yoinka

Analyst, Third Party Risk Management

Intercontinental Exchange

Atlanta, Georgia; Jacksonville, FloridaFull TimeSenior
Sign in to applyVerified 1h ago
Location
Atlanta, Georgia; Jacksonville, Florida
Employment
Full Time
Work model
On-Site
Level
Senior
Posted
1h ago

Skills

CybersecurityServiceNow

About this role

Overview

Job Purpose The Third-Party Risk Management (TPRM) Risk Analyst II is responsible for supporting the end-to-end lifecycle management of third-party relationships and serving as a key point of contact for vendor risk assessments, due diligence reviews, and onboarding activities. This role evaluates the risks associated with third-party engagements and ensures compliance with the organization's Third-Party Risk Management Program, policies, and regulatory requirements.   The Analyst II will collaborate with business stakeholders, control functions, and external vendors to facilitate risk assessments, identify control gaps, monitor remediation activities, and support ongoing vendor oversight. This role plays a critical part in protecting the organization from operational, compliance, information security, financial, and reputational risks arising from third-party relationships.

Responsibilities

Third-Party Risk Assessments & Due Diligence Conduct risk assessments and due diligence reviews for new and existing third-party relationships in accordance with TPRM policies, procedures, and established timelines. Evaluate vendor controls, documentation, and risk factors across information security, operational resilience, compliance, financial, and business continuity domains. Identify risks, control gaps, and policy exceptions, and recommend appropriate mitigation strategies. Review supporting documentation including SOC reports, financial statements, business continuity plans, cybersecurity assessments, and regulatory compliance artifacts. Perform inherent risk analyses to determine assessment scope and due diligence requirements. Lifecycle Management Support vendor onboarding, ongoing monitoring, contract renewals, and termination activities throughout the vendor lifecycle. Partner with business relationship owners to ensure appropriate risk management activities are completed prior to vendor engagement and throughout the relationship. Track assessment findings, remediation plans, and exception management activities to completion. Monitor vendor performance and risk indicators and escalate emerging risks as appropriate. Stakeholder Engagement & Compliance Collaborate with business units, Legal, Procurement, Compliance, Information Security, Privacy, and Operational Risk teams to facilitate risk reviews and issue resolution. Provide guidance to stakeholders regarding TPRM requirements, processes, and regulatory expectations. Assist in maintaining compliance with applicable regulatory requirements and internal TPRM standards. Support internal and external audit examinations by gathering documentation, responding to inquiries, and tracking remediation efforts. Reporting & Program Support Maintain accurate and complete vendor records within TPRM systems and repositories. Perform data validation and quality assurance reviews to ensure the integrity of third-party risk information. Generate reports, metrics, and dashboards that provide visibility into assessment status, risk issues, remediation activities, and program performance. Assist with the continuous improvement of TPRM processes, procedures, templates, and governance practices. Support TPRM training and awareness initiatives across the organization. Other Responsibilities Serve as a primary contact for assigned business areas regarding third-party risk management activities. Participate in special projects and program initiatives as assigned. Occasional domestic travel may be required. Maintain a regular in-office presence in accordance with company policy.   Knowledge and Experience Bachelor's degree in Finance, Risk Management, Information Systems, Cybersecurity, or a related field. 3-5+ years of experience in Third-Party Risk Management, Vendor Risk Management, Operational Risk, Information Security Risk, Audit, Compliance, or a related risk discipline. Experience conducting risk assessments, due diligence reviews, and control evaluations. Working knowledge of

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Analyst, Third Party Risk Management at Intercontinental Exchange, Atlanta, Georgia; Jacksonville, Florida | Yoinka