Business Controls Senior Associate - Third Party

Fifth Third Bank

Cincinnati (OH)

On-site

USD 90,000 - 130,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fifth Third Bank is seeking a seasoned risk professional to join its Enterprise Risk Management team in Cincinnati. The role focuses on identifying, assessing, mitigating, and managing risks to comply with evolving laws and internal standards.

You will transform data into insights for stakeholders and support risk programs across multiple functions. The candidate will review security controls, conduct third-party due diligence, and contribute to risk reporting and remediation efforts, with

Qualifications

  • Bachelor’s degree or equivalent experience in a related field.
  • Master’s degree in a relevant field preferred.
  • CISA or CRISC certification preferred.

Responsibilities

  • Assist with the development and implementation of controls, policies, procedures, and risk mitigation strategies.
  • Provide expertise in identification, assessment, monitoring, testing, and reporting of operational, compliance, information security, and third-party risks.
  • Conduct third-party due diligence activities, onsite assessments, assurance reviews, and risk assessments.
  • Travel domestically and internationally to perform onsite third-party assessments and evaluate compliance with Bank requirements.
  • Review assurance reports (SOC 1, SOC 2, ISO SOC), audit reports, and other compliance documentation.
  • Perform third-party risk assessments to evaluate compliance with internal policies, contractual obligations, and regulatory requirements.
  • Review contracts and security requirements to assess third-party obligations and risks.
  • Evaluate information security controls, data privacy controls, and secure workflows.

Skills

Risk assessment
Regulatory compliance
Data analysis
Third-party risk
Communication with stakeholders

Education

Bachelor's degree
Master's degree preferred
CISA or CRISC certification

Tools

Archer
Coupa
Power BI

Job description

Make banking a Fifth Third better®

We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.

GENERAL FUNCTION:

As first line of defense, conducts analysis related to identifying, assessing, mitigating, and managing risks necessary to comply with new or changing laws, regulations, regulatory guidance, and best practices deemed necessary by key stakeholders (such as Third Party Management, Legal, Information Security, Compliance, Enterprise Risk and Audit partners). Supports Business Controls in advancing risk management, structure, processes, and tools in support of the organization's Enterprise Risk Management (ERM) framework. Transforms data into business intelligence by developing and presenting information and insights to stakeholders. Monitors and manages risks to ensure compliance and validation of program effectiveness with assigned line of business or functional area, and Bancorp initiatives.

Responsible and accountable for risk by openly exchanging ideas and opinions, elevating concerns, and personally following policies and procedures as defined. Accountable for always doing the right thing for customers and colleagues and ensures that actions and behaviors drive a positive customer experience. While operating within the Bank's and LOB's risk appetites, achieves results by consistently identifying, assessing, managing, monitoring, and reporting risks of all types.

ESSENTIAL DUTIES AND RESPONSIBILITIES:
  • Assist Business Controls leadership with the development and implementation of controls, policies, procedures, and risk mitigation strategies.
  • Provide expertise related to the identification, assessment, monitoring, testing, and reporting of operational, compliance, information security, and third-party risks.
  • Conduct third-party due diligence activities, including onsite assessments, site visits, assurance reviews, and risk assessments.
  • Travel domestically and internationally to perform onsite third-party assessments and evaluate compliance with Bank requirements.
  • Review assurance reports, including SOC 1, SOC 2, ISO SoA, audit reports, and other compliance documentation.
  • Perform third-party risk assessments to evaluate third-party compliance with internal policies, contractual obligations, regulatory requirements, and industry standards.
  • Review contracts and security requirements to assess third-party obligations, risks, and control expectations.
  • Evaluate information security controls, data privacy controls, restricted environments, and secure workflow processes.
  • Review vulnerability management programs, vulnerability assessments, penetration testing results, and remediation activities.
  • Support ongoing monitoring activities, periodic reassessments, and third-party lifecycle management processes.
  • Investigate and assist with root cause analysis for control failures, operational losses, audit findings, and risk events.
  • Support issue management activities, including remediation tracking, validation of corrective actions, and issue closure.
  • Identify control breakdowns, process inefficiencies, and risk exposures and recommend corrective actions.
  • Support internal audits, external audits, regulatory examinations, and compliance reviews.
  • Monitor and assess compliance with applicable laws, regulations, standards, and industry best practices, including OCC Heightened Standards.
  • Build and maintain effective relationships with Third-Parties, Business Partners, Legal, Compliance, Enterprise Risk, Information Security, and Internal Audit.
  • Coordinate risk assessments, control reviews, issue remediation efforts, and governance activities across multiple stakeholders.
  • Maintain assessment, issue, exception, and risk documentation within Archer, Coupa, Power BI, and other governance tools.
  • Assist with regulatory change management activities and the implementation of new risk management requirements.
  • Participate in escalated supplier-related issues and support enterprise risk mitigation efforts.
  • Support special projects, acquisitions, strategic investments, and other risk management initiatives as required.
  • Executes on ERM Scenario Analysis risk management program.
  • Develop and manage product inventory and execute on ERM product risk review program.
  • May have additional responsibilities as assigned by LOB/Function leadership and Risk, including but not limited to:
    • Assistance with new government programs or special internal projects.
    • Assistance with new risk programs required by regulatory authorities or ERM.
    • Assistance with diligence, closing, and other matters relating to acquisitions and strategic investments.
MINIMUM KNOWLEDGE AND SKILLS REQUIRED:
  • Bachelor's degree or equivalent experience required (related field preferred).
  • Master's degree in relevant field preferred.
  • Recognized industry certifications such as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Technology Risk Advisor
Senior Technology Risk Advisor

Fifth Third Bank • Cincinnati (OH)

On-site
USD 70,000 - 100,000
W&AM Business Controls Senior Associate
W&AM Business Controls Senior Associate

Fifth Third Bank • Cincinnati (OH)

On-site
USD 70,000 - 95,000
Senior Third-Party Risk & Controls Analyst
Senior Third-Party Risk & Controls Analyst

Fifth Third • Cincinnati (OH), Northern (KY)

Hybrid
USD 80,000 - 110,000
Business Controls Manager - Commercial and Payments IT
Business Controls Manager - Commercial and Payments IT

Fifth Third Bank • Cincinnati (OH)

On-site
USD 120,000 - 170,000
Third-Party Business Controls Manager
Third-Party Business Controls Manager

Bank of America • Town of Charlotte (NY)

On-site
USD 90,000 - 120,000
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director
Commercial and Investment Bank, Controls – Third Party and Resiliency Risk & Control Manager - Executive Director

JPMorgan Chase & Co. • New York (NY)

On-site
USD 180,000 - 240,000
Senior Associate — Business Controls & Risk Analysis
Senior Associate — Business Controls & Risk Analysis

Fifth Third Bank • Cincinnati (OH)

On-site
USD 70,000 - 95,000
Third Party Risk Control Manager - Vice President
Third Party Risk Control Manager - Vice President

JPMorgan Chase & Co. • Chicago (IL)

On-site
USD 180,000 - 240,000
Senior Risk & Controls Analyst
Senior Risk & Controls Analyst

Fifth Third Bank • Cincinnati (OH)

On-site
USD 90,000 - 130,000
Associate, Technology Business Control & Risk Management
Associate, Technology Business Control & Risk Management

santander • Miami (FL)

On-site
USD 90,000 - 120,000