×
Register Here to Apply for Jobs or Post Jobs. X

Senior Risk Analyst, Privacy & Third-Party Risk

Job in Baltimore, Anne Arundel County, Maryland, 21276, USA
Listing for: T. Rowe Price
Full Time position
Listed on 2026-03-01
Job specializations:
  • IT/Tech
    Data Security, Cybersecurity, Information Security, IT Consultant
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below

At T. Rowe Price, we identify and actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi‑asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.

We believe doing the right thing for our clients and our associates is good business. With a career at the firm, you can expect opportunities to create real impact at work and in your community. You’ll enjoy resources to support your career path, as well as compensation, benefits, and flexibility to enrich your life. Here, you’ll find a collaborative culture that respects and values differences and colleagues who share a spirit of generosity.

Join us for the opportunity to grow and make a difference in ways that matter to you.

Role Summary

The Senior Risk Analyst – Privacy & Third Party Risk is a Second Line of Defense (2

LoD) role and a member of the Global Privacy Office (GPO) and Third Party Risk Management (TPRM) function. The role provides independent risk oversight, effective challenge, and assurance over first‑line activities and outsourced TPRM services, operating with minimal supervision and a high degree of professional judgment.

This position is expected to independently manage complex risk assessments, lead oversight activities, identify emerging risk themes, and deliver clear, actionable insights to senior stakeholders and governance committees.

Responsibilities Privacy Risk – Global Privacy Office
  • Independently provide 2

    LoD oversight of privacy risks arising from first-line business activities and serve as a subject matter resource on privacy risk matters.
  • Lead review and challenge of Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments.
  • Evaluate the design and operating effectiveness of privacy controls and recommend enhancements aligned with regulatory expectations and risk appetite.
  • Independently review privacy incidents, including root cause analyses and remediation plans.
  • Provide technical expertise and support the implementation of privacy and data protection processes, controls, and procedures based on enterprise‑wide guidance issued by the Global Privacy Office.
  • Support the process of Privacy and Security by Design reviews, in particular, where they relate to the development and deployment of new technologies. This includes reviewing technical implementation details and design documentation for new systems and features, and providing guidance on improving privacy features in those systems.
  • Collaborate with technology and security teams to embed privacy controls into the architecture of products and services, including providing advice and best practices to protect and mitigate privacy risks.
  • Identify opportunities to enhance the Global Privacy Office’s technical capabilities, develop, test and work with technology teams to deploy such capabilities.
  • Support the maintenance of the firm’s required privacy compliance documentation (e.g., Records of Processing Activities, Transfer Impact Assessments, procedures, guides, training, Share Point sites).
  • Support the execution of the privacy compliance monitoring program.
Third‑Party Risk Management
  • Perform quality assurance and effective challenge of third‑party risk outputs produced by external service providers and first‑line stakeholders.
  • Monitor adherence to SLAs, KPIs, and contractual obligations of outsourced TPRM providers and elevate deficiencies as appropriate.
  • Identify systemic control gaps, concentration risk, and emerging third‑party risk trends across the vendor population.
  • Support third party cyber and information security risk review activities.
  • Contribute to the ongoing development of fourth‑party risk governance and oversight practices.
  • Identify opportunities to enhance TRPM’s technical capabilities, develop, test and work with technology teams to deploy such…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary