Third Party & Vendor Risk Specialist
Albuquerque, NM Risk
Job Type
Full-time
Description

Summary

Administers Sunward’s third-party / vendor risk management program, as an individual contributor within the enterprise risk function, providing independent second-line oversight of vendor relationships and ensuring consistent, compliant execution across the vendor risk lifecycle.

The role supports and executes the third-party risk management lifecycle — vendor inventory and tiering, risk-based due diligence, ongoing monitoring, fourth party and concentration risk, and contract/SLA risk review — partnering closely with vendor relationship owners (VROs), Legal, Information Security, and Compliance. It coordinates day-to-day program activities across business units, advises stakeholders on program requirements, ensures adherence to established procedures, and escalates concerns appropriately.

Operating with general guidance within established policy, the Third Party & Vendor Risk Specialist resolves routine to moderately complex issues within authority, and escalates higher-risk, ambiguous, or cross-departmental situations to the Manager, Enterprise Risk.

Essential Functions:

Third-Party / Vendor Risk Management

  • Maintains Sunward’s third-party risk management policy and program, including program documentation; ensures activities are performed and records retained in compliance with applicable laws, regulations, and Sunward policies, escalating concerns as necessary.
  • Maintains a complete vendor inventory and risk tiering framework; conducts risk-based due diligence at onboarding and through ongoing monitoring cadences by tier, including SOC report review, financial-condition tracking, cybersecurity posture, and adverse-news monitoring, and maintains the resulting risk scores and registers.
  • Coordinates vendor offboarding and contract termination activities, including confirmation of data return or destruction, access revocation, and closeout documentation, to ensure risks are appropriately managed through the end of the vendor relationship.
  • Supports assessment of fourth party (subcontractor) and concentration risk, helping identify key dependencies and potential points of failure across the vendor portfolio, and escalating higher-risk findings for guidance.
  • Engages Legal and IT to review technical and legal vendor documents and coordinates with VROs and/or counsel to close gaps in confidentiality, subcontracting, regulatory compliance, service levels, data requirements, and breach liability.
  • Supports VROs in evaluating vendor diligence documents (financial statements, SOC reports, etc.), ensuring reviews are completed accurately and consistently, and follows up to resolve inconsistencies and close documentation gaps.
  • Administers the systems used for vendor, contract, and business continuity management (e.g., Tandem), helping ensure data integrity and supporting front-line adoption of system changes.
  • Partners across Compliance, Procurement, IT Security, and Legal to manage third-party relationships and escalate risk issues throughout the vendor lifecycle.

Program Support, Reporting & Examinations

  • Provides reporting and analysis on program performance — vendor risk, VRO adherence, business continuity readiness, and issue status — informing operational decision-making and feeding the Manager’s ROC and Board reporting.
  • Supports the risk acceptance and issue management programs — helping ensure processes are followed, tracking documentation and follow-up actions, and escalating exceptions appropriately.
  • Assists with regulatory examinations (e.g., NCUA), audits, and similar inquiries — supporting documentation requests and helping prepare and execute management responses.
  • Looks for opportunities to improve processes across the third-party management and business continuity lifecycles, recommending refinements and supporting program updates to enhance accuracy and efficiency.
  • Performs other duties and responsibilities as assigned in support of departmental and organizational objectives.


Requirements

Qualifications

Experience

  • Minimum of 2–4 years of experience in risk management, third-party / vendor risk management, business continuity, or related risk functions within a financial institution.
  • Demonstrated experience supporting or administering a vendor management and/or business continuity program, including diligence, monitoring, and documentation.
  • Experience supporting regulatory examinations or audit activities within a financial institution preferred.

Education

  • Bachelor’s degree in business administration, finance, risk management, or a related field, or equivalent experience.
  • Relevant certification (e.g., CRVPM, CTPRP, CERP, or similar) preferred.

Knowledge

  • Strong practical knowledge of third-party / vendor risk management, SOC reports, and risk assessments (inherent and residual risk, mitigation, and controls), and how to apply those insights to operational workflows.
  • Applied understanding of COSO, risk management frameworks, and NCUA examination practices, with the ability to translate findings into program actions.
  • Working knowledge of business continuity, incident response, issue management, and risk acceptance programs, able to support tracking, documentation, and escalation.
  • Familiarity with risk analytics and KRIs/KRMs, and the use of data to support operational and executive reporting.
  • Proficiency in MS Office and experience administering vendor/BCP software (e.g., Tandem) to support operational execution of programs.

Skills/Abilities

  • Ability to administer an assigned program area (third-party risk) accurately and reliably, exercising judgment within established frameworks and seeking guidance for higher-risk or ambiguous situations.
  • Applies sound professional judgment within established frameworks to resolve routine to moderately complex issues and escalates higher-risk, ambiguous, or cross-departmental situations to the Manager, Enterprise Risk.
  • Demonstrates high ethical standards and adherence to compliance procedures; conducts routine checks and raises concerns to the Manager, Enterprise Risk as needed.
  • Acts as an operational resource for VROs and process owners: advises them on program requirements, supports adoption of procedures, and follows up to prevent recurrence of issues.
  • Facilitates cross-functional collaboration among VROs, Legal, Information Security, and Compliance as an effective individual contributor.
  • Strong analytical and critical-thinking skills; evaluates information, identifies options, and recommends practical solutions.
  • Excellent written and verbal communication skills for synthesizing and presenting technical material, policy, program documentation, and operational recommendations.
  • Able to professionally represent the institution to regulators, auditors, strategic partners, and other third parties.
  • Strong organizational skills; prioritizes multiple tasks and projects, meets deadlines, and competing priorities within established procedures.
  • Self-starter with a high sense of urgency who manages multiple priorities and supports continuous operational improvement with a positive, adaptable mindset.

Physical Requirements/Work Environment

  • Primarily office-based work with frequent use of computers, phones, and other standard office equipment.
  • Ability to sit, stand, and work at a desk for extended periods throughout the workday.
  • Occasional lifting or moving of light materials (up to 15–20 pounds), such as files or office supplies.
  • May require participation in meetings, training sessions, or site visits within the organization.
  • Work environment includes deadlines, audits, or regulatory review periods requiring focused attention and multitasking.
  • Ability to communicate clearly in person, by phone, and electronically, including exchanging information with internal stakeholders and external partners.
  • Minimal exposure to environmental hazards; primarily a standard office setting.
Salary Description
$64,275.20 - $80,344.00 annually (DOE)