
Cyber Third Party Risk - Senior Analyst (Remote)
- Arizona North Carolina
- Permanent
- Full-time
Responsibilities
- Design and implement new reporting and metrics that will help measure and quantify third party cyber risk across the enterprise. This will require collecting data from multiple systems and identifying new data sources and developing plans to acquire new data.
- A sound knowledge of the industry and TPRM experience will be applied to assist leadership with ongoing strategic efforts, such as: integration with surrounding functions and systems, program facilitation and reporting capabilities and associated KPIs, and implementation of additional program automation and identified development opportunities.
- Lead the development and expansion of our third-party continuous monitoring capabilities. Build integration points with other areas within Cyber and other supporting TPRM functions to provide reporting that is beneficial and helps manager third party cyber risk.
- Develop and implement new third-party oversight activities moving away from point in time assessments and identifying other ways to reduce third party risk. Identify tools currently within the organization or support the evaluation of new products.
- Experience working directly in the Third Party Risk Management Program in a regulated industry in a position focused on driving and delivering on strategic improvements.
- Proven track record in leading large projects involving multiple stakeholders and influencing other business units to help support the successful delivery.
- Broad knowledge and understanding of cybersecurity risks and controls, including IT infrastructure, cloud computing, mobile technologies, and cybersecurity domains
- Experience with building out Third Party lifecycle activities in emerging risks such as Artificial Intelligence or new regulatory requirements.
- Proven experience in risk reporting and analytics, with strong data interpretation and communication skills.
- Strong understanding of the financial services industry, operational processes, and risk mitigation techniques.
- Possess relevant certifications such as CISSP, CISA, CISM, CRISC, CIA or equivalent