It Starts With Our Employees FourLeaf's ultimate goal is to provide the best-in-class member and employee experience, and it all begins with two things: hiring incredible people and giving them a great place to work. What You’ll Do As part of the 2LOD under Enterprise Risk Management, the Senior Manager of Third-Party Risk Management (TPRM) reports to the Vice President of Enterprise Risk Management and is responsible for the day-to-day oversight and development of the third-party risk program and analyst team. In collaboration with leadership, the Senior Manager develops, implements, and executes on the Third-Party risk program ensuring robust assessment and monitoring practices for the Credit Union’s portfolio of third-party relationships. Core Contributions Directly manage the third-party risk analyst team. Foster a team driven by service and efficiency through leadership and training, ensuring deliverables are accurate, timely and consistent with the established Risk program and strategic direction. Develop and execute a plan for individual and team education. Supervise activities to ensure adherence to policy, procedures, and regulatory requirements. Collaborate with business leads, CUSO’s, external third parties, and internal subject matter experts including but not limited to Legal, Privacy, Information Security, and Compliance to conduct new and annual third-party risk assessments and performance reviews, ensuring business units understand how to measure and manage the risk associated with third-party relationships. Prepare, develop, implement, manage, and maintain the credit unions’ risk Third-Party Risk framework including associated policies and procedures. Supports the Business Continuity Management team by providing valuable insight into the credit union’s third-party risk profile and dependences for testing preparation and incident management. Supports business units and leadership across the organization with vendor issues and correspondence. Lead the TPRM team in the identification and evaluation of risks and controls associated the Third Parties such as cyber, financial, strategic, reputational, operational, and regulatory risk. Ensures the timely monitoring, maintenance, communication and record retention of all third-party risk assessments requirements (including contracts and due diligence information). Ongoing monitoring, measuring and tracking of Third-Party key risk indicators (KRI’s) for trends and emerging risks. Works closely with leadership, business units, and external parties, to communicate risk-related issues with remediation recommendations. Act as program lead in the development and management of Third-Party risk systems and support tools such as the GRC. Prepare and present risk reports to senior management and the Enterprise Risk Management Committee highlighting key risk exposure, trends, and mitigation actions. Manage the preparation of the monthly, quarterly, annual, and ad hoc Third-Party Risk reports and presentations for Senior Management, Enterprise Risk Management Committee and the Board. Act as the key support contact for the Credit Union’s exams, internal, external audits for Third-Party Risk matters. Stay up to date on applicable regulations to ensure the organization's Third-Party risk management and practices align with regulatory requirements. Continuously monitor industry developments, best practices, and emerging risk management techniques to enhance the organization's third-party risk management capabilities. Educate and train employees on third-party risk management principles, policies, and procedures to enhance risk awareness and promote a risk-aware culture. Assets You Will Bring Bachelor’s Degree or equivalent work experience. Field of study: Business Administration, Risk Management, Information Systems, or related field. 10+ Years Third-Party Risk, Technology Risk or Risk Management. 5+ years of people experience management. Strong knowledge of vendor management practices, technology risk, SOC controls contract language, and contract management. Strong knowledge of Third Party and Technology risk management frameworks, methodologies, and tools. Certifications: Certified Third-Party Risk Professional, Certified Regulatory Vendor Program Manager, or equivalent is desired; or the willingness to obtain certifications within a reasonable period. The expected salary for this position is $117,456.00 - $176,183.00 annually. ( FourLeaf Federal Credit Union offers a comprehensive benefits package, including medical, dental, and vision coverage; life and disability insurance; voluntary benefit programs; a 401(k) plan with employer match; reimbursement and wellness programs; and an annual performance-based bonus. ) In addition to the salary or hourly rate listed above there may be other compensation & benefits available. #LI-Remote What Sets Us Apart? In addition to our comprehensive benefits, we invest in employee connection and well-being through: Competitive 401(k) Tuition and fitness reimbursement programs Flexible work options Volunteer opportunities Executive “Water Cooler Chats” Clubs, sports, and social events Food truck days ….and more! Who is FourLeaf? FourLeaf Federal Credit Union (FourLeaf) has been committed to the financial well-being of our members for over 80 years. Through our full range of competitive savings and loan products, you can trust us in every step of your financial journey. From applying for a credit card to closing on your mortgage to opening your child’s first savings account, FourLeaf is here to help you reach your financial goals. We are proud to be an award-winning place to work! Some of our recent recognitions include Certified Great Place to Work 2024-2025, America’s Greatest Midsize Workplaces 2025, and Fortune’s Best Workplaces in Financial Services & Insurance 2024. As a credit union, our vision is to enrich the lives of our members, employees, and communities. Since 2002, we have been an integral community partner through our charitable giving and community development programs in New York and beyond.
Security Analyst, Third-Party Ecosystem Risk Management
Plaid
Third Party Risk Management Lead
Sungrow
Director, Third-Party Risk Management and Technical Information Security Lead
Pfizer
Director, Third-Party Risk Management and Technical Information Security Lead
Pfizer
Third-Party Risk Analyst
OpenRouter
Third Party Risk Director
Candidate Experience site