Third-Party Risk Management (TPRM) Risk Analyst
MongoDB
- Location
- Dublin, Ireland
- Employment
- Full Time
- Work model
- Hybrid
- Level
- Senior
- H-1B history
- 30 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
Description
The key objectives of the TPRM Program are to:
• Assess the risk of third-party relationships which drive the rigor of risk management activities both during the third-party onboarding and ongoing monitoring lifecycle phases using the TPRM Program’s formula-based risk methodology
• Act as a liaison across key internal stakeholder teams (Procurement, Legal, Enterprise Security and the Business) to ensure clear and accurate communication of third-party risks aligned to risk management activities in order to complete risk assessments in a timely manner
• Identify TPRM program enhancements aimed at the effective and efficient management of third-party risk in order to support Business strategic initiatives
Reporting to the TPRM Manager, the TPRM Risk Analyst will be expected to have strong experience operating in a risk-based, data-driven model that will accommodate the business’s need to onboard vendors in a shortened timeframe, all while managing expectations and heightened scrutiny of both internal and external stakeholders including our customers. The TPRM Risk Analyst will understand and clearly communicate not only the “What” but also the “Why” in terms of third-party risk management activities in order to support efficient and effective third-party risk management as MongoDB continues to grow. This role requires substantial ability to interpret data and apply risk knowledge and judgment as the TPRM Risk Analyst manages a complex ecosystem of data, regulations, and stakeholder relationships while continuously identifying areas of enhancement to support effective third-party risk management.
We are looking to speak to candidates who are based in Dublin for our hybrid working model.
Responsibilities
Risk Assessment Validation & Remediation
• Strong experience in managing the full lifecycle of a Third Party from Sourcing to Payment
• Independently validate inherent risk rating and Criticality designation for all third-party relationships with minimal intervention while proactively flagging any concerns to the TPRM Manager
• Review third-party provided information and documentation for all third-party relationships in accordance with TPRM assessment methodology, proactively flagging any gaps or follow-up questions
• Lead communication to third parties to remediate gaps for all High Risk and Critical third-party relationships, including documentation of remediation plans
Reporting & Trend Analysis
• Independently lead portfolio-level trend analysis, build leadership- and audit-facing reporting, and translate findings into risk-based recommendations
Oversight & Periodic Review
• Lead identification, tracking, and review of the adequacy of completion of SME reviews and assessments for all third-party relationships at onboarding with minimal oversight from manager
• Independently provide oversight of the periodic review process, including identification and escalation of higher-risk findings or gaps
Mentorship & Stakeholder Support
• Mentor the Associate TPRM Risk Analyst and support the TPRM Manager in audit and customer discussions
Experience & Education
• 7-10 years of experience in Third-Party Risk Management (TPRM) or Governance, Risk & Compliance (GRC)
• Demonstrated experience performing substantive risk assessments and applying formula-based or quantitative risk methodologies
• Bachelor’s degree in a relevant field (Cybersecurity, Business, Information Systems)
• Certifications (at least one required): CRISC (Certified in Risk and Information Systems Control), CISM (Certified Information Security Manager), CTPRP (Certified Third-Party Risk Professional), or CRVPM (Certified Regulatory Vendor Program Manager) up to