GRC Vendor Risk Analyst

Community Financial System, Inc.

City of Syracuse (NY)

On-site

USD 85,000 - 120,000

Full time

25 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Community Financial System, Inc. is seeking a role focused on third-party risk management and AI governance. You will administer the vendor due diligence portal, coordinate security questionnaires, and gather evidence for assessments.

The position involves reviewing SOC reports, identifying risks, and supporting governance decisions across information security and AI initiatives. Responsibilities include coordinating across business lines, tracking remediation, and maintaining records for audits

Responsibilities

  • Administer the third-party due diligence portal and keep content aligned with policies.
  • Coordinate and track information security questionnaires from customers and partners.
  • Gather responses and evidence from multiple stakeholders for assessments.
  • Review vendor security posture using SOC reports, policies and tests to assess risk.
  • Identify information security risks and remediation recommendations for governance decisions.
  • Support AI Governance activities for third-party AI solutions and monitoring.
  • Contribute to enhancements of risk processes, reports, workflows and metrics.
  • Assist identity and access governance efforts and related coordination.
  • Maintain organized assessment records and supporting documentation.
  • Support audits and examinations related to vendor management and governance.

Job description

Overview

At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration. Just as our employees are committed to helping our customers manage their finances, we're committed to our employees. After all, they make it happen for our customers every day. To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.

Responsibilities

Support CFSI's third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.

Essential Duties:

  • Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
  • Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
  • Partner with stakeholders across various business lines to gather responses and supporting evidence.
  • Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
  • Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
  • Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
  • Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
  • Support identity and access management governance, review, and related coordination activities as assigned.
  • Track remediation items, follow-up actions, and review outcomes to support timely resolution.
  • Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
  • Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
  • Perform other Information Security, third-party risk, and related governance duties as assigned by management.Ancillary Duties:As an integral member of CFSI, this position is responsible to provide assistance wherever
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Vendor Risk Analyst
GRC Vendor Risk Analyst

Benefit Plans Administrative Services, Inc. • City of Syracuse (NY)

On-site
USD 2,000 - 5,000
11 paid holidays
Medical, Vision & Dental insurance
401K with generous match
+2
GRC Vendor Risk Analyst
GRC Vendor Risk Analyst

OneGroup • City of Syracuse (NY)

On-site
USD 70,000 - 100,000
Health insurance
Vision & Dental insurance
401K with company match
+5
GRC Vendor Risk Analyst
GRC Vendor Risk Analyst

Community Bank, N.A. • City of Oneonta (NY)

On-site
USD 60,000 - 90,000
GRC Vendor Risk Analyst
GRC Vendor Risk Analyst

Community Bank, N.A. • City of Utica (NY)

On-site
USD 29,000 - 48,000
11 paid holidays
Paid vacation
Medical insurance
+5
GRC Vendor Risk Analyst
GRC Vendor Risk Analyst

Community Financial System, Inc. • City of Utica (NY), Town of Oneonta (NY)

On-site
USD 29,000 - 48,000
11 paid holidays
Paid vacation
Medical insurance
+5
GRC Vendor Risk Analyst: AI Governance & Security
GRC Vendor Risk Analyst: AI Governance & Security

Community Bank, N.A. • City of Oneonta (NY)

On-site
USD 60,000 - 90,000
Vendor Risk & AI Governance Analyst
Vendor Risk & AI Governance Analyst

OneGroup • City of Syracuse (NY)

On-site
USD <1,000
Health insurance
Vision & Dental insurance
401K with company match
+5
Vendor Risk & AI Governance Analyst
Vendor Risk & AI Governance Analyst

Benefit Plans Administrative Services, Inc. • City of Syracuse (NY)

On-site
USD 2,000 - 5,000
11 paid holidays
Medical, Vision & Dental insurance
401K with generous match
+2
Vendor Risk & AI Governance Analyst
Vendor Risk & AI Governance Analyst

Community Bank, N.A. • City of Utica (NY)

On-site
USD 29,000 - 48,000
11 paid holidays
Paid vacation
Medical insurance
+5
Vendor Risk & AI Governance Analyst
Vendor Risk & AI Governance Analyst

Community Financial System, Inc. • City of Utica (NY), Town of Oneonta (NY)

On-site
USD 29,000 - 48,000
11 paid holidays
Paid vacation
Medical insurance
+5