SALARYThis position has a base salary range of $120,000.00 - $180,000.00 USD Annual . This range represents the expected base salary range for this position. The actual salary may vary based upon several factors including, but not limited to, relevant skills/experience and time in the role.
SUMMARYThis role is responsible for overseeing and enhancing BCU's Third-Party Risk Management (TPRM) Program. This role leads the assessment, monitoring, governance, and reporting of risks associated with vendors and other third-party relationships, ensuring compliance with regulatory expectations and alignment with BCU's enterprise risk appetite.
The position owns the end-to-end third-party risk process, including onboarding, risk tiering, due diligence, contract review, ongoing monitoring, issue management, and offboarding. This role is also responsible for program governance, reporting, regulatory readiness, and continuous improvement initiatives designed to strengthen BCU's third-party risk framework.
ROLE AND RESPONSIBILITIES- Manage BCU's Third-Party Risk Management Program, including policies, standards, procedures, and governance frameworks ensuring alignment with applicable regulatory requirements, including NCUA, FFIEC, CFPB, GLBA, NIST, and other relevant industry guidance.
- Maintain and make recommendations to enhance risk-based methodologies for vendor segmentation, inherent risk assessments, due diligence, ongoing monitoring, and issue management.
- Prepare and deliver risk reporting, metrics, and dashboards to executive leadership, management committees, and audit stakeholders.
- Support regulatory examinations, internal audits, and external reviews related to third-party risk management activities.
- With the assistance of advisors in Finance, Business Resiliency, Information Technology, Information Security, Procurement and Legal, evaluating vendor controls, practices, and supporting documentation, including SOC reports, cybersecurity assessments, business continuity plans, financial statements, insurance coverage, and compliance evidence.
- Identify control gaps and risk exposures, document findings, and partner with business owners to create mitigation strategies.
- Manage ongoing monitoring activities for critical and high-risk third parties.
- Maintain accurate third-party inventories, risk ratings, documentation, and assessment records.
- Perform basis system administration and optimization of the vendor management platform, including workflow configuration, reporting, user support, and data quality oversight.
- Identify opportunities to automate processes, improve efficiency, and enhance program maturity.
- Maintain procedures, templates, assessment tools, and training materials supporting the TPRM program.
QUALIFICATIONS AND EDUCATION REQUIREMENTS- Bachelor's degree in Business, Finance, Risk Management, Information Systems, Cybersecurity, Accounting, or a related field.
- 5 years of experience in Third-Party Risk Management, Vendor Management, Enterprise Risk Management, Information Security, or a related discipline.
- Strong understanding of third-party risk lifecycle management, including onboarding, due diligence, risk assessments, ongoing monitoring, issue management, contract review, and offboarding.
- Experience evaluating vendor documentation, including SOC 1 and SOC 2 reports, cybersecurity assessments, business continuity plans, financial statements, and compliance certifications.
- Working knowledge of regulatory expectations governing financial institutions and third-party relationships.
- Experience using Governance, Risk, and Compliance (GRC) platforms and vendor management systems.
- Strong analytical, organizational, project management, and communication skills.
- Ability to influence stakeholders and effectively communicate risk to both technical and non-technical audiences.