The Sr. Risk Analyst will assist with the day-to-day management of the second line of defense Third Party Risk Management (TPRM) program. The Sr. Risk Analyst plays a critical role at Varo and will be responsible for evaluating and managing third-party risks and supporting the TPRM Manager with additional program activities. The Sr. Risk Analyst will carry out ongoing reviews of all third parties, identify operational risks and requirements, and challenge and monitor third parties’ ability to perform within risk appetite. This role will partner with the first line of defense on the execution of program deliverables.
What you’ll be doing
Enhance Varo’s Third-Party Risk Management Framework to ensure it meets regulatory expectations and Varo’s risk appetiteDefine and meet SLA expectations for Third Party Risk Assessments, vendor onboarding, proof of concept periods, and retirementOversee the implementation and adherence to Varo’s policy and procedures regarding third-party risk management, including training internal departments on requirements and managing third-party service providers/vendors on an ongoing basisEnhance fourth-party oversight including the performance of risk assessments and identification of controlsCollaborate with internal stakeholders to establish and maintain a comprehensive inventory of third-party relationships, applications, and associated risksWork closely with all Varo departments and internal risk groups that are seeking third-party services/vendor relationships to ensure that appropriate risk assessment and due diligence are conducted for any new third-party servicePrepare and present comprehensive reports and recommendations to senior management regarding third-party risk exposures and mitigation strategies through performance assessmentsTrack compliance with Varo’s third-party policies and procedures, analyze and report on any gaps, and provide recommendations for remediation of such gapsSupport the enhancement of the Governance Risk and Compliance third-party risk management platform covering the life cycle of third-party relationships including on-boarding/off-boarding of third parties and management of proof of concept periodsYou’ll bring the following required skills and experiences
3-5 years of third-party risk management experience with a financial institution, a fintech company, or a provider to the financial services business sectorRisk assessment and due diligence experience with a particular focus on identifying risks and identifying and implementing solutions to remediate these gapsAbility to conduct and report on testing of applicable controls that are in place regarding third-party service providersExperience designing systems and workflows that support effective prioritization of monitoring Third Parties and work for the teamExperience assisting with a continually evolving risk-based monitoring program with a focus on automation and scalabilityExperience working within a diverse environment with a wide range of cross-functional stakeholdersExperience managing multiple projects in a fast-paced, high-volume environmentFamiliarity in dealing with regulators, particularly OCC, FDIC, and Federal Reserve Board examinersPrevious experience reporting to senior management, the Board, and/or Committees of the Board on the status of third-party risk management effortsExperience with RSA Archer or similar GRC toolCTPRP and/or CRISC certifications are highly preferred#MidSenior