Third-Party Risk Management Officer

SmartBank

• $100K — $120K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's in Business, Finance, Risk Management, or related field preferred.
  • 5+ years in vendor management, third-party risk management, or compliance-related roles.
  • Relevant banking and risk management experience can substitute for degree.
  • Preferred certifications: CRVPM, CTPRP; additional credentials like CRCM, CISA, CRISC, CISSP are advantageous.
  • Strong knowledge of third-party risk management laws and regulations.

Responsibilities

  • Manage the entire third-party lifecycle from planning to termination.
  • Conduct risk-based due diligence on vendors including cybersecurity and compliance.
  • Maintain and categorize third-party inventories and risk classifications.
  • Oversee contract reviews to identify risks across various dimensions.
  • Track and escalate high-risk issues affecting vendor relationships.
  • Facilitate periodic vendor reviews based on risk ratings and policy standards.
  • Prepare detailed reports for management and board on vendor risk metrics.

Benefits

  • Part of a values-driven organization focused on integrity and teamwork.
  • Opportunity to work across multiple business units to enhance accountability.
  • Access to ongoing training and development programs in risk management.
  • Engagement with a diverse range of internal stakeholders including compliance and audit teams.
Full Job Description
Major Duties and Responsibilities:

Core Values & Culture Commitment:
  • Uphold SmartBank Core Values and Core Purpose.
  • Adheres to and embraces the SmartBank Way by Acting Smart, Looking Smart and Being Smart.


General Responsibilities:
  • Manage the full third-party lifecycle, including planning, risk assessment, due diligence, contract review coordination, monitoring, escalation, offboarding, and termination.
  • Perform risk-based due diligence covering SOC reports, financial condition, cybersecurity, privacy, business continuity, insurance, subcontractors, compliance documentation, and unresolved control issues.
  • Maintain the third-party inventory, risk tiering, criticality designations, ownership assignments, service descriptions, data access indicators, fourth-party considerations, and risk classifications.
  • Coordinate contract and service agreement reviews to identify operational, compliance, security, privacy, business continuity, audit rights, service level, termination, subcontracting, and transition risks.
  • Track remediation, document risk acceptances or exceptions, escalate overdue or high-risk issues, validate corrective actions, and drive timely resolution.
  • Facilitate risk-based annual and periodic vendor reviews based on policy, regulatory expectations, risk ratings, criticality, performance, control changes, and material relationship changes.
  • Monitor concentration risk, fourth-party and subcontractor dependencies, geographic or service-provider exposure, and emerging risks affecting operations, customers, compliance, or resilience.
  • Prepare management and board reporting on vendor risk metrics, critical and high-risk providers, due diligence status, overdue reviews, open issues, risk acceptances, emerging risks, concentration risk, exceptions, and program effectiveness.
  • Partner with Information Security, Compliance, Legal, Procurement, Finance, Business Continuity, Operational Risk, Internal Audit, and other Business Units to support oversight and reinforce business-owner accountability.
  • Maintain accurate, accessible documentation supporting due diligence, risk assessments, monitoring, issue management, risk acceptance, reporting, audits, exams, and regulatory reviews.
  • Monitor regulatory guidance and industry practices related to third-party risk management.
  • Coordinate annual SOX-related vendor reviews, including SOC report and vendor control assessments impacting financial reporting and key business processes.


Position Requirements and Qualifications:

Education:

  • Bachelor's degree in Business Administration, Finance, Accounting, Risk Management, Information Systems, Information Security, or related field preferred.
  • Relevant banking, risk management, compliance, or information security experience may be considered in lieu of a degree.
  • Minimum of 5+ years of experience in vendor management, third-party risk management, information security, compliance, audit, enterprise risk management, procurement, or banking operations.


Training (licenses, programs, or certificates):

  • CRVPM (Certified Regulatory Vendor Program Manager) preferred.
  • CTPRP (Certified Third-Party Risk Professional) preferred.
  • CRCM, CISA, CRISC, CISSP preferred.


Knowledge, Skills, and Abilities:

  • Ability to apply knowledge and sound judgment in decision-making using established guidelines.
  • Strong written and oral communication skills.
  • Detail oriented and ability to function in a team environment.
  • Demonstrates ability to maintain a positive attitude.
  • High level of integrity.
  • Able to maintain regular and predictable attendance.
  • Must possess the ability to handle multiple tasks simultaneously, with frequent interruptions.
  • Must be able to able to prioritize and organize daily workflow.
  • Strong relationship management and business development/sales skills.
  • Thorough knowledge of bank products and services.
  • Knowledge of third-party risk management laws, regulations, and supervisory expectations, including interagency guidance, FFIEC guidance, GLBA, privacy, business continuity, and banking regulator expectations.
  • Strong analytical, organizational, communication, relationship management, issue management, documentation, project management, and executive reporting skills, with the ability to constructively challenge and escalate risk issues.
  • Working knowledge of FFIEC, GLBA, OCC, FDIC, Federal Reserve, and interagency third-party risk management guidance.
  • Experience reviewing contracts, SOC reports, risk assessments, business continuity documentation, and regulatory compliance materials.
  • Experience preparing executive and board-level reporting.
  • Experience supporting regulatory examinations and audits.
  • Extensive experience with Examiner interactions.


Work Conditions:

  • Able to routinely stand, sit, bend and stoop.
  • Frequently and regularly required movements using wrists, hands, and/or fingers.
  • Average, ordinary, visual acuity necessary to prepare and inspect documents or products and operate machinery.
  • Ability to hear average or normal conversations and receive ordinary information.
  • May be required to travel to training sessions or meetings.

Similar Jobs

More Jobs at SmartBank

More Finance & Insurance Jobs

Find similar Third-Party Risk Management Officer jobs: