Risk & Third-Party Risk Specialist

FIRST BANK OF THE LAKE

Risk & Third-Party Risk Specialist

Osage Beach, MO
Full Time
Paid
  • Responsibilities

    The Risk & Third-Party Risk Specialist supports the Bank's risk management and third-party risk management activities, with particular emphasis on fintech and other higher-risk third-party relationships. This technical staff position performs due diligence, ongoing monitoring, risk and control assessments, and related analysis to identify, evaluate, document, and escalate risk across third-party relationships, products, processes, and controls. The position works collaboratively with business units and control functions to support effective risk mitigation, sound governance, and compliance with applicable Bank requirements and regulatory expectations.

    Key Responsibilities:

    • Perform risk assessments and due diligence for prospective and existing third parties, including fintech partners, evaluating risk areas such as regulatory compliance, information security and cybersecurity, data privacy, financial condition, operational resilience, business continuity, concentration risk, subcontractor/fourth-party risk, and reputational risk.
    • Conduct enhanced due diligence and ongoing monitoring for fintech and other higher-risk third-party relationships, including review of relevant policies, procedures, control documentation, audit and assurance reports, financial information, business continuity and disaster recovery materials, compliance documentation, and other risk information.
    • Assist with the performance of risk and control assessments of Bank processes, products, services, and third-party activities by identifying inherent risks, documenting key controls, evaluating control design and implementation, and supporting the determination and documentation of residual risk.
    • Analyze control evidence and testing results to identify gaps, weaknesses, or emerging risks; clearly document conclusions and escalate material concerns or items requiring management attention.
    • Support risk reviews associated with new fintech partnerships, new products or services, material changes to existing arrangements, and changes in a third party's risk profile, operations, ownership, technology, or control environment.
    • Perform periodic and event-driven third-party reviews in accordance with established risk tiering, due diligence, and monitoring requirements, and ensure supporting documentation is complete and current.
    • Monitor third-party performance, risk indicators, incidents, audit results, control exceptions, regulatory developments, and other relevant information for changes that may affect the Bank's risk exposure.
    • Assist in assessing third-party incidents, control failures, service disruptions, data or security events, compliance concerns, and other material events; document risk impacts and support appropriate escalation and remediation tracking.
    • Track identified risk issues, findings, exceptions, and remediation activities; review supporting evidence, follow up on open items, and escalate overdue, unsupported, or higher-risk remediation matters.
    • Maintain accurate third-party inventory, risk ratings, due diligence records, assessment documentation, issue records, and other information within applicable third-party risk management or governance, risk, and compliance systems.
    • Identify and analyze concentrations, dependencies, critical service relationships, and fourth-party exposures that may create elevated or interconnected risk across the Bank's third-party portfolio.
    • Develop and maintain risk metrics, key risk indicators, assessment summaries, and other reporting used to communicate third-party and operational risk trends, exceptions, and emerging concerns to management.
    • Review third-party contract provisions and supporting documentation from a risk perspective and coordinate with Legal, Compliance, Information Security, Operations, and other stakeholders when required terms, controls, or risk mitigations require attention.
    • Collaborate with fintech program owners, business units, Compliance, Legal, Information Security, Information Technology, Operations, Finance, and other stakeholders to obtain information, communicate assessment results, and support timely resolution of risk matters.
    • Support internal audits, external audits, regulatory examinations, and other reviews by gathering documentation, preparing assessment support, responding to information requests, and assisting with remediation activities related to assigned areas.
    • Assist with updates to third-party risk management and risk assessment procedures, tools, methodologies, and documentation based on regulatory expectations, internal requirements, lessons learned, and changes in the Bank's risk environment.
    • Perform additional responsibilities and duties as assigned or requested by management for the purpose of supporting the Bank's risk management framework and facilitating corporate objectives.
    • Must complete all required training, including Bank Secrecy Act/Anti-money Laundering training, suitable to their position within the bank.

    **Education & Experience Requirements: **

    • Bachelor's degree in business administration, finance, risk management, information technology, accounting, or a related field preferred. Additional relevant work experience may be substituted on a year-for-year basis for the formal education requirement.
    • Minimum of 3 years of relevant experience in third-party risk management, enterprise or operational risk, compliance, audit, information security, banking operations, or a related risk or control function, preferably within financial services or another highly regulated industry.
    • Experience performing third-party due diligence, risk assessments, control assessments, monitoring, issue management, or similar risk evaluation activities.
    • Experience with fintech, banking-as-a-service, embedded finance, payments, or other technology-enabled financial services relationships preferred.
    • Working knowledge of third-party risk management principles, risk and control assessment methodologies, and applicable banking regulatory expectations for third-party relationships.
    • Professional certification related to third-party risk, risk management, information security, audit, or compliance is preferred but not required.

    Skill & Knowledge Requirements:

    • Ability to evaluate control environments and interpret supporting evidence such as policies and procedures, audit or assurance reports, security documentation, business continuity materials, financial information, compliance documentation, and remediation evidence.
    • Strong analytical and problem-solving skills with the ability to assess risk across multiple domains, identify relevant control considerations, distinguish material issues from routine exceptions, and document well-supported conclusions.
    • Strong written and verbal communication skills with the ability to clearly communicate risk observations, information requests, assessment conclusions, and escalation items to business and control-function stakeholders.
    • Strong organizational and documentation skills, with the ability to manage multiple assessments, reviews, and follow-up activities while maintaining accuracy and attention to detail.
    • Ability to work independently within established frameworks and procedures, exercise sound judgment, and seek guidance or escalate matters when risk significance, complexity, or uncertainty warrants additional review.
    • Proficiency with third-party risk management, governance-risk-compliance, workflow, or similar platforms, along with Microsoft Office applications and data analysis tools used for risk assessment and reporting.
    • A commitment to continuous learning and professional development in third-party risk management, fintech risk, and risk and control assessment practices.
    • Must be able to be bonded.

    Physical Requirements:

    • Prolonged periods sitting at a desk and working on a computer.
    • Must be able to lift up to 25 pounds at times.

    Work Arrangement:

    • This position is remote.
    • Occasional travel may be required for in-person training or meetings.

    EEO Statement:

    We are an equal-opportunity employer. All qualified applicants will receive consideration for employment regardless of race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, or any other protected category. All offers of employment shall be subject to the successful completion of all pre-employment screenings, verifications, and processes. Failure to comply with these processes or failure to successfully pass all phases of the pre-employment screening will result in a withdrawal of the employment offer.

    Other Duties:

    Please note that this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, obligations, and activities may change at any time, with or without notice.

    Compensation is based on geographic location and individual pay decisions will vary based on demonstrated job related skills, knowledge, experience, education, certifications, etc.

    Benefits:

    • 401(k)
    • 401(k) matching
    • Health insurance
    • Dental insurance
    • Life insurance
    • Paid time off
    • Vision insurance
    • Short- and Long-term disability
    • Company-paid holidays

    __

    For Advertising Purposes Only: #LI-DNI