Third Party Risk Analyst
CurrentEnsure all new vendor engagements that involve the vendor handling, processing, storing, or accessing sensitive information are reviewed to provide assurance the vendor has appropriate controls in place to protect information prior to the business signing a contract.• Perform periodic reviews of all existing active vendor engagements.• Ensure accurate vendor risk ratings are completed, validated and all required vendor artifacts and documentation is collected appropriately.• Maintain a vendor repository for all vendor engagements that handle, process, store, or access sensitive information.• Recommend systems and process enhancements to reduce processing times and improve accuracy.• Provides oversight of compliance, audit and regulatory reviews and acts as the primary point of contact for management, responsible for providing regulatory and information security expertise.• Ensure that appropriate security controls are in place and that key regulatory timelines and required documents are tested• Document and report audit findings to management of affected areas• Perform risk analysis to determine level of risk and recommend action(s) to mitigate along with contract and Third Party Risk reviews, including SSAE16 and vendor assessment