Third Party Risk Management Lead
Third Party Risk Management (TPRM) Lead is responsible for providing enterprise wide third party risk management services, including taking a lead role to define, implement, and maintain a risk framework, operating model, policies, procedures, governance and oversight programs for all lines of business and subsidiaries. CNB established the TPRM program as a second line function, enabling CNB to manage third party risk effectively and efficiently, relative to its size and complexity. The lead is responsible for ensuring the program meets regulatory guidance, aligns with CNB's parent company, and incorporate changes as necessary.
In partnership with the TPRM Program Manager, develop a successful implementation plan consisting of :
- Assist with the development and execution of an TPRM risk framework, policies and procedures
- Direct assessments on key controls and overall compliance with the TPRM program, including the timeliness, completeness, and accuracy of risk assessments.
- Provide risk-consulting serves to first line third party risk managers for complex arrangements.
- Develop risk analysis and reporting, including risk metrics, for dissemination to both first line of defense (technology) leadership, risk management committees, CNB's parent holding company, and CNB's regulators.
- Streamline processes for risk identification and assessment, control assessment, testing and issue management.
- Lead continuous improvement activities and initiatives for TPRM, working with stakeholders, subject matter experts, and analysis of exception reports to define issues, determine root cause, and determine appropriate changes.
- Identify and assess requirements for CNB's GRC system to increase automation, and process effectiveness and efficiency.
- Responsible for reviewing SSAE 18 reports for CNB's third parties and evaluate for completeness, appropriateness, and assess impact to CNB on findings and exceptions to support CNB's Sarbanes Oxley, FDICA, and SOC programs.
- Manage coordination of assignment of resources based on demand and capacity, and required subject matter expertise, including augmenting internal staff with external resources as necessary.
- Ensure appropriate escalate of issues to first line and senior management as required.
Required Qualifications :
Minimum of 7 years of third party risk management, assurance and / or oversight or relevant supplier or third party audit or compliance experienceMinimum of 4 years of experience in risk and controls for information technology and cybersecurity, appropriately scoping assessments, providing credible challenges, and performing assurance testing.Minimum of 4 years working with a GRC system, incorporating continuous improvement for the system and process.Additional Qualifications :
Comprehensive knowledge of third party and information technology risk management processes and methodologiesExperience using third party risk management / Governance, Risk and Compliance (GRC) systemsExperience assessing contracts, including master service agreements, statements of work, and license agreements.Experience assessing cloud servicing arrangementsKnowledge of and experience in designing and operating governance, frameworks and processes to comply with vendor management / third party risk management related regulatory requirements, guidance and oversight (OCC 2013-29, Fed SR 13-19 or other relevant third party risk management / vendor management regulation applicable to the financial services industry)Currently hold or quickly obtain industry recognized third party risk management or vendor management certificationExcellent oral and written communication skills; experience performing both detailed and executive-level documentationAdvanced knowledge of Microsoft Office tools; specifically, Excel, PowerPoint and SharePointExperience with reporting platforms such as Tableau, SQL scripts, and Microsoft SSRS desirableCompensation : Starting base salary : $99,000 - $176,000 per year. Exact compensation may vary based on skills, experience, and location. This job is eligible for bonus and / or commissions.
Benefits and Perks : At City National, we strive to be the best at whatever we do, including the benefits and perks we offer our colleagues including :
Comprehensive healthcare coverage, including Medical, Dental and Vision plans, available the first of the month following start dateGenerous 401(k) company matching contributionCareer Development through Tuition Reimbursement and other internal upskilling and training resourcesValued Time Away benefits including vacation, sick and volunteer timeSpecialized health and family planning benefits including fertility benefits, and cancer, diabetes and musculoskeletal support programsCareer Mobility support from a dedicated recruitment teamColleague Resource Groups to support networking and community engagementCity National Bank fosters an inclusive environment where all forms of diversity are valued and leveraged to make us a better company and employer. We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, veteran status or other basis protected by law.