Third-Party Risk Manager

Nightowl Consulting

Philippines

On-site

PHP 900,000 - 1,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nightowl Consulting is seeking a dedicated Third-Party Risk Manager to lead our vendor risk management program in the Philippines. You will determine risk tiers, conduct onboarding assessments, and oversee due diligence processes for third-party relationships.

Responsibilities include maintaining the vendor inventory, coordinating Legal reviews, and reporting to senior leadership on risk, incidents, and remediation status.

Responsibilities

  • Determine the inherent risk tier (Tier 1, Tier 2, or Tier 3) for every third party prior to contracting or engagement, consistent with the criteria defined in TPRM02.
  • Perform and document inherent risk assessments during onboarding, according to the policy reassessment schedule (annual for Tier 1 and bi-annual for Tier 2 vendors), and whenever a material change occurs in the vendor relationship.
  • Administer the due diligence process, including the issuance and evaluation of vendor due diligence questionnaires (DDQs), SOC 1 and SOC 2 reports, financial statements, insurance certificates, business continuity and information security documentation, and licensing or regulatory standing.
  • Maintain the authoritative third-party inventory, including assigned risk tier, services provided, data classification, system access, contract status, and all supporting documentation.
  • Administer the Company’s vendor management software platform, including profile setup, document collection, workflow configuration, expiration tracking, contract repository management, and audit history maintenance.
  • Monitor all vendors, contractors, and third-party counterparties against the FHFA Suspended Counterparty List (SCL) prior to engagement and on a recurring monthly basis; immediately escalation any matches to General Counsel and Compliance.
  • Coordinate contract reviews with Legal to ensure all required clauses are included, including information security, confidentiality, audit rights, subcontracting, breach notification, business continuity, termination, and return or destruction of data provisions.
  • Track and report vendor incidents, performance issues, breaches, and remediation activities; communicate findings to business owners and escalate material concerns to the Risk Management Committee.
  • Maintain documentation of vendor reviews, due diligence activities, identified risks, and required remediation efforts; provide training to business owners on intake and approval workflows.
  • Administer the vendor termination process, including coordination of the return of Company property and the return or destruction of Company data and information in accordance with legal and regulatory requirements.
  • Document and route policy exceptions for approval by the Third-Party Risk Manager and, when required, the Risk Management Committee.
  • Prepare periodic TPRM reporting and performance metrics for senior leadership, the Risk Management Committee, internal audit, external examiners, investors, and warehouse lenders.
  • Support audits and regulatory examinations by producing vendor inventories, risk assessments, due diligence files, and program documentation upon request.
  • Coordinate with the AI Governance Committee on due diligence and risk tiering activities related to third-party AI solutions and AI-enabled vendor features, consistent with RAIG01 Section 10.
  • Lead the annual review of the Third-Party Risk Management Policy (TPRM02) and recommend revisions for approval.
  • Perform other duties and responsibilities as assigned.

Job description

  • Determine the inherent risk tier (Tier 1, Tier 2, or Tier 3) for every third party prior to contracting or engagement, consistent with the criteria defined in TPRM02.
  • Perform and document inherent risk assessments during onboarding, according to the policy reassessment schedule (annual for Tier 1 and bi-annual for Tier 2 vendors), and whenever a material change occurs in the vendor relationship.
  • Administer the due diligence process, including the issuance and evaluation of vendor due diligence questionnaires (DDQs), SOC 1 and SOC 2 reports, financial statements, insurance certificates, business continuity and information security documentation, and licensing or regulatory standing.
  • Maintain the authoritative third-party inventory, including assigned risk tier, services provided, data classification, system access, contract status, and all supporting documentation.
  • Administer the Company’s vendor management software platform, including profile setup, document collection, workflow configuration, expiration tracking, contract repository management, and audit history maintenance.
  • Monitor all vendors, contractors, and third-party counterparties against the FHFA Suspended Counterparty List (SCL) prior to engagement and on a recurring monthly basis; immediately escalation any matches to General Counsel and Compliance.
  • Coordinate contract reviews with Legal to ensure all required clauses are included, including information security, confidentiality, audit rights, subcontracting, breach notification, business continuity, termination, and return or destruction of data provisions.
  • Track and report vendor incidents, performance issues, breaches, and remediation activities; communicate findings to business owners and **escalate** material concerns to the Risk Management Committee.
  • Maintain documentation of vendor reviews, due diligence activities, identified risks, and required remediation efforts; provide training to business owners on intake and approval workflows.
  • Administer the vendor termination process, including coordination of the return of Company property and the return or destruction of Company data and information in accordance with legal and regulatory requirements.
  • Document and route policy exceptions for approval by the Third-Party Risk Manager and, when required, the Risk Management Committee.
  • Prepare periodic TPRM reporting and performance metrics for senior leadership, the Risk Management Committee, internal audit, external examiners, investors, and warehouse lenders.
  • Support audits and regulatory examinations by producing vendor inventories, risk assessments, due diligence files, and program documentation upon request.
  • Coordinate with the AI Governance Committee on due diligence and risk tiering activities related to third-party AI solutions and AI-enabled vendor features, consistent with RAIG01 Section 10.
  • Lead the annual review of the Third-Party Risk Management Policy (TPRM02) and recommend revisions for approval.
  • Perform other duties and responsibilities as assigned.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third-Party Risk Manager
Third-Party Risk Manager

NightOwl Consulting • Quezon City

On-site
Above market salary
HMO on Day 1
Performance-based Incentives
Third-Party Risk Manager
Third-Party Risk Manager

NightOwl Consulting Philippines Inc. • Philippines

On-site
Above market salary
HMO on Day 1
Government benefits
+4
Vendor Risk Analyst I: TPRM & Compliance
Vendor Risk Analyst I: TPRM & Compliance

TP • Philippines

On-site
PHP 360,000 - 600,000
Third Party Vendor Analyst
Third Party Vendor Analyst

GR8 Global Philippines • Philippines

Hybrid
PHP 600,000 - 900,000
Vendor Risk & TPRM Program Lead
Vendor Risk & TPRM Program Lead

NightOwl Consulting • Quezon City

On-site
Above market salary
HMO on Day 1
Performance-based Incentives
Remote Third-Party Risk Analyst
Remote Third-Party Risk Analyst

GR8 Deal Two, LLC • Philippines

On-site
PHP 420,000 - 900,000
Vendor Risk Analyst I - McKinley - 12-Month Contract
Vendor Risk Analyst I - McKinley - 12-Month Contract

TP • Philippines

On-site
PHP 360,000 - 600,000
Senior TPRM Manager: Drive Vendor Excellence
Senior TPRM Manager: Drive Vendor Excellence

NightOwl Consulting Philippines Inc. • Philippines

On-site
Above market salary
HMO on Day 1
Government benefits
+4
Risk Assessment QA Analyst - McKinley
Risk Assessment QA Analyst - McKinley

Teleperformance • Philippines

On-site
PHP 300,000 - 420,000
Vendor Risk & Compliance Lead
Vendor Risk & Compliance Lead

Nightowl Consulting • Philippines

On-site
PHP 900,000 - 1,500,000