Third Party Risk Management (TPRM) Senior Analyst
On-siteNew York City, New York, United States or New York, United States
Job Summary
Execute and support all phases of the third-party lifecycle in compliance with the TPRM Program, including intake, onboarding documentation, risk assessments, approvals, and ongoing reviews. Perform mapping and validation of services and agreements, review vendor contracts for key risk-relevant terms, and track application onboarding status within the Archer system. Bridge communication across stakeholders to ensure timely coordination, documented reviews, and management sign-off while administering training and providing system support to business users. Ensure all vendor-related evidence and approvals are accurately captured and maintain audit-ready documentation for regulatory exam requests. Cross-train and provide flexible support to the Director of Operational Risk as required.
Required Qualifications
- Bachelor's degree
- 3–6 years of experience in third-party risk management, operational risk, compliance, audit, or a related risk/control function
- Experience supporting third-party or vendor lifecycle activities, including onboarding, documentation review, assessments, approvals, or ongoing monitoring
- Familiarity with third-party due diligence documentation, such as SOC 2 Type II reports, penetration testing results, information security policies, SIG questionnaires, and business continuity or resiliency plans
- Experience working with risk management systems or workflow tools (e.g., TPRM platforms, GRC systems, or similar systems of record)
- Experience supporting audit or regulatory exam requests, including evidence gathering and response coordination
Desired Qualifications
- Business, Finance, Risk Management, Information Systems, or a related field
- Exposure to technology risk, system testing, or workflow validation
- Prior experience in financial services or a regulated environment
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.