
Junior Analyst, Third-Party Risk Management
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in New York.
• Assist in the Third-Party Risk Management program within a highly regulated banking environment.
• Perform initial and ongoing risk evaluations for both new and existing vendors, focusing on cybersecurity and data protection.
• Analyze vendor due diligence responses, including information security, security architecture, and cloud environments.
• Identify control deficiencies and propose risk mitigation strategies.
• Evaluate vendors that manage sensitive data, critical systems, or customer information.
• Aid in vendor due diligence, concentration risk, fourth-party risk, and business continuity evaluations.
• Support preparations for regulatory examinations and internal audits.
• Maintain documentation that demonstrates regulatory compliance and risk-based decision-making.
• Assist in updating TPRM policies, procedures, and standards.
• Assess vendor security programs against established frameworks, such as: NIST Cybersecurity Framework, ISO 27001, SOC 2 Type II.
• Aid in the monitoring of critical and high-risk vendors.
• Track vendor performance, compliance, and remediation actions.
• Prepare risk summaries and reporting materials for leadership.
• Escalate significant risks promptly.
• Review vendor incident response and breach notification protocols.
• Evaluate business continuity and disaster recovery capabilities.
• Prepare succinct risk reports for senior leadership and risk committees.
• Maintain precise documentation within the TPRM system.
• Collaborate with Information Security, Compliance, Legal, Procurement, and business units.
• Bachelor’s degree in business, Information Security, Cybersecurity, Risk Management, Finance, or a related field.
• 1-3 years of experience in TPRM and Information security risk.
• Experience in an OCC-regulated financial institution (preferred).
• Familiarity with cloud risk management (AWS, SaaS environments) (preferred).
• Experience with TPRM platforms (preferred).
• Working knowledge of risk assessment methodologies (inherent vs. residual risk).
• Knowledge of NIST Cybersecurity Framework.
• Familiarity with ISO 27001.
• Understanding of SOC 2 reports.
• Medical, Dental, and Vision insurance.
• 401(k).
• Life and disability insurance.
Kemboi Financial Agency
Kemboi Financial Agency
Kemboi Financial Agency
Kemboi Financial Agency
Get handpicked remote jobs straight to your inbox weekly.