IT Third-Party Risk Assessor

MUFG Bank, Ltd.$125K — $164K *
Tampa, FL 33647In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field or equivalent experience.
  • 5+ years in Third-Party Risk Management or related areas.
  • Experience in regulated industries like financial services or healthcare.
  • Understanding of cybersecurity principles and security frameworks.
  • Preferred certifications such as CISSP, CISM, or CTPRP.

Responsibilities

  • Conduct comprehensive risk assessments of third-party vendors.
  • Review vendor security documentation and manage risks in Archer GRC.
  • Leverage AI tools for risk evaluation and monitoring.
  • Prepare and present risk assessment reports to stakeholders.
  • Perform ongoing monitoring of vendor compliance and risk status.

Benefits

  • Hybrid work arrangement with one remote day per week.
  • Collaborative work environment with various business units.
  • Opportunities for professional development and certification support.
  • Engagement in critical cybersecurity and risk management initiatives.
Full Job Description
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The IT Third-Party Risk Assessor is responsible for evaluating, monitoring, and reporting on information technology risks associated with third-party vendors, suppliers, service providers, and other external business partners. This role supports the organization's Third-Party Risk Management (TPRM) program by conducting risk assessments, reviewing cybersecurity controls, identifying potential vulnerabilities, and ensuring third parties comply with organizational policies, industry standards, and regulatory requirements. The successful candidate will evaluate the information security and technology frameworks of external partners, SaaS providers, and financial technology associates. This position enforces strict alignment with banking regulations, manages risk lifecycles inside Archer, and leverages AI technologies to accelerate due diligence and continuous monitoring. TPRM SME will partner with business stakeholders, procurement / contract management teams, security teams, compliance functions, and vendors to identify and mitigate risks throughout the third-party lifecycle. Key Responsibilities Third-Party Risk Assessments ulli Conduct cybersecurity, information security, and technology risk assessments of third-party vendors and service providers. ulli Review vendor security documentation, including: ulli SIG questionnaires ulli SOC 1 and SOC 2 reports (may include Bridge Letter verification) ulli ISO 27001 certifications to include SoA reviews ulli Archer Management: Track, document, and manage the end-to-end vendor risk lifecycle within Archer GRC. ulli AI Tool Integration: Use AI-powered risk platforms to parse vendor documentation and summarize control gaps. ulli Security policies and procedures ulli Assess inherent and residual risks associated with third-party relationships. ulli Evaluate vendor compliance with internal policies, security standards, and regulatory requirements. Risk Analysis and Reporting ulli Identify and document control gaps, vulnerabilities, and areas of concern. ulli Develop risk ratings and provide recommendations for risk mitigation. ulli Prepare concise risk assessment reports and executive-level summaries. ulli Present assessment findings to business owners, risk committees, and senior management. Ongoing Monitoring ulli Perform periodic reassessments of critical and high-risk vendors. ulli Monitor vendors for cybersecurity incidents, financial instability, regulatory actions, and emerging risks. ulli Track remediation activities and validate corrective actions. ulli Maintain vendor risk profiles and assessment documentation. Stakeholder Collaboration ulli Partner with Procurement, Information Security, Legal, Compliance, Privacy, and Business Units throughout the vendor lifecycle. ulli Provide guidance regarding security requirements during vendor onboarding and renewals. ulli Support contract reviews by recommending security and data protection requirements. ulli Assist business partners in understanding and managing third-party technology risks. Governance, Risk, and Compliance ulli Ensure alignment with regulatory requirements and industry frameworks such as: ulli NIST Cybersecurity Framework ulli NIST CRI ulli NIST 800-53 ulli NIST 800-171 ulli FFIEC Guidance ulli ISO 27001 ulli HIPAA (as applicable) ulli Support audits, examinations, and regulatory reviews related to third-party risk. ulli Contribute to continuous improvements of the Third-Party Risk Management Program. Required Qualifications Education ulli Bachelor's degree in Information Technology, Information Security, Cybersecurity, Risk Management, Business Administration, or a related field. ulli Equivalent combination of education and experience will be considered. Experience ulli 5+ years of experience in: ulli Third-Party Risk Management (TPRM) ulli Information Security ulli Cybersecurity Risk Management ulli IT Audit ulli Technology Risk ulli Operational Risk ulli Business Continuity Planning ulli Experience reviewing vendor security assessments and industry-standard assurance reports. ulli Experience working in regulated industries such as financial services, healthcare, insurance, or technology preferred. ulli Banking Knowledge: Solid understanding of financial regulatory expectations regarding data protection and operational resilience. Technical Knowledge ulli Understanding of cybersecurity principles and security control frameworks. ulli Familiarity with: ulli Access management ulli Network security ulli Cloud security ulli Data protection and encryption ulli Disaster recovery and business continuity ulli Vulnerability management ulli Incident response ulli Service Level Management (Agreements review & verification) ulli Release Management / SDLC ulli IT Asset Management ulli IT Configuration Management ulli Change Management ulli Problem Management ulli System Capacity and Performance ulli Knowledge of vendor risk assessment methodologies and control evaluation techniques. Preferred Certifications One or more of the following certifications are preferred: ulli Certified Information Systems Security Professional (CISSP) ulli Certified Information Security Manager (CISM) ulli Certified Third-Party Risk Professional (CTPRP) ulli Certified Third Party Risk Assessor (CTPRA) ulli Certified Information Systems Auditor (CISA) ulli Certified in Risk and Information Systems Control (CRISC) ulli Certified Cloud Security Professional (CCSP) ulli Security+ or equivalent cybersecurity certification Key Competencies ulli Risk assessment and analysis ulli Critical thinking and problem solving ulli TPRM Full Lifecycle ulli Information security knowledge ulli Regulatory and compliance awareness ulli Written and verbal communication ulli Executive reporting and presentation skills ulli Attention to detail ulli Stakeholder relationship management ulli Time management and organization Success Metrics ulli Timely completion of third-party risk assessments. ulli Quality and accuracy of risk evaluations. ulli Reduction of unresolved vendor control issues. ulli Effectiveness of remediation tracking and closure. ulli Compliance with regulatory and internal TPRM requirements. ulli Positive audit and examination outcomes. ulli Continuous improvement of third-party risk processes and controls. Reporting Structure Reports To: Head of Data and Financial Operations Transformation Individual Contributor: Yes Travel: Minimal (0-10%) Comp Range: 125k-164k Work Arrangement: Hybrid (based on business needs) This position plays a critical role in protecting the organization from cybersecurity, operational, compliance, and reputational risks arising from third-party relationships while enabling the business to engage vendors safely and effectively.

About MUFG Bank, Ltd.

MUFG Bank, Ltd. Careers

There has never been a better time to join the global team at MUFG Bank, Ltd., a premier institution recognized for its leadership in the financial sector. MUFG Bank, Ltd. offers a plethora of job opportunities that cater to a variety of skills and interests, all while fostering professional growth and innovation.

Work You’ll Do

Join MUFG Bank, Ltd.'s distinguished team to assist some of the most sophisticated clients in navigating their financial landscapes. At MUFG Bank, Ltd., team members lead from a unique position in the marketplace, at the crossroads of financial expertise, industry knowledge, and digital innovation. Engage with a global team of business and financial advisors to help clients master their economic strategies and challenges. Collaborate with the largest group of finance professionals in the industry – a network that spans across continents offering unmatched opportunities for networking and professional development.

Introducing the MUFG Bank, Ltd. Business Advisory

The team is dedicated to building a leading Advisory group to guide some of the most renowned companies through their financial strategies using innovative solutions.

Do Innovative Work

Be part of a team that delivers targeted financial solutions through a depth and breadth of consulting experience and innovation that’s second to none.

Be Part of a Great Team

Work on a wide range of financial technologies and harness the unparalleled capabilities, global scale, and joint solution development that only MUFG Bank, Ltd. can offer.

Future-Proof Your Career

Advance your career as far as your ambition can take you with limitless opportunities supported by unmatched training, development, and certification support.

Explore

Discover how MUFG Bank, Ltd. is leading the way in financial innovation with cutting-edge projects like blockchain for secure transactions and AI for risk assessment.

The MUFG Bank, Ltd. Alliance

The combined service capabilities, global scale, and joint solution development enable clients to overcome challenges and lead transformation in their industries. Clients worldwide turn to MUFG Bank, Ltd. for new strategies and financial solutions to drive growth and success in the digital era.

Stay Connected

Join the Team

Search open positions that match your skills and interests. MUFG Bank, Ltd. seeks passionate, curious, creative, and solution-driven team players.

SEARCH MUFG JOBS

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who work at MUFG Bank, Ltd.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Explore the exciting and rewarding opportunities that await at MUFG Bank, Ltd.
Learn more about MUFG Bank, Ltd.

Similar Jobs

More Jobs at MUFG Bank, Ltd.

More Information Technology Jobs

Find similar IT Third-Party Risk Assessor jobs: