Title: AVP Third Party Risk Monitoring & Due Diligence
Office Status: Hybrid New York, NY
Base Salary: $103k $135k + Bonus
ABOUT THE ROLE
This AVP-level opportunity sits within the Third Party Due Diligence team of a well-established global financial institution's first-line Enterprise Controls Department, offering end-to-end ownership of the continuous monitoring program for third and fourth party service providers across cybersecurity, financial, compliance, operational, geographic, and ESG risk domains. The role combines rigorous ongoing monitoring with due diligence assessment execution, stakeholder engagement, and audit-ready documentation making it an ideal fit for a detail-oriented third party risk management professional with 5+ years of TPRM, IT audit, or risk assessment experience who thrives in a regulated financial services environment and is comfortable translating complex technical risks into clear business language for senior stakeholders.
RESPONSIBILITIES
Own end-to-end ongoing monitoring of third and fourth party risks across cybersecurity (BitSight) and enterprise risk domains (Supply Wisdom) including weekly alert reviews, trend and impact analysis, ransomware and vulnerability assessments, fourth-party incident reporting, and composite risk-rating evaluations across Macro-Economic, Financial, Geo-Political, Infrastructure, Business, Legal, Security & Compliance, Scalability, and ESG domains
Coordinate with Cyber Defense to review NCFTA alerts and identify, assess, and respond to emerging high-risk cyber threats affecting third parties
Serve as primary point of contact for Third Party Managers, Business Approvers, Legal, Compliance, CISO/Cyber Defense, DLP, and SMEs to assess the business impact of third and fourth party risk events;document material incidents in Archer including score declines, severe incidents, sanctions hits, and breaches
Identify and analyze risk issues, communicate impacts in clear business terms, drive and track remediation to closure, and escalate Critical or High-risk issues to TPDD and TPRM leadership as appropriate
Support monthly concentration and portfolio risk monitoring including engagement volume, service locations, contingent workers, and sole-provider exposure;contribute to quarterly reporting and maintain accurate BitSight portfolios and Supply Wisdom license assignments
Lead and perform due diligence reviews, reassessments, and significant change evaluations in accordance with TPRM policies and procedures;assess inherent risk and control effectiveness across Information Security, Technology, Business Continuity, Risk Management, Incident Management, Physical Security, Nth-Party Risk, and HR domains
Identify and document due diligence gaps and risk exposures;recommend remediation, risk acceptance, or escalation actions in Archer;coordinate Certificate of Insurance validation as needed
Review Archer KRI reports to identify threshold breaches and overdue activities;ensure risk acceptances are recorded and tracked;support internal and external audits, regulatory exams, and Federal Banking Agency ROE reviews through timely and accurate documentation
Maintain complete audit-ready records including QA reviews of 10% of Moderate/Low and 100% of Critical/High assessments
Contribute to enhancement of IRQs, DDQs, monitoring playbooks, KRIs, and reporting processes;identify and remediate data anomalies in Archer and support reconciliations across systems