Role DescriptionThe Head of Vendor Risk Management is responsible for leading the Bank's first line Third-Party Management Operations (TPMO) program across all business lines and corporate functions. This executive leadership role oversees the governance, framework, policies, and ongoing monitoring of third-party and affiliate risks to ensure compliance with regulatory expectations and alignment with the Bank's risk appetite.
The role serves as the primary subject matter expert for vendor risk and is responsible for identifying, assessing, monitoring, and mitigating risks arising from external service providers, strategic partnerships, outsourcing arrangements, and critical third-party relationships. The Executive Director will partner closely with Technology, Information Security, Procurement, Legal, Compliance, Operational Risk, Internal Audit, Vendor Management and Business stakeholders to ensure a robust and effective vendor risk management framework.
Role ObjectivesLeadership & Strategy- Lead the enterprise-wide Vendor Risk Management Program and establish the strategic vision as we work more globally including development of goals and target operating roadmap.
- Drive continuous enhancement of the third-party risk framework, governance model, policies, standards, and procedures.
- Serve as a trusted advisor to executive management and risk committees on emerging third-party risks and industry developments.
- Build, develop, and mentor a high-performing team of vendor risk professionals.
Third-Party Risk Governance- Execute the Bank's Third-Party Risk Management Framework, ensuring alignment with regulatory guidance and industry best practices.
- Establish risk assessment methodologies and ongoing new ways of monitoring activities.
- Define risk appetite statements, key risk indicators (KRIs), and reporting metrics for third-party risk exposures.
- Oversee governance forums and escalation processes for critical vendor risks.
Risk Assessment & Monitoring- Oversee due diligence reviews for new and existing vendors, including financial, operational, cybersecurity, compliance, privacy, resiliency, and concentration risk assessments.
- Ensure appropriate risk tiering of vendors and implementation of monitoring requirements based on risk levels.
- Review findings, remediation plans, and risk acceptance decisions for material third-party relationships.
- Monitor concentration risk and interdependencies among critical service providers.
Regulatory & Audit Management- Ensure compliance with applicable regulatory guidance, including OCC, Federal Reserve, FDIC, and other relevant third-party risk management requirements.
- Lead regulatory examinations and internal/external audits related to vendor management programs.
- Coordinate responses to regulatory findings, audit issues, and management action plans.
Stakeholder Management- Partner with Procurement, Legal, Compliance, Information Security, Business Continuity, Data Privacy, and Technology teams throughout the vendor lifecycle.
- Provide regular reporting and strategic updates to executive leadership, risk committees, and governance forums.
- Influence senior leaders across the organization to drive effective risk management practices.
Reporting & Analytics- Establish executive dashboards and management reporting on vendor risk exposures, issue remediation, concentration risks, and program effectiveness.
- Leverage data analytics and automation capabilities to improve risk identification and decision-making.
- Present vendor risk trends and emerging threats to executive committees and Board-level stakeholders
Qualifications and SkillsEducation- Bachelor's degree required.
- Advanced degree (MBA, MS, JD, or equivalent) preferred.
Experience- 12+ years of experience in Vendor Risk Management, Third-Party Risk, Operational Risk, Enterprise Risk, Audit, Compliance, or related financial services functions.
- Minimum of 7 years of leadership experience managing teams and enterprise-wide programs within a large financial institution.
- Deep understanding of banking regulations, third-party risk frameworks, outsourcing risk management, and operational resilience.
- Experience interacting with regulators, executive management, and Board committees.
- Proven success building and enhancing enterprise risk programs.
Preferred Certifications- Certified Third Party Risk Professional (CTPRP)
- Certified Information Systems Auditor (CISA)
- Certified Risk Professional (CRP)
- Certified Information Systems Security Professional (CISSP)
- Project Management Professional (PMP)
#LI-RCH
Additional RequirementsSMBC's employees participate in a Hybrid workforce model that provides employees with an opportunity to work from home, as well as, from an SMBC office. SMBC requires that employees live within a reasonable commuting distance of their office location. Prospective candidates will learn more about their specific hybrid work schedule during their interview process. Hybrid work may not be permitted for certain roles, including, for example, certain FINRA-registered roles for which in-office attendance for the entire workweek is required.