Third-Party Risk Management Officer

SmartBankBrentwood, New YorkOn-siteFull-timeSenior, 5–8 yearsListed 6 days ago

Apply now

About this role

Looking to join a Great Place to Work Employer and become a valued member of our growing team? At SmartBank, we're not just offering a job; we're inviting you to be a part of a culture built on excellence.

Major Duties and Responsibilities:

Core Values & Culture Commitment:

- Uphold SmartBank Core Values and Core Purpose.
- Adheres to and embraces the SmartBank Way by Acting Smart, Looking Smart and Being Smart.

General Responsibilities:

- Manage the full third-party lifecycle, including planning, risk assessment, due diligence, contract review coordination, monitoring, escalation, offboarding, and termination.

- Perform risk-based due diligence covering SOC reports, financial condition, cybersecurity, privacy, business continuity, insurance, subcontractors, compliance documentation, and unresolved control issues.

- Maintain the third-party inventory, risk tiering, criticality designations, ownership assignments, service descriptions, data access indicators, fourth-party considerations, and risk classifications.
- Coordinate contract and service agreement reviews to identify operational, compliance, security, privacy, business continuity, audit rights, service level, termination, subcontracting, and transition risks.

- Track remediation, document risk acceptances or exceptions, escalate overdue or high-risk issues, validate corrective actions, and drive timely resolution.

- Facilitate risk-based annual and periodic vendor reviews based on policy, regulatory expectations, risk ratings, criticality, performance, control changes, and material relationship changes.

- Monitor concentration risk, fourth-party and subcontractor dependencies, geographic or service-provider exposure, and emerging risks affecting operations, customers, compliance, or resilience.

- Prepare management and board reporting on vendor risk metrics, critical and high-risk providers, due diligence status, overdue reviews, open issues, risk acceptances, emerging risks, concentration risk, exceptions, and program effectiveness.

- Partner with Information Security, Compliance, Legal, Procurement, Finance, Business Continuity, Operational Risk, Internal Audit, and other Business Units to support oversight and reinforce business-owner accountability.

- Maintain accurate, accessible documentation supporting due diligence, risk assessments, monitoring, issue management, risk acceptance, reporting, audits, exams, and regulatory reviews.

- Monitor regulatory guidance and industry practices related to third-party risk management.

- Coordinate annual SOX-related vendor reviews, including SOC report and vendor control assessments impacting financial reporting and key business processes.

Position Requirements and Qualifications:

Education:

- Bachelor's degree in Business Administration, Finance, Accounting, Risk Management, Information Systems, Information Security, or related field preferred.

- Relevant banking, risk management, compliance, or information security experience may be considered in lieu of a degree.

- Minimum of 5+ years of experience in vendor management, third-party risk management, information security, compliance, audit, enterprise risk management, procurement, or banking operations.

Training  (licenses, programs, or certificates):

- CRVPM (Certified Regulatory Vendor Program Manager) preferred.
- CTPRP (Certified Third-Party Risk Professional) preferred.
- CRCM, CISA, CRISC, CISSP preferred.

Knowledge, Skills, and Abilities:

- Ability to apply knowledge and sound judgment in decision-making using established guidelines.
- Strong written and oral communication skills.
- Detail oriented and ability to function in a team environment.
- Demonstrates ability to maintain a positive attitude.
- High level of integrity.
- Able to maintain regular and predictable attendance.
- Must possess the ability to handle multiple tasks simultaneously, with frequent interruptions.
- Must be able to able to prioritize and organize daily workflow.
- Strong relationship management and business development/sales skills.
- Thorough knowledge of bank products and services.
- Knowledge of third-party risk management laws, regulations, and supervisory expectations, including interagency guidance, FFIEC guidance, GLBA, privacy, business continuity, and banking regulator expectations.
- Strong analytical, organizational, communication, relationship management, issue management, documentation, project management, and executive reporting skills, with the ability to constructively challenge and escalate risk issues.
- Working knowledge of FFIEC, GLBA, OCC, FDIC, Federal Reserve, and interagency third-party risk management guidance.
- Experience reviewing contracts, SOC reports, risk assessments, business continuity documentation, and regulatory compliance materials.
- Experience preparing executive and board-level reporting.
- Experience supporting regulatory examinations and audits.
- Extensive experience with Examiner interactions.

Work Conditions:

- Able to routinely stand, sit, bend and stoop.

- Frequently and regularly required movements using wrists, hands, and/or fingers.
- Average, ordinary, visual acuity necessary to prepare and inspect documents or products and operate machinery.
- Ability to hear average or normal conversations and receive ordinary information.
- May be required to travel to training sessions or meetings.