Risk Management Associate
Current• Revamped a third-party risk program worth $29 million to align with OCC regulations, resulting in a significant reduction in compliance issues and a more robust risk management framework• Audited approximately 130 vendors and products, updating profiles and discovering 58 additional vendors, improving vendor management visibility by 45%• Requested, analyzed, and compiled contracts (SoWs, License Agreements, MSAs) for 30+ vendors, ensuring compliance with FFIEC and OCC requirements and integrating 8 critical addendums to meet regulatory standards• Created comprehensive templates and standards for SOC reviews, Business Continuity, Incident Response, Disaster Recovery, Exit Plans, Financial reviews, and contract reviews, with criteria to trigger each review based on vendor risk ratings• Completed annual user access reviews across 15 roles to ensure least privilege access and mitigate security risks• Spearheaded a data classification and retention initiative, collaborating with 15+ data owners to establish and schedule retention periods for customer data, ensuring compliance with internal policies and regulatory requirements, reducing data storage costs by 60%• Analyzed and reviewed 40+ information security reports weekly to proactively monitor access surges, malware threats, changes in user data, and unauthorized account modifications