Third Party Risk Sr Analyst
About the Role
As the Third Party Risk Senior Analyst, you will manage vendor issues, complete quality assurance functions, and execute Third Party Vendor Assessment reviews. This includes managing relationships with both business leaders and vendors while providing robust insight on business risk and the adequacy and effectiveness of control processes. The role delivers assessment reviews and provides opinions on the quality of the vendor control environment to meet Citizens policies, identifying issues and assisting the business in agreeing to action plans to mitigate risk.
The Third-Party Assessment function adds value by providing specific business function assurance on vendors related to customer, financial, or reputational risk, driving momentum for action plans to address risk, and leveraging findings and best practices bank-wide.
Responsibilities
- Collaborate with senior management to influence key decisions.
- Evaluate third-party vendors' control infrastructure effectiveness and obtain evidence of controls.
- Apply experience in audit, security, and regulatory frameworks including ISO 27001, GLBA, SOX, PCI, HIPAA, State Privacy Regulations, and FFIEC.
- Assist in Governance Risk and Compliance (GRC) program design, process reengineering, enhancements, and tool/technology implementations.
- Lead current risk assessments, continual risk assessments, and risk metrics and visualizations.
- Perform quality assurance on vendor assessment and remediation activities.
- Work directly with key business leaders to facilitate risk analysis and risk management processes, identifying acceptable levels of risk and establishing roles and responsibilities.
- Maintain and monitor the enterprise risk exception process to identify areas of noncompliance.
- Support and participate in regulatory exam preparation, execution, and remediation as applicable.
- Coach and mentor junior analysts and clearly articulate Third Party Vendor Assessment program goals and objectives.
- Produce Third Party Vendor Assessment reports that clearly articulate risks for varied audiences.
- Translate security risk and communicate effectively to business partners within the organization.
- Travel within the United States is required.
Qualifications
- Ability to navigate program requirements independently.
- Demonstrates advanced critical thinking and identifies opportunities with recommended solutions.
- Ability to manage multiple complex assessments and related activities.
- Strong verbal and written communication skills among various internal and external stakeholders.
- Strong analytical skills to identify and classify inherent and residual risks.
- Effectively leads calls with various stakeholders to achieve desired results.
- Experience in financial services, particularly in Risk, Audit, Compliance, Cyber, or Third-Party Risk.
- Proficient use of Microsoft Word and Microsoft Excel.
- Experience gathering and analyzing evidence through various methods (e.g., email, virtual sessions, onsite) and sources (e.g., artifacts, interviews, meetings, demonstrations, independent audits, review of processes/policies).
Preferred Qualifications
- Bachelor’s Degree (preferred).
- Relevant industry certification(s) (e.g., CISA, CRCM, CRISC, CTPRP, TPCRA) (preferred).
Schedule
Hours per Week: 40
Work Schedule: 8 AM – 5 PM (4 days in office, 1 day remote)
Work Authorization
This role is not eligible for new employer-sponsored or current H-1B visa holders. Applicants, including current OPT, L, and other visa holders, must be authorized to work in the U.S. without the need for new employer sponsorship for themselves or their spouses now and in the future.