T Rowe Price Group, Inc

Senior Risk Analyst, Privacy & Third-Party Risk

T Rowe Price Group, Inc$87K — $148K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s degree in Risk Management, Information Systems, Finance, Business, Law, or a related field.
  • 5+ years of experience in risk management or related field, preferably within financial services.
  • Ability to operate independently in a 2LoD risk function.
  • Strong knowledge of risk management principles with expertise in privacy and third-party risk domains.
  • Experience in identifying control weaknesses and developing remediation plans.

Responsibilities

  • Provide independent oversight of privacy risks from first-line business activities.
  • Lead assessments of Privacy Impact Assessments (PIAs) and Data Protection Impact Assessments (DPIAs).
  • Review and analyze privacy incidents and propose remediation plans.
  • Evaluate third-party risk assessments and escalate significant deficiencies.
  • Develop executive-level risk reporting and monitor emerging risks.

Benefits

  • Hybrid work option with flexibility for remote work.
  • Opportunities for professional certification support.
  • Involvement in advanced technology projects, including AI and automation initiatives.
Full Job Description

Role Summary

The Senior Risk Analyst – Privacy & Third-Party Risk is a Second Line of Defense (2LoD) role and a member of the Global Privacy Office (GPO) and Third-Party Risk Management (TPRM) function. The role provides independent risk oversight, effective challenge, and assurance over first-line activities and outsourced TPRM services, operating with minimal supervision and a high degree of professional judgment.

This position is expected to independently manage complex risk assessments, lead oversight activities, identify emerging risk themes, and deliver clear, actionable insights to senior stakeholders and governance committees. The role also supports the effective operation and continuous improvement of the GPO and TPRM programs through risk reporting, data analysis, issue management, technology enablement, and maintenance of core governance and compliance processes.

Responsibilities

Privacy Risk – Global Privacy Office:

  • Independently provide 2LoD oversight of privacy risks arising from first-line business activities and serve as a subject matter resource on privacy risk matters.
  • Lead review and challenge of Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments, including assessments involving new technologies, artificial intelligence, sensitive data, and elevated privacy risk.
  • Evaluate the design and operating effectiveness of privacy controls and recommend enhancements aligned with regulatory expectations and risk appetite.
  • Independently review privacy incidents, including root cause analyses and remediation plans, and support reconciliation, trend analysis, governance reporting, and escalation of significant privacy incidents.
  • Provide technical expertise and support the implementation of privacy and data protection processes, controls, and procedures based on enterprise-wide guidance issued by the Global Privacy Office.
  • Support Privacy and Security by Design activities by evaluating new technologies, systems, products, and business initiatives; assessing privacy risks and control requirements; and providing risk-based guidance to business and technology stakeholders.
  • Partner with Technology, Information Security, Legal, Compliance, and business stakeholders to support appropriate implementation of privacy requirements and controls.
  • Identify opportunities to enhance the Global Privacy Office’s technical capabilities; develop, test, and work with technology teams to deploy such capabilities, including workflow automation, reporting, analytics, and AI-enabled solutions.
  • Support the maintenance of the firm’s required privacy compliance documentation (e.g., Records of Processing Activities, Transfer Impact Assessments, procedures, guides, training, SharePoint sites), privacy inventories, registers, response materials, and supporting program records.
  • Support the execution of the privacy compliance monitoring program.
  • Support recurring privacy governance and compliance activities, including regulatory reporting, metrics, management information, periodic reconciliations, annual recertifications, readiness exercises, and regulatory or operational-impact assessments.
  • Support privacy-related inquiries, due diligence questionnaires, requests for information, and other stakeholder requests by researching issues, coordinating responses, and maintaining reusable response content.

Third-Party Risk Management:

  • Perform quality assurance and effective challenge of third-party risk outputs produced by external service providers and first-line stakeholders.
  • Independently review and challenge complex or elevated-risk third-party assessments, including due diligence findings, control deficiencies, risk responses, and recommendations to business stakeholders.
  • Monitor adherence to SLAs, KPIs, and contractual obligations of outsourced TPRM providers and escalate deficiencies as appropriate.
  • Identify systemic control gaps, concentration risk, and emerging third-party risk trends across the vendor population.
  • Evaluate and challenge third-party information security, technology, resiliency, privacy, and other risk considerations, partnering with domain subject matter experts where specialized expertise is required.
  • Contribute to the ongoing development of fourth-party risk governance and oversight practices.
  • Identify opportunities to enhance TPRM’s technical capabilities; develop, test, and work with technology teams to deploy such capabilities, including AI-assisted quality assurance, workflow automation, risk analytics, and reporting solutions.
  • Support the maintenance of the firm’s required TPRM compliance documentation (e.g., Policy, Supplier Management Standards, questionnaire templates, frameworks, training, SharePoint sites).
  • Support TPRM intake and stakeholder inquiries, including coordination and routing of requests, maintenance of supplier and program data, and development of reusable due diligence and client-response content.
  • Support risk-based prioritization, supplier tiering, and methodology enhancements by testing proposed approaches and analyzing their impact on the third-party population.

Risk Governance, Reporting & Analytics:

  • Independently develop and deliver executive-level risk reporting, dashboards, and management information.
  • Prepare and coordinate recurring management and governance reporting, including metrics, risk trends, control issues, incident information, and other program performance indicators.
  • Assist with monitoring and reporting emerging AI and technology risks across privacy and third-party risk, contributing to oversight of controls, assessments, and reporting.
  • Leverage AI-enabled tools and advanced analytics to identify trends, emerging risks, and control weaknesses.
  • Analyze assessment results, incidents, performance data, and other risk indicators to identify systemic weaknesses, recurring issues, concentration or dependency risks, and emerging themes requiring management attention.
  • Lead preparation for regulatory examinations, internal audits, and management assurance activities related to privacy and third-party risk oversight.
  • Maintain accurate, complete documentation in GRC, privacy, and TPRM systems and ensure audit-ready artifacts.
  • Identify, document, and escalate risk and control deficiencies; assess the adequacy of remediation plans; and monitor significant issues through resolution.

Technology, Process Improvement & Program Enablement:

  • Translate business and risk requirements into functional requirements and user stories for GRC, privacy, TPRM, reporting, and workflow solutions.
  • Perform user acceptance testing and validation of system implementations, enhancements, and fixes; document defects and support retesting through resolution.
  • Partner with technology, enablement, and program teams to develop and enhance dashboards, reporting, workflow automation, AI-enabled tools, and other capabilities that improve risk visibility and program efficiency.
  • Identify opportunities to improve Privacy and TPRM frameworks, processes, controls, operating models, and supporting technology, and lead or support implementation of prioritized enhancements.
  • Support data quality and stewardship activities necessary to maintain reliable program inventories, supplier information, business-process information, reporting, and risk records.

Qualifications

Required:

  • Bachelor’s degree in Risk Management, Information Systems, Finance, Business, Law, or a related field.
  • 5+ years of experience in risk management, GRC, information security, privacy, third-party risk, operational risk, technology risk, or a related oversight function, preferably within financial services, asset management, or another highly regulated industry.
  • Demonstrated ability to operate independently with minimal guidance in a 2LoD environment or in a risk function requiring independent review, challenge, and escalation.
  • Strong knowledge of risk management principles and demonstrated expertise in one or more relevant domains, such as privacy, third-party risk, information security, technology risk, operational risk, or compliance, with the ability to develop expertise across both Privacy and TPRM.
  • Demonstrated experience identifying control weaknesses, assessing risk, developing or challenging remediation plans, and communicating findings to stakeholders.
  • Strong analytical skills and experience working with risk data, metrics, reporting, or management information.

Preferred:

  • Experience leading or independently managing 2LoD privacy or TPRM oversight activities.
  • Asset management or broader financial services experience.
  • Experience spanning multiple risk domains, such as operational risk, information security, technology risk, privacy, resiliency, compliance, or third-party risk.
  • Experience with control testing, risk and control assessments, issue management, root cause analysis, remediation oversight, or similar risk-management activities.
  • Experience supporting or implementing risk-management frameworks, policies, standards, or program enhancements.
  • ISO 27001 Lead Implementer, Auditor, or other relevant risk, security, privacy, or third-party risk certifications.
  • Familiarity with SEC, FINRA, and global regulatory expectations.

Tools & Technology – Preferred

  • Advanced experience with GRC, privacy, and TPRM platforms (e.g., Archer, ServiceNow, OneTrust, IBM OpenPages).
  • Strong proficiency with reporting and analytics tools (e.g., Power BI, advanced Excel).
  • Practical experience using AI-enabled risk, compliance, or data analytics tools to enhance oversight and reporting (e.g., Microsoft Copilot, ChatGPT Enterprise).
  • Ability to automate reporting and improve risk visibility.
  • Experience developing business requirements, user stories, test scenarios, or performing UAT for risk-management technology solutions is preferred.
  • Familiarity with workflow and automation tools such as Power Automate or similar technologies is a plus.

Certifications

Relevant professional certification or demonstrated equivalent experience preferred. Candidates actively pursuing a relevant certification will also be considered. Examples include:

  • Certified Information Privacy Professional (CIPP/US, CIPP/E)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Third Party Risk Professional (CTPP/CTPRP)
  • Certified Information Privacy Manager (CIPM)
  • Certified Information Privacy Technologist (CIPT)

Key Competencies

  • Strong independent judgment and risk-based decision-making.
  • Ability to provide credible, effective challenge at senior levels.
  • Excellent written and verbal communication skills.
  • Strong issue management, quality assurance, and governance discipline.
  • Comfort operating autonomously in a global, regulated environment.
  • Ability to manage both complex analytical work and recurring operational responsibilities with accuracy and discipline.
  • Strong stakeholder-management skills and ability to collaborate across business, Technology, Information Security, Legal, Compliance, Procurement, and other risk functions while maintaining appropriate 2LoD independence.
  • Continuous-improvement mindset with the ability to translate risk-management needs into practical process and technology enhancements.

FINRA Requirements

FINRA licenses are not required and will not be supported for this role.

Work Flexibility

This role is eligible for hybrid work, with up to one day per week from home.

Base Salary Ranges

Please review the job posting for the location of this specific opportunity.

$87,000.00 - $148,000.00 for the location of: Maryland, Colorado, Washington and remote workers
$95,500.00 - $163,000.00 for the location of: Washington, D.C.
$108,000.00 - $185,000.00 for the location of: New York, California

Plac

About T Rowe Price Group, Inc

T. Rowe Price Group, Inc. is an American publicly owned global asset management firm that offers funds, advisory services, account management, and retirement plans and services for individuals, institutions, and financial intermediaries. The company was founded in 1937 by Thomas Rowe Price Jr. and went public in 1986. The company is headquartered in Baltimore, Maryland and has offices in 16 countries worldwide. As of December 31, 2020, the company had $1.47 trillion in assets under management. The company is listed on the NASDAQ stock exchange under the ticker symbol TROW.
Learn more about T Rowe Price Group, Inc
Size
7,529 employees
Market Cap
$24.5 billion
Industry
Net Income
$2.3 billion
Founded
1937
5 Year Trend
+12.4%
Revenue
$6.2 billion
NASDAQ

Similar Jobs

More Jobs at T Rowe Price Group, Inc

More Finance & Insurance Jobs

Find similar Senior Risk Analyst, Privacy & Third-Party Risk jobs: