This position serves as a trusted advisor to the business, driving risk-based decision-making while ensuring alignment with regulatory expectations, policy requirements, and service-level objectives. With direct responsibility for partnering with Product Service Owners (PSOs) in assigned Business Lines (BL), BL Chief Risk Officers (CRO) staff,Risk/Compliance/Audit(RCA) Managers, Procurement Partners, Law Division, Technology and Information Security teams to manage the end-to-end execution of third-party risk management lifecycle.
Key Responsibilities
- Strategic Risk Oversight
Provide leadership in identifying, assessing, and mitigating third-party risks across the enterprise, with a focus on critical services, operational resilience, information security, compliance, and concentration risk. Drive alignment with enterprise risk appetite and regulatory expectations. - Program Governance & Lifecycle Management
Oversee the execution and continuous improvement of third-party lifecycle processes—including due diligence, risk assessments, monitoring, issue remediation, and exit strategies—ensuring consistency with internal policies and control frameworks. - Cross-Functional Leadership & Stakeholder Engagement
Act as a strategic advisor and escalation point for business line leaders, risk SMEs, legal, compliance, and procurement. Facilitate informed decision-making and ensure appropriate risk treatment strategies are applied across third-party engagements. - Performance & Service Level Oversight
Lead the governance of third-party performance against defined SLAs and KPIs. Drive accountability for remediation of underperformance and ensure alignment with business continuity and resiliency objectives. - Regulatory & Policy Alignment
Maintain subject matter expertise on evolving regulatory requirements (e.g., OCC, FRB, DORA) and internal policies. Ensure the TPRM program remains compliant and audit-ready and proactively address regulatory changes. - Portfolio & Relationship Management
Provide oversight of third-party portfolios across business lines, ensuring effective segmentation, risk assessments, and alignment with strategic objectives. Foster strong relationships with key third-party contacts and internal stakeholders to support service delivery and risk mitigation. - Process Optimization & Continuous Improvement
Champion enhancements to TPRM tools, processes, and reporting capabilities. Promote a culture of continuous improvement and innovation, leveraging data and insights to inform strategic decisions. - Risk Reporting & Governance Support
Support business line CROs and risk committees with timely, accurate reporting on third-party risk posture, emerging issues, and remediation progress. Ensure transparency and accountability across the TPRM ecosystem.
Qualifications
- Bachelor’s degree in risk management, Business, Finance, or related field (advanced certifications such as CTPRP, CRVPM preferred).
- Demonstrated leadership in program or team management.
- 6+ years of experience in third-party risk, vendor management, or enterprise risk functions.
- Deep understanding of third-party risk domains (e.g., cybersecurity, compliance, operational resilience).
- Proven ability to influence across functions and levels, including senior leadership.
- Strong analytical, communication, and problem-solving skills.
- Experience with TPRM platforms (e.g., Archer, ServiceNow) and contract lifecycle tools.
- Ability to manage competing priorities in a dynamic, fast-paced environment.
- Strategic thinker with a proactive, risk-aware mindset.