Associate Director, Third Party Risk Governance & Framework
- Hiring from
- United States
- Work type
- Hybrid
- Posted
- Oct 2, 2026
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Impact You Will Have in This Role
As part of Operational Risk & Resilience (ORR), the Associate Director, Third Party Risk Governance & Framework strengthens DTCC's second line of defense (2LoD) by managing and implementing the design, governance, and enhancements of the Third Party Risk framework. The role defines how Third Party Risk is managed across DTCC through policies, standards, methodologies, regulatory alignment, resilience integration, lifecycle requirements, and program governance. In this capacity, you will help strengthen DTCC's Third Party Risk program, control environment, and risk culture.
Primary Responsibilities
Third Party Risk Framework & Lifecycle Governance
- Maintain Third Party Risk policies, standards, procedures, methodologies, controls, and governance documentation.
- Define risk-based lifecycle requirements across third-party identification, assessment, management, monitoring, contingency planning, and termination.
- Drive framework enhancements and work with first line of defense (1LoD) Third Party Management (TPM) to improve program effectiveness, training, operational clarity, regulatory alignment, and responsiveness to emerging risks.
Risk Taxonomy, Methodology & Control Integration
- Maintain Third Party Risk taxonomies, risk categories, classification criteria, tiering standards, and criticality methodologies.
- Promote consistent application of segmentation, assessment, monitoring, oversight, and reporting standards across the enterprise.
- Integrate Third Party Risk expectations into enterprise risk processes, including RCSAs, CPRAs, risk scenarios, control expectations, and assessment methodologies.
Regulatory Alignment & Examination Support
- Maintain awareness of applicable regulatory expectations and translate changes into policy, standards, control, and governance enhancements.
- Partner with Compliance, Legal, Internal Audit, TPM, and business stakeholders to support regulatory examinations, remediation activities, and ongoing supervisory readiness.
Critical Third Party, Resilience & Dependency Governance
- Establish governance requirements for critical third parties, including enhanced due diligence, ongoing monitoring, resilience, contingency planning, substitutability, and exit strategies.
- Partner with Business Continuity and Operational Resilience teams to embed third-party resilience and dependency considerations into lifecycle and governance decisions.
Specialized Third Party Risk Governance
- Establish enterprise requirements for specialized third-party risk areas, including third party provider types (e.g. technology, market data, staff augmentation, exchange and trading venues, financial market infrastructure, clearing brokers), CriticalPlus+ designations and contingent worker risk management.
- Define governance controls for onboarding, access, tenure, concentration risk, privileged access, role dependency, supervisor accountability, and regulatory compliance.
Qualifications
- 8-10 years of experience in Third Party Risk Management, Operational Risk, Enterprise Risk Management, Compliance, Regulatory Affairs, or related disciplines.
- Bachelor's degree preferred or equivalent experience.
- Strong understanding of Third Party Risk frameworks, cyber, resiliency, compliance, privacy, governance models, lifecycle requirements, and regulatory expectations.
- Experience developing or enhancing policies, standards, controls, and risk frameworks in highly regulated environments.
- Financial services, market infrastructure, banking, or regulatory experience preferred.
Talents Needed for Success
- Ability to translate complex regulatory expectations into practical, scalable, and risk-based governance requirements.
- Sound judgement and risk-based decision making.
- Strong knowledge of risk taxonomy, classification, tiering, segmentation, and assessment methodologies.
- Experience supporting regulatory examinations, remediation programs, and framework enhancement initiatives.
- Executive communication, stakeholder management, influencing, strategic thinking, and program execution skills.
- Collaborative, proactive, and focused on continuous improvement, risk reduction, and regulatory excellence.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).