THIRD PARTY RISK MANAGEMENT LEAD
Third Party Risk Management (TPRM) Lead is responsible for providing enterprise-wide third party risk management services, including defining, implementing, and maintaining a risk framework, operating model, policies, procedures, governance, and oversight programs for all lines of business and subsidiaries. CNB established the TPRM program as a second line function to manage third-party risk effectively and efficiently, aligned with its size and complexity. The lead ensures the program meets regulatory guidance, aligns with CNB's parent company, and incorporates necessary changes.
- Partner with the TPRM Program Manager to develop and execute an implementation plan, including the development of a risk framework, policies, and procedures.
- Conduct assessments on key controls and overall compliance, ensuring timeliness, completeness, and accuracy of risk assessments.
- Provide risk consulting to first-line third-party risk managers for complex arrangements.
- Develop risk analysis and reporting metrics for leadership, risk committees, the parent company, and regulators.
- Streamline processes for risk identification, assessment, control testing, and issue management.
- Lead continuous improvement initiatives for TPRM, working with stakeholders and analyzing reports to identify issues and root causes.
- Identify requirements for CNB’s GRC system to improve automation and efficiency.
- Review SSAE 18 reports for third parties, evaluate their adequacy, and assess impacts on CNB’s compliance programs.
- Coordinate resource allocation based on demand and expertise, including external resources as needed.
- Escalate issues to management as appropriate.
WHAT DO YOU NEED TO SUCCEED?
Required Qualifications*
- At least 7 years of experience in third-party risk management, assurance, oversight, or relevant audit or compliance roles.
- Minimum 4 years of experience in IT and cybersecurity risk and controls, including assessment scoping, providing credible challenges, and assurance testing.
- At least 4 years of experience working with GRC systems, including process improvements.
Additional Qualifications
- Deep knowledge of third-party and IT risk management processes and methodologies.
- Experience with third-party risk management/GRC systems.
- Experience evaluating contracts, including service agreements and licensing.
- Experience assessing cloud service arrangements.
- Knowledge of regulatory requirements such as OCC 2013-29, Fed SR 13-19, and others relevant to financial services.
- Industry-recognized third-party risk or vendor management certification (current or obtainable quickly).
- Excellent communication skills, both written and oral.
- Proficiency in Microsoft Office, especially Excel, PowerPoint, and SharePoint.
- Experience with reporting tools like Tableau, SQL, and SSRS is desirable.
Compensation: Starting at $111,408 - $189,738 annually, with potential bonuses or commissions, depending on skills and location.
Benefits and Perks: Comprehensive healthcare, 401(k) matching, tuition reimbursement, paid time off, health and family support programs, career development, resource groups, and more. More details available at
Benefits and Perks.
Founded in 1954, City National Bank is committed to integrity, community, and client relationships. A subsidiary of Royal Bank of Canada, we foster a dynamic culture. Learn more at
About Us.
INCLUSION AND EQUAL OPPORTUNITY EMPLOYMENT
We value diversity and are an equal opportunity employer. All qualified applicants will be considered without regard to race, color, religion, sexual orientation, gender identity, national origin, disability, veteran status, or other protected categories. Massachusetts law prohibits lie detector tests for employment decisions. Applications are accepted until the position is filled.