Salary range: An annual salary range of $190,000 - $200,000 is what we expect to pay for this position, based on overall skills and experience.
Must be legally eligible to work in the United States without sponsorship, now or in the future, to be considered.
What You'll Do:It is expected that the team member will work with the Director of TPRIM and other Customers Bank stakeholders, as well as Cubi's vendors to perform/deliver, at a minimum, the following and other possible duties as assigned based on the TM's level of experience:
Tasksa) Review and enhance the foundation of the TPRIM program regarding the building blocks of the program, such as:
- Policy
- Framework
- Standard Operating Procedures
- Contractual template language
- Risk appetite and scope
- Identify the "right" value metric
b) Operationalize the selected TP Cyber Risk Rating platform:
- Scope of vendor inventory
- Scope of the vendor risk profile to monitor
- Develop smart alerts notifications according to vendor scope and risk profile
- Identify and develop the proper data to report to Leadership
- Socialize the program with key internal stakeholders as well as a rollout introduction to our critical TPs
c) Eyes on Glass Cyber Risk intelligence monitoring:
- Respond to alerts
- Perform vulnerability risk assessments
- Conduct an Impact Analysis for certain alerts such as breaches and zero-day events
- Communication and collaboration to our internal stakeholders and the Targets
- Collaboration on Target Action Plans and time to resolve
- Interact with Customers Bank's vendor supporting the Cyber Risk Rating platform as an extension of the TPRIM Team
- Tracking open issues
- Notification to stakeholders
- Escalation
- Reporting
- Continuous Improvement
What Do You Need?- Minimum 7 years of knowledge of Third-Party Risk Management methodologies and regulatory guidance and/or risk management at a fintech organization.
- Minimum 5 years of experience at a Bank, financial institution, larger corporation, or a fintech.
- Bachelor's degree or equivalent experience.
- Well versed in financial regulatory and supervisory expectations in the risk areas.
- Expert level creative thinking and strong "on the spot" problem solving skills.
- Hands-on experience with executing on a Third-Party Risk Management program.
- Proven experience in contract management, being able to read a contract and understand and communicate contractual provisions and the impact to risk.
- Excellent verbal, written, and interpersonal communication skills with the ability to explain programs, features, policies, and procedures to Customers Bank employees, customers, and business owners.
- Previous leadership experience that included mentoring junior employees.
- Self-starter with the ability to work independently.
- Familiarity with vendor technology risk assessment controls and associated subdomains (i.e., information security, business continuity, etc.) or similar experience in related IT-audit or IT-audit support roles.
- Familiarity with the current regulatory environment on Technology-related Vendor Risk for financial institutions, i.e., OCC 2013-29, FFIEC BRP/DR Handbook, FDIC guidance.
- Demonstrated understanding of information security, business continuity/resumption, compliance, financial analysis, legal, and audit are preferred skills/knowledge requirements.
- Ability to take initiative and perform in a challenging, agile, fast-paced technical and business environment.
- Ability to maintain confidentiality.
- Above all, a desire to learn and a passion for third party risk management.
Technology Skills:- Familiarity with AI and automation tools that support productivity, workflow efficiency, and client engagement.
- Certified in third party risk or other risk domains (CRVPM, CTPRA, CERP, CRISC).
- Project Management Professional (PMP), Certified Information Systems Auditor (CISA) or Certified Information Systems Security Professional (CISSP) or relevant IT certifications and credentials a plus.
- Third party risk tool or GRC experience.