Location Designation: Hybrid - 3 days per week
Job Title: Third Party & Supply Chain Exposure Management, Corporate Vice President
Reporting to: Head of Third Party Risk Management
Role Overview:New York Life is seeking an experienced third-party risk professional to identify, understand, and reduce exposure to emerging third-party and deeper supply chain risks.
The Corporate Vice President, Third Party & Supply Chain Exposure Management is a senior individual contributor in Third Party Risk Management (TPRM), combining monitoring, external risk signals, incidents, financial condition indicators, assessments, and supply chain dependencies to develop a dynamic view of New York Life's exposure.
This role will move beyond point-in-time assessments by determining what changes in third-party risk mean for New York Life and driving deeper analysis and mitigation. Focus areas include emerging risks, event-driven response, fourth- and Nth-party dependencies, concentration risk, technology deep dive integrated reviews, and financial condition monitoring.
What You'll Do:- Own and advance New York Life's ongoing third-party monitoring program, establishing an integrated approach for identifying, evaluating, and responding to material changes in third-party risk.
- Evaluate cyber intelligence, external monitoring, financial condition indicators, incidents, and other risk signals to determine when additional investigation, reassessment, remediation, or escalation is warranted.
- Lead TPRM analysis and response for significant external events-including cyber incidents, technology disruptions, critical vulnerabilities, supplier events, and other emerging risks-to rapidly identify potential exposure and coordinate appropriate action.
- Enhance Mythos response capabilities to identify impacted third parties, assess New York Life's exposure, and coordinate follow-up, escalation, and mitigation across relevant stakeholders.
- Develop a more comprehensive view of extended supply chain risk, identifying fourth- and Nth-party dependencies, common suppliers, cloud and technology providers, subcontractors, and other sources of concentration or systemic exposure.
- Identify emerging themes, dependencies, and concentrations across the third-party portfolio and translate complex risk information into clear exposure insights and actionable recommendations for senior management.
- Support oversight of critical third parties by integrating assessments, ongoing monitoring, financial condition, incidents, external risk signals, and supply chain dependencies into a holistic view of risk.
- Partner with Technology, Cybersecurity, and TPRM assessment teams to identify third parties requiring enhanced review and lead targeted technology risk deep dives across areas such as cloud, SaaS, application security, infrastructure, and data protection.
- Partner with the TPRM Brand/Reputation and Financial Condition Assessment team to incorporate changes in third-party reputation and financial condition into the broader exposure view and identify situations warranting enhanced diligence, escalation, or mitigation.
- Establish clear triggers, escalation paths, and response mechanisms that enable TPRM to move from periodic assessment toward a more continuous, event-driven, and exposure-based approach to third-party risk management.
- Operate across a matrixed organization to drive analysis, decisions, remediation, and risk reduction through influence and partnership
What You'll Bring:- Bachelor's degree required; degree in Information Systems, Cybersecurity, Technology, Risk Management, Business, or related field preferred.
- 8+ years of experience in third-party risk management, technology risk, cybersecurity, operational risk, supply chain risk, or related field.
- Deep understanding of third-party and vendor technology risk management, including assessments, monitoring, critical third-party oversight, remediation, and risk acceptance.
- Strong understanding of cybersecurity and technology risk, including cloud, SaaS, application security, and data protection.
- Experience evaluating monitoring, cyber ratings, threat intelligence, financial condition indicators, and other signals to identify changes in third-party risk.
- Experience responding to third-party incidents or emerging threats requiring rapid analysis and coordination.
- Understanding of fourth-party, nth-party, concentration, and supply chain risk concepts.
- Strong analytical skills, executive presence, and ability to operate independently, synthesize complex risk information, and drive outcomes without direct authority.
- Financial services or regulated industry experience preferred.
Preferred Certifications:
- CISA, CISSP, CRISC, CTPRP, or similar.
#LI-VL1
#LI-HYBRID
Pay TransparencySalary Range: $168,000-$210,000
Overtime eligible: Exempt
Discretionary bonus eligible: Yes
Sales bonus eligible: No
Actual base salary will be determined based on several factors but not limited to individual's experience, skills, qualifications, and job location. Additionally, employees are eligible for an annual discretionary bonus. In addition to base salary, employees may also be eligible to participate in an incentive program.
Our BenefitsWe provide a full package of benefits for employees - and have unique offerings for a modern workforce, including leave programs, adoption assistance, and student loan repayment programs. Based on feedback from our employees, we continue to refine and add benefits to our offering, so that you can flourish both inside and outside of work.Click hereto discover more about our comprehensive benefit options or visit our NYL Benefits Site.
Job Requisition ID: 95133