future: industry-leading 401K retirement savings plan with matching and company contributions, student loan pay downs, and 529 educational savings assistance programs, tuition reimbursement, employee stock purchase plan, and financial learning center and financial coach access.
- Supporting your Health & Well-being: flexible health and insurance options, employee, spouse, and child life insurance, short- and long-term disability, pre-tax Health Savings Account with employer contributions, Healthcare FSA, critical illness, accident & hospital indemnity insurance, and a total well-being program that helps you and your family stay on track physically, socially, emotionally, and financially.
- Building a Family: adoption, surrogacy, and fertility assistance as well as paid parental and caregiver leave, Dependent Day Care FSA back-up child and adult/elder care days and childcare discounts.
- Work-Life Integration: Mentally Fit Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs.
For more detailed information about Ally's Total Rewards, please visit this link.