Senior Third Party Risk Analyst
About the role
This position provides full-service enterprise third party risk services to analyze and assess third party products and vendors for risk to the organization’s financial plans and growth goals. The role ensures compliance with regulatory requirements, such as NYDFS.
Responsibilities
- Recommend and implement innovations to continuously improve processes.
- Manage third party risk program templates, tools, procedures, and processes; update as necessary.
- Design and maintain Third Party Risk program tools, such as third party risk scorecards, risk assessments, workflows, reports, and process improvement initiatives.
- Train team members on tools and processes to ensure purchasing standards are met.
- Partner and collaborate with Legal, Information Security, IT, Finance, and Business Continuity departments on complex risk assessments and contractual matters.
- Gather, synthesize, and prepare data for reports and departmental presentations.
- Prepare market analysis or data related to third party risk as necessary.
- Design and manage complex data sets; draw conclusions related to third party and contract data.
- Maintain current knowledge of trends and best practices for third party risk and the insurance industry.
- Analyze the risk posed by third parties in purchasing and third party relationships.
- Execute a risk-based engagement and monitoring program consistent with the third party risk program, regulatory requirements, and company policies.
- Produce robust governance and oversight reporting consistent with risk rating and program requirements.
- Analyze complex financial reports and risk-related reports to assess third party financial viability and business legitimacy.
- Use independent judgment based on data compilation and documented processes to recommend or disqualify third parties from doing business with ICW Group.
- Complete information security reviews by assessing required third party documentation such as SOC reports, incident response plans, and Cloud security protocols.
- Execute the third party risk management lifecycle, including planning, due diligence, negotiation, ongoing monitoring, and termination of third party relationships.
- Manage relationships with third parties, prospective third parties, and other external constituencies involved in the third party risk program.
- Complete due diligence risk assessments, including financial viability reviews and information security requirements for potential third parties.
- Vet third parties and negotiate terms related to risk remediation consistent with regulatory requirements and ICW Group policies.
- Assess third party ongoing financial and commercial viability and identify associated risks.
- Monitor third party performance for consistency with service level expectations.
- Collect and review supporting documentation for potential and existing third parties.
- Drive completion of ongoing assessments of ICW Group third parties.
- Manage a library of third party documentation, scorecards, and other applicable documents in relevant systems.
- Manage process improvements, contract standardization, and other departmental projects.
- Provide specialized advice and risk analysis results to various departments throughout the company.
- Provide vetted third party data and recommendations to business stakeholders in departments such as Legal, Compliance, Information Security, IT, and Finance.
- Articulate and present recommendations to stakeholders based on findings during third party analysis, including financial strength data, information security practices, and other operational risk measurements.
- Advise buyers and other internal procurement professionals in third party risk assessments during selection and vetting.
- Audit current third party relationships and proactively escalate deficient third parties to appropriate parties, such as internal legal and finance leaders.
- Ensure satisfactory outcomes of regulatory audits and exams.
Requirements
- Bachelor’s degree from a four-year college or university with a major or emphasis in Finance, Data Science, Information Security, or related field; or equivalent combination of education and experience.
- Minimum 5-7 years of experience working with third party contracts, information security protocol documentation, or financial documentation.
- Previous experience with operational risk analysis, including IT risks, software risks, and security risks preferred.
- Extensive experience with Microsoft Excel, Word, Visio, and PowerPoint.
- Prior experience with governance, risk, and compliance (GRC) tools and contract negotiation preferred.
Qualifications
- One or more of the following certifications are preferred:
- Amazon Web Services (AWS) Certified Cloud Practitioner certification or similar Cloud-based technology certification.
- Certified Regulatory Vendor Program Manager (CRVPM).
- Certified in Risk and Information Systems Control (CRISC).
- Certified Third Party Risk Professional (CTPRP).
- Certified Internal Auditor (CIA).
- Certified Financial Services Auditor (CFSA).
- Certified Fraud Examiner (CFE).
- Knowledge of regulatory third party standards including New York Department of Financial Services cybersecurity (NYDFS), Office of the Comptroller of the Currency (OCC), Federal Financial Institutions Examination Council (FFIEC), and Consumer Financial Protection Bureau (CFPB).
- Ability to work with mathematical concepts such as probability and statistical inference.
- Ability to apply principles of logical or scientific thinking to a wide range of intellectual and practical situations.
- Ability to hypothesize root causes of inefficiencies and test probable solutions.
- Ability to analyze complex sets of data and develop creative solutions to support business needs.
- Ability to read, analyze, and interpret technical journals, financial reports, contracts, and other related documents.
- Excellent interpersonal and communication skills with the ability to directly influence others.
- Ability to accept new ideas and embrace change.
- Demonstrated organizational and time management skills.
- Capability to coordinate and organize input from various channels, perform negotiation, resolve conflicts, and build consensus at all levels of the organization.
- Must be able to read, write, and speak English effectively.
Physical Requirements
- Frequently required to sit; regularly required to stand, walk, reach with hands and arms, stoop, kneel, crouch, or crawl.
- Must occasionally lift and/or move up to 30 pounds.
- Specific vision abilities required include close vision.
- Required to have visual acuity and be capable of operating and viewing computers and other electronic devices for extended periods.
Work Environment
This position operates in an office environment and requires frequent use of a computer, telephone, copier, and other standard office equipment. The noise level in the office is usually moderate.
Pay
The current range for this position is $78,678.61 - $132,686.15. This range is exclusive of fringe benefits and potential bonuses. Final base salary compensation will be determined by factors unique to each candidate, including experience, education, and location of the role, and considers employees performing substantially similar work.
Benefits
- Competitive benefits package, including generous medical, dental, and vision plans.
- 401K retirement plans with company match.
- Bonus potential for all positions.
- Paid Time Off.
- Paid holidays throughout the calendar year.
- Support for continuing education and professional development.