Third Party Risk Analyst

Suncoast Credit Union

Tampa (FL)

Remote

USD 60,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus program up to 12%
401K Matching up to 8%
Retirement Planning
Pay Increases based on Competency
Employee Loan Discounts
Flex Spending Accounts
Medical Coverage
Dental and Vision Coverage
Access to 4,000+ Gyms
Mental Health Resources
PTO Wellness Days
Short Term Disability Coverage
Long Term Disability Coverage
11 Paid Holidays
3 weeks Paid Time Off
4 weeks Paid Parental Leave
Birthday PTO
Paid Volunteer Hours
Degree Assistance up to $5,000 peryear

Job summary

Suncoast Credit Union is seeking a Third-Party Risk Analyst to support the TPRM program by performing risk assessments, maintaining vendor profiles, and assisting with monitoring and reporting. This is a full-time remote role, with residency required in the state of Florida, and collaboration with Legal, IT, Compliance, and Procurement.

Responsibilities include reviewing SOC reports and ISO certifications, maintaining vendor inventories, tracking remediation, and preparing evidence packages for

Qualifications

  • Bachelor’s degree in business, information systems, cybersecurity, risk management, or related field; a combination of work experience and training may substitute.
  • Minimum of 1 year of experience in risk, compliance, vendor management, procurement, or audit.

Responsibilities

  • Perform initial and periodic inherent/residual vendor risk assessments across security, privacy, operational, financial, and compliance domains.
  • Issue and track standardized questionnaires and review SOC reports, ISO certifications, insurance certificates, privacy policies, and BC/DR plans.
  • Maintain accurate vendor inventories, lifecycle statuses, findings, ratings, and remediation actions in the TPRM system of record.
  • Support contract reviews by identifying standard risk clauses (SLAs, data protection, audit rights) and escalating gaps to the director.
  • Monitor vendors using internal KPIs/KRIs and external data; trigger re-assessments when thresholds are met.
  • Prepare dashboards and evidence packages for audits, regulatory exams, and management committees.
  • Coordinate with stakeholders to track remediation and verify closure of issues by due dates.
  • Contribute to process documentation, playbooks, templates, and operational efficiency initiatives.
  • Maintain knowledge and understanding of current trends, laws, and issues affecting the area of expertise.
  • Complete annual compliance and info security training to understand employees' role in maintaining effective compliance and security programs.
  • Attend educational events to increase professional knowledge.

Skills

Analytical skills
Writing skills
Documentation
Confidentiality
Vendor contracts
Prioritization
Attention to detail
Problem solving
Communication
Regulatory compliance
CU systems knowledge
Risk frameworks
Excel/Sheets
GRC/TPRM tools

Education

Bachelor’s degree
1 year risk/compliance/vendor management/audit experience

Tools

Excel/Sheets
GRC/TPRM tools (Archer/ServiceNow/OneTrust/Prevalent/ProcessUnity)

Job description

Overview

Compensation: $60,000 - $90,000 based on experience and credentials


Location Type: Remote (Candidate must reside in the state of FL)


Position Type: Full Time


The Third-Party Risk Analyst supports the Third-Party Risk Management (TPRM) program by executing risk assessments, maintaining vendor profiles, and assisting with ongoing monitoring and reporting. The Analyst collaborates with business stakeholders, procurement, Information Security, Legal/OGC, Enterprise Risk Management (ERM), and Compliance to ensure vendor risks are identified, documented, and addressed per policy and regulatory expectations.


Responsibilities


  • Perform initial and periodic inherent/residual vendor risk assessments across security, privacy, operational, financial, and compliance domains

  • Issue and track standardized questionnaires and review SOC reports, ISO certifications, insurance certificates, privacy policies, and BC/DR plans

  • Maintain accurate vendor inventories, lifecycle statuses, findings, ratings, and remediation actions in the TPRM system of record

  • Support contract reviews by identifying standard risk clauses (SLAs, data protection, audit rights) and escalating gaps to the director

  • Monitor vendors using internal KPIs/KRIs and external data (financial health, adverse media); trigger re-assessments when thresholds are met

  • Prepare dashboards and evidence packages for audits, regulatory exams, and management committees

  • Coordinate with stakeholders to track remediation and verify closure of issues by due dates

  • Contribute to process documentation, playbooks, templates, and operational efficiency initiatives

  • Maintain knowledge and understanding of current trends, laws, and issues affecting the area of expertise

  • Complete annual compliance and info security training to understand employees' role in maintaining effective compliance and security programs

  • Attend educational events to increase professional knowledge


Qualifications


  • Bachelor’s degree in business, information systems, cybersecurity, risk management, or a related field (A comparable combination of work experience and training may be substituted for education requirements.)

  • Minimum of 1 year of experience in risk, compliance, vendor management, procurement, or audit

  • Working knowledge of risk frameworks (NIST CSF/800-53, ISO 27001, SOC 2) and industry regulations (e.g., GLBA, HIPAA, GDPR/CCPA)

  • Proficiency with Excel/Sheets; familiarity with GRC/TPRM tools (Archer, ServiceNow, OneTrust, Prevalent, ProcessUnity)

  • Strong analytical, writing, and documentation skills

  • Ability to maintain a high level of confidentiality

  • Experience with contracts, vendor SLAs, and financial services preferred

  • Ability to prioritize tasks by effectively managing competing and changing priorities to meet deadlines

  • Accurate, detail-oriented, and organized with task management

  • Ability to analyze and resolve difficult and often complex problems or situations

  • Strong written, verbal, and interpersonal communication skills to interact effectively with members, staff, vendors, and government regulators

  • Strong knowledge and understanding of credit union products, services, policies, and procedures

  • Strong knowledge and understanding of regulatory compliance

  • Strong knowledge and understanding of credit union computer systems and software applications required to perform job duties


Benefits


  • Financial Well-Being: Bonus Program up to 12%, 401K Matching up to 8%, Retirement Planning, Pay Increases based on Competency, Employee Loan Discounts, Flex Spending Accounts

  • Wellness: Medical Coverage, Dental and Vision Coverage, Access to 4,000+ Gyms, Mental Health Resources, PTO Wellness Days, Short Term and Long Term Disability Coverage

  • Work-Life Balance: 11 Paid Holidays, 3 weeks of Paid Time Off, 4 weeks of Paid Parental Leave, Birthday PTO

  • Community Involvement: Paid Volunteer Hours

  • Growth: Degree Assistance up to $5,000 per year


For more information, including additional benefits, please visit our benefits website at https://careers.suncoastcreditunion.com/benefits

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Third-Party Risk Analyst (Vendor Risk)
Remote Third-Party Risk Analyst (Vendor Risk)

Suncoast-Credit-Union • Tampa (FL)

On-site
USD 60,000 - 90,000
Bonus program
401K matching
Retirement planning
+5
Remote Third-Party Risk Analyst (GRC)
Remote Third-Party Risk Analyst (GRC)

Suncoast Credit Union • Tampa (FL)

Remote
USD 60,000 - 90,000
Bonus program up to 12%
401K Matching up to 8%
Retirement Planning
+16
Third Party Risk Sr Analyst
Third Party Risk Sr Analyst

Citizens • Johnston (RI)

Hybrid
USD 80,000 - 100,000
Third Party Risk Sr Analyst - Cybersecurity
Third Party Risk Sr Analyst - Cybersecurity

Citizens Bank • Rhode Island

Hybrid
USD 95,000 - 123,000
Vendor Risk Analyst 2
Vendor Risk Analyst 2

Summit Credit Union • Village of Cottage Grove (WI)

On-site
USD 75,000 - 95,000
Excellent health insurance options to支
401(k) with employer match
Generous paid time off
+4
Third Party Risk Sr Analyst
Third Party Risk Sr Analyst

Citizens Bank • Rhode Island

Hybrid
USD 80,000 - 100,000
Information Security Vendor Management Analyst
Information Security Vendor Management Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000
Vendor Risk Analyst 2 (Hybrid Role)
Vendor Risk Analyst 2 (Hybrid Role)

Summit Credit Union • Town of Cottage Grove (WI)

On-site
USD 80,000 - 110,000
Health insurance
401(k) with employer match
Generous paid time off
+3
Contract Analyst
Contract Analyst

Redstone Federal Credit Union • Huntsville (AL)

On-site
USD 65,000 - 90,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000