Overview: The Vendor Risk Manager owns, develops, implements, enhances, and maintains MCU's vendor risk management frameworks, taxonomies, policies, and procedures. The Vendor Risk Manager administers MCU's vendor risk management program, ensuring compliance with NCUA, NYDFS, and FFIEC requirements and protecting the credit union from third-party operational and compliance risks
Responsibilities:
Specific duties include, but are not limited to, the following:
- Lead the end-to-end Vendor Risk Management Program in alignment with regulatory requirements (e.g., NCUA, NYDFS, FFIEC) and internal policies.
- Manage the vendor due diligence lifecycle including risk assessments, contracting support, ongoing monitoring, and offboarding processes.
- Facilitate periodic reviews of critical and high-risk vendors, including SOC reports, financial health, cybersecurity practices, regulatory compliance, and performance metrics.
- Collaborate with Enterprise Risk, Legal, Information Security, and business units to evaluate and mitigate vendor risks.
- Provides subject-matter expertise to business lines on vendor selection, onboarding, and risk remediation.
- Maintain the Vendor Risk Register and ensure vendor risk ratings are accurate and current.
- Coordinate with internal audit and external examiners on vendor risk management reviews.
- Develop and deliver periodic vendor risk reports to senior management and the Board, including risk exposure, trends, and performance metrics.
- Monitor regulatory changes and industry best practices to ensure continuous improvement of the Vendor Risk Management Program.
- Provide coaching and oversight to staff or cross-functional teams involved in vendor risk activities.
- Perform other related duties as requested and special projects as assigned.
Requirements:
- Bachelor's degree required, advanced degree preferred.
- Minimum of 5 years of experience in the financial services industry required.
- Minimum of 5 years of risk management experience, with demonstrable knowledge in third-party vendor risk.
- Knowledge of operational risk management, regulatory compliance, general IT risk/IT operations, and financial industry business lines and workflows required.
- Preferred certifications: Certified Third-Party Risk Professional or Certified Regulatory Vendor Program Manager.
- Ability to perform in a high-volume environment and meet deadlines while maintaining exceptional attention to detail.
- Technologically proficient.
Why You'll Love Working Here:The pay range for this position is between $87,500-116,500 annually. Actual base pay offered may vary depending on a number of factors such as job-related knowledge, skills, experience, and location. Employees in this position may also be eligible for a discretionary bonus, 401(k) with an 6% employer match per pay period. Benefits for this position include Medical, vision, dental, life, and disability insurance, flexible paid time off and 11 paid holidays annually.