Associate Third-Party Risk Management (TPRM) Risk Analyst
Core
Support the day-to-day execution of the third-party risk lifecycle, applying established risk methodologies to standard engagements and maintaining accurate assessment records.
Role type
Associate Third-Party Risk Management (TPRM) Risk Analyst
Builds
Third-party risk assessments, remediation tracking, and status reporting for standard engagements
Domain
Risk Management / Compliance / Governance
Deliverable
dashboards & analysis
Required skills
Third-Party Risk Management (TPRM), Governance, Risk & Compliance (GRC), formula-based risk methodologies, data completeness checks, documentation analysis, SME coordination, risk remediation tracking, status reporting, data quality checks
Preferred skills
TPRM platform proficiency, control frameworks (NIST SP 800-53, ISO 27001, SOC 2, SIG Core/Lite, CAIQ), regulatory knowledge (DORA, GDPR, NIS2, FedRAMP, PCI-DSS, OCC, CCPA)
Technologies
Graphite Connect, Jira
Responsibilities
Apply formula-based inherent risk methodology and assign Criticality designations for standard third-party relationships; perform completeness and consistency checks on intake information and risk calculations; gather and maintain third-party documentation; route and track SME reviews; support remediation of identified gaps for Medium-Risk and Low-Risk engagements; compile assessment-level data and prepare routine status updates for internal stakeholders
Seniority
Mid-level, hands-on IC