Third-Party Risk Management (TPRM) Risk Analyst
MongoDB
Job Description
<h3>Description:</h3> <p>The key objectives of the TPRM Program are to: </p> <ul> <li>Assess the risk of third-party relationships which drive the rigor of risk management activities both during the third-party onboarding and ongoing… ## What you'll do </h3> <p>Risk Assessment Validation & Remediation</p> <ul> <li>Strong experience in managing the full lifecycle of a Third Party from Sourcing to Payment</li> <li>Independently validate inherent risk rating and Criticality designation for all third-party relationships with minimal intervention while proactively flagging any concerns to the TPRM Manager</li> <li>Review third-party provided information and documentation for all third-party relationships in accordance with TPRM assessment methodology, proactively flagging any gaps or follow-up questions</li> <li>Lead communication to third parties to remediate gaps for all High Risk and Critical third-party relationships, including documentation of remediation plans</li> </ul> <p>Reporting & Trend Analysis</p> <ul> <li>Independently lead portfolio-level trend analysis, build leadership- and audit-facing reporting, and translate findings into risk-based recommendations</li> </ul> <p>Oversight & Periodic Review</p> <ul> <li>Lead identification, tracking, and review of the adequacy of completion of SME reviews and assessments for all third-party relationships at onboarding with minimal oversight from manager</li> <li>Independently provide oversight of the periodic review process, including identification and escalation of higher-risk findings or gaps</li> </ul> <p>Mentorship & Stakeholder Support</p> <ul> <li>Mentor the Associate TPRM Risk Analyst and support the TPRM Manager in audit and customer discussions</li> </ul> <h3> ## What you'll bring </h3> <p>Experience & Education:</p> <ul> <li>7-10 years of experience in Third-Party Risk Management (TPRM) or Governance, Risk & Compliance (GRC)</li> <li>Demonstrated experience performing substantive risk assessments and applying formula-based or quantitative risk methodologies</li> <li>Bachelor’s degree in a relevant field (Cybersecurity, Business, Information Systems)</li> <li>Certifications (at least one required): CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), CTPRP (Certified Third-Party Risk Professional), or CRVPM (Certified Regulatory Vendor Program Manager) up to or in process of Level V</li> </ul> <p>Technical & Operational Proficiency:</p> <ul> <li>Proficiency with a well established TPRM platform, including the ability to interpret intake data, Data Level classifications, and inherent risk scoring logic</li> <li>Deep operational understanding of standard control frameworks ( ### Nist Sp 800 …
Requirements
See the listing for full requirements.
Related jobs
More roles you might like
The worldwide data management software market is massive, forecasted to grow from approximately $82 billion in 2023 to approximately $137 billion in 2027. ## What you'll do have gained a deep understanding of MongoDB and its partner ecosystem and completed New Hire Training -…
The data management software market is transforming how organisations build and run applications. MongoDB is the leading developer data platform and the first database provider to IPO in more than 20 years. ## What you'll bring Excellent customer communication, prioritisation,…
MongoDB Technical Services Engineers use their exceptional problem solving and customer service skills, along with their deep technical experience, to advise customers and to solve their complex MongoDB problems. ## What you'll do also be responsible for mentoring and ramping …