DTCC

Associate Director, Third Party Risk Governance & Framework

DTCC • $120K — $145K *
Finance & Insurance
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8-10 years of experience in Third Party Risk Management or related fields.
  • Bachelor's degree preferred or equivalent experience.
  • Strong understanding of Third Party Risk frameworks and regulatory expectations.
  • Experience in developing policies and controls in regulated environments.
  • Preferred experience in financial services or market infrastructure.

Responsibilities

  • Maintain Third Party Risk policies and governance documentation.
  • Define lifecycle requirements for third-party management.
  • Drive enhancements in collaboration with first line of defense teams.
  • Maintain risk taxonomies and classification criteria.
  • Promote consistent risk assessment and reporting standards.
  • Translate regulatory changes into governance enhancements.
  • Establish governance for critical third parties and resilience planning.

Benefits

  • Comprehensive health and life insurance benefits.
  • Pension and retirement benefits.
  • Paid time off and family care leave.
  • Flexible/hybrid work model with 3 days onsite and 2 days remote.
Full Job Description
Job Description

The Impact You Will Have in This Role

As part of Operational Risk & Resilience (ORR), the Associate Director, Third Party Risk Governance & Framework strengthens DTCC's second line of defense (2LoD) by managing and implementing the design, governance, and enhancements of the Third Party Risk framework. The role defines how Third Party Risk is managed across DTCC through policies, standards, methodologies, regulatory alignment, resilience integration, lifecycle requirements, and program governance. In this capacity, you will help strengthen DTCC's Third Party Risk program, control environment, and risk culture.

Primary Responsibilities

Third Party Risk Framework & Lifecycle Governance
  • Maintain Third Party Risk policies, standards, procedures, methodologies, controls, and governance documentation.
  • Define risk-based lifecycle requirements across third-party identification, assessment, management, monitoring, contingency planning, and termination.
  • Drive framework enhancements and work with first line of defense (1LoD) Third Party Management (TPM) to improve program effectiveness, training, operational clarity, regulatory alignment, and responsiveness to emerging risks.


Risk Taxonomy, Methodology & Control Integration
  • Maintain Third Party Risk taxonomies, risk categories, classification criteria, tiering standards, and criticality methodologies.
  • Promote consistent application of segmentation, assessment, monitoring, oversight, and reporting standards across the enterprise.
  • Integrate Third Party Risk expectations into enterprise risk processes, including RCSAs, CPRAs, risk scenarios, control expectations, and assessment methodologies.


Regulatory Alignment & Examination Support
  • Maintain awareness of applicable regulatory expectations and translate changes into policy, standards, control, and governance enhancements.
  • Partner with Compliance, Legal, Internal Audit, TPM, and business stakeholders to support regulatory examinations, remediation activities, and ongoing supervisory readiness.


Critical Third Party, Resilience & Dependency Governance
  • Establish governance requirements for critical third parties, including enhanced due diligence, ongoing monitoring, resilience, contingency planning, substitutability, and exit strategies.
  • Partner with Business Continuity and Operational Resilience teams to embed third-party resilience and dependency considerations into lifecycle and governance decisions.


Specialized Third Party Risk Governance
  • Establish enterprise requirements for specialized third-party risk areas, including third party provider types (e.g. technology, market data, staff augmentation, exchange and trading venues, financial market infrastructure, clearing brokers), CriticalPlus+ designations and contingent worker risk management.
  • Define governance controls for onboarding, access, tenure, concentration risk, privileged access, role dependency, supervisor accountability, and regulatory compliance.


Qualifications
  • 8-10 years of experience in Third Party Risk Management, Operational Risk, Enterprise Risk Management, Compliance, Regulatory Affairs, or related disciplines.
  • Bachelor's degree preferred or equivalent experience.
  • Strong understanding of Third Party Risk frameworks, cyber, resiliency, compliance, privacy, governance models, lifecycle requirements, and regulatory expectations.
  • Experience developing or enhancing policies, standards, controls, and risk frameworks in highly regulated environments.
  • Financial services, market infrastructure, banking, or regulatory experience preferred.


Talents Needed for Success
  • Ability to translate complex regulatory expectations into practical, scalable, and risk-based governance requirements.
  • Sound judgement and risk-based decision making.
  • Strong knowledge of risk taxonomy, classification, tiering, segmentation, and assessment methodologies.
  • Experience supporting regulatory examinations, remediation programs, and framework enhancement initiatives.
  • Executive communication, stakeholder management, influencing, strategic thinking, and program execution skills.
  • Collaborative, proactive, and focused on continuous improvement, risk reduction, and regulatory excellence.


Pay and Benefits:

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).


The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations.

About DTCC

The Depository Trust & Clearing Corporation (DTCC) is a financial services company that provides clearing, settlement, and information services for the global financial industry. DTCC was founded in 1999 and is headquartered in New York City. The company operates through subsidiaries that provide services such as trade matching, risk management, and asset servicing. DTCC is owned by its users, which include broker-dealers, banks, and other financial institutions. The company is committed to reducing risk and increasing efficiency in the financial markets.
Learn more about DTCC
Size
4,000 employees
Industry
Founded
1973

Similar Jobs

More Jobs at DTCC

More Finance & Insurance Jobs

Find similar Associate Director, Third Party Risk Governance & Framework jobs: