Senior Vendor Risk Analyst
Listed on 2026-01-12
-
Security
Cybersecurity, Information Security, Data Security
Rochdale is an industry leader providing customized strategy and risk management services in the financial industry. Our industry consulting expertise and cutting‑edge software, apogee iQ, is helping industry players navigate the complex and ever‑changing risks present in today’s marketplace. Built with modern features and functions coupled with intelligent module integration, apogee iQ is customized to specifically address the needs of the credit union industry.
With this unique, integrated approach to software and services, Rochdale transforms risk and compliance burdens into a competitive advantage.
Rochdale believes that its people are the foundation of success. Our objective is to recruit and retain exceptional people who do exceptional work. Our values serve as the cornerstone for creating a culture of engagement and inclusion. A culture which values different perspectives and the uniqueness of every person. We value those with a passion to serve, selflessness, the courage to speak‑up, that celebrate others, exhibit a thirst for knowledge and innovation, and exhibit the type of behaviors others can rely on.
On most days, working at Rochdale feels more like going to work with a big family. We are here to do a great job and have a good time while doing it! We value a good sense of humor, desire to innovate, and a “we’re‑in‑this‑together” attitude. And while we’re driven to do great work, we also value work/life balance. We are passionate about this work, but we are also passionate about each other.
We believe the relationships we build with clients are only as strong as those we maintain with each other. Finally, innovation is a core value as new ideas are not only welcome, but expected, from everyone.
The Senior Vendor Risk Consultant plays a pivotal role in assisting our clients in safeguarding their organization by assessing, mitigating, and monitoring risks associated with third‑party vendors. This individual will conduct thorough due diligence on potential and existing vendors, ensuring their compliance with security, operational, financial, and regulatory standards. The Senior Vendor Risk Consultant will work collaboratively with clients to develop and implement a robust vendor risk management program and to document initial and ongoing risk assessments of vendors.
Job Responsibilities- Risk Assessment:
Perform initial and ongoing risk assessments of vendors, identifying potential areas of vulnerability across various risk domains (e.g., cybersecurity, financial stability, operational resilience, regulatory compliance). - Due Diligence Evaluation:
Conduct comprehensive due diligence reviews, including analysis of financial statements, SOC reports, policies and procedures, penetration tests, business continuity plans, and other relevant documentation. - Policy and Procedure Development:
Contribute to the creation and refinement of vendor risk management policies, procedures, and standards, ensuring alignment with industry best practices and regulatory requirements. - Vendor Contract Review:
Collaborate with clients to review vendor contracts, identifying potential risks and ensuring appropriate risk mitigation language is included. - Monitoring and Reporting:
Establish ongoing monitoring mechanisms to track vendor performance, identify changes in risk profiles, and elevate potential issues promptly to clients. Assist clients in developing clear risk reports to management. - Training and Awareness:
Provide training to clients on vendor risk management principles and processes. - Relationship Management:
Build and maintain effective relationships with clients, facilitating communication and collaboration on risk mitigation strategies. - Team Supervisor:
Assist the Vice President, Compliance, with day‑to‑day supervision of the Vendor Risk Management team.
- Education:
Bachelor’s degree in Business, Risk Management, Information Security, or a related field. - Experience:
Minimum 5 years of experience at a financial institution in a risk management, third‑party vendor management, regulatory compliance role, or a related field. Experience supervising a team. - Certifications:
Banking…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).