Mgr, Third-Party Risk Management

BCU

Vernon Hills (IL)

On-site

USD 120,000 - 180,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

BCU seeks a seasoned leader to oversee and enhance its Third-Party Risk Management (TPRM) program in Vernon Hills, ensuring regulatory readiness and governance. You will own onboarding, due diligence, ongoing monitoring, contract review, and offboarding for third parties, while driving continuous program improvements.

You will collaborate with Finance, IT, Legal, and Procurement to assess controls, review SOC reports, and report metrics to executives.

Qualifications

  • Bachelor’s degree required in Business, Finance, Risk Management, Information Systems, Cybersecurity, Accounting, or related field.
  • 5 years of experience in Third-Party Risk Management, Vendor Management, Enterprise Risk Management, Information Security, or related discipline.
  • Strong understanding of third-party risk lifecycle management (onboarding, due diligence, risk assessments, monitoring, issue management, offboarding).
  • Experience evaluating vendor documentation including SOC 1 and SOC 2 reports, cybersecurity assessments, business continuity plans, financial statements, and compliance certifications.
  • Working knowledge of regulatory expectations governing financial institutions and third-party relationships.
  • Experience using Governance, Risk, and Compliance (GRC) platforms and vendor management systems.
  • Strong analytical, organizational, project management, and communication skills.
  • Ability to influence stakeholders and communicate risk to technical and non-technical audiences.

Responsibilities

  • Manage BCU’s Third-Party Risk Management Program, including policies, standards, procedures, and governance frameworks.
  • Maintain and enhance risk-based methodologies for vendor segmentation, inherent risk assessments, due diligence, monitoring, and issue management.
  • Prepare and deliver risk reporting, metrics, and dashboards to executives and audit stakeholders.
  • Support regulatory examinations, internal audits, and external reviews related to third-party risk management.
  • Evaluate vendor controls and supporting documentation with cross-functional teams (Finance, IT, Legal, Procurement).
  • Identify control gaps, document findings, and partner with business owners to implement mitigations.
  • Oversee ongoing monitoring activities for critical and high-risk third parties.
  • Maintain accurate inventories, risk ratings, and assessment records.

Skills

Vendor risk lifecycle
GRC platforms
Regulatory communication
Stakeholder influence
Risk reporting

Education

Bachelor’s degree in Business, Finance, Risk Management, Information Systems, Cybersecurity, Accounting, or related field

Tools

GRC platforms
Vendor management systems
SOC reports (SOC 1, SOC 2)

Job description

SALARY

This position has a base salary range of $120,000.00 - $180,000.00 USD Annual. This range represents the expected base salary range for this position. The actual salary may vary based upon several factors including, but not limited to, relevant skills/experience and time in the role.

SUMMARY

This role is responsible for overseeing and enhancing BCU's Third-Party Risk Management (TPRM) Program. This role leads the assessment, monitoring, governance, and reporting of risks associated with vendors and other third-party relationships, ensuring compliance with regulatory expectations and alignment with BCU's enterprise risk appetite.

The position owns the end-to-end third-party risk process, including onboarding, risk tiering, due diligence, contract review, ongoing monitoring, issue management, and offboarding. This role is also responsible for program governance, reporting, regulatory readiness, and continuous improvement initiatives designed to strengthen BCU's third-party risk framework.

ROLE AND RESPONSIBILITIES
  • Manage BCU's Third-Party Risk Management Program, including policies, standards, procedures, and governance frameworks ensuring alignment with applicable regulatory requirements, including NCUA, FFIEC, CFPB, GLBA, NIST, and other relevant industry guidance.
  • Maintain and make recommendations to enhance risk-based methodologies for vendor segmentation, inherent risk assessments, due diligence, ongoing monitoring, and issue management.
  • Prepare and deliver risk reporting, metrics, and dashboards to executive leadership, management committees, and audit stakeholders.
  • Support regulatory examinations, internal audits, and external reviews related to third-party risk management activities.
  • With the assistance of advisors in Finance, Business Resiliency, Information Technology, Information Security, Procurement and Legal, evaluating vendor controls, practices, and supporting documentation, including SOC reports, cybersecurity assessments, business continuity plans, financial statements, insurance coverage, and compliance evidence.
  • Identify control gaps and risk exposures, document findings, and partner with business owners to create mitigation strategies.
  • Manage ongoing monitoring activities for critical and high-risk third parties.
  • Maintain accurate third-party inventories, risk ratings, documentation, and assessment records.
  • Perform basis system administration and optimization of the vendor management platform, including workflow configuration, reporting, user support, and data quality oversight.
  • Identify opportunities to automate processes, improve efficiency, and enhance program maturity.
  • Maintain procedures, templates, assessment tools, and training materials supporting the TPRM program.
QUALIFICATIONS AND EDUCATION REQUIREMENTS
  • Bachelor’s degree in Business, Finance, Risk Management, Information Systems, Cybersecurity, Accounting, or a related field.
  • 5 years of experience in Third-Party Risk Management, Vendor Management, Enterprise Risk Management, Information Security, or a related discipline.
  • Strong understanding of third-party risk lifecycle management, including onboarding, due diligence, risk assessments, ongoing monitoring, issue management, contract review, and offboarding.
  • Experience evaluating vendor documentation, including SOC 1 and SOC 2 reports, cybersecurity assessments, business continuity plans, financial statements, and compliance certifications.
  • Working knowledge of regulatory expectations governing financial institutions and third-party relationships.
  • Experience using Governance, Risk, and Compliance (GRC) platforms and vendor management systems.
  • Strong analytical, organizational, project management, and communication skills.
  • Ability to influence stakeholders and effectively communicate risk to both technical and non-technical audiences.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Third-Party Risk Management Analyst
Senior Third-Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 150,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

Intercontinental Exchange Holdings, Inc. • Atlanta (GA)

On-site
USD 80,000 - 120,000
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE Clear Europe Limited • Northern (KY)

Hybrid
USD 90,000 - 120,000
Third Party Risk Management Analyst
Third Party Risk Management Analyst

Phyton Talent Advisors • Red Bank (NJ)

On-site
USD 90,000 - 130,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000
Senior Consultant, Third Party Risk Management
Senior Consultant, Third Party Risk Management

Northern Trust • Chicago (IL)

On-site
USD 83,100 - 141,300
Analyst, Third Party Risk Management
Analyst, Third Party Risk Management

ICE • Atlanta (GA)

On-site
USD 85,000 - 120,000
Third Party Risk Manager
Third Party Risk Manager

ADP, Inc. • Elgin (IL)

On-site
USD 121,000 - 151,000
Long-term Disability Insurance
Life Insurance
401(k) match
+5
Senior Third Party Risk Analyst - Governance (Hybrid)
Senior Third Party Risk Analyst - Governance (Hybrid)

BankUnited • Town of Florida (NY)

On-site
USD 100,000 - 140,000
Third-Party Security Manager
Third-Party Security Manager

Guild Mortgage • United States

On-site
USD 95,000 - 136,000
Medical insurance
Dental insurance
Vision insurance
+4