IT Third-Party Risk Assessor

Mitsubishi UFJ Financial GroupTempe, AZ
Hybrid

About The Position

The IT Third-Party Risk Assessor is responsible for evaluating, monitoring, and reporting on information technology risks associated with third-party vendors, suppliers, service providers, and other external business partners. This role supports the organization's Third-Party Risk Management (TPRM) program by conducting risk assessments, reviewing cybersecurity controls, identifying potential vulnerabilities, and ensuring third parties comply with organizational policies, industry standards, and regulatory requirements. The successful candidate will evaluate the information security and technology frameworks of external partners, SaaS providers, and financial technology associates. This position enforces strict alignment with banking regulations, manages risk lifecycles inside Archer, and leverages AI technologies to accelerate due diligence and continuous monitoring. TPRM SME will partner with business stakeholders, procurement / contract management teams, security teams, compliance functions, and vendors to identify and mitigate risks throughout the third-party lifecycle.

Requirements

  • Bachelor's degree in Information Technology, Information Security, Cybersecurity, Risk Management, Business Administration, or a related field. Equivalent combination of education and experience will be considered.
  • 5+ years of experience in: Third-Party Risk Management (TPRM) Information Security Cybersecurity Risk Management IT Audit Technology Risk Operational Risk Business Continuity Planning
  • Experience reviewing vendor security assessments and industry-standard assurance reports.
  • Experience working in regulated industries such as financial services, healthcare, insurance, or technology preferred.
  • Solid understanding of financial regulatory expectations regarding data protection and operational resilience.
  • Understanding of cybersecurity principles and security control frameworks.
  • Familiarity with: Access management Network security Cloud security Data protection and encryption Disaster recovery and business continuity Vulnerability management Incident response Service Level Management (Agreements review & verification) Release Management / SDLC IT Asset Management IT Configuration Management Change Management Problem Management System Capacity and Performance
  • Knowledge of vendor risk assessment methodologies and control evaluation techniques.

Nice To Haves

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Third-Party Risk Professional (CTPRP)
  • Certified Third Party Risk Assessor (CTPRA)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Cloud Security Professional (CCSP)
  • Security+ or equivalent cybersecurity certification

Responsibilities

  • Conduct cybersecurity, information security, and technology risk assessments of third-party vendors and service providers.
  • Review vendor security documentation, including: SIG questionnaires SOC 1 and SOC 2 reports (may include Bridge Letter verification) ISO 27001 certifications to include SoA reviews
  • Track, document, and manage the end-to-end vendor risk lifecycle within Archer GRC.
  • Use AI-powered risk platforms to parse vendor documentation and summarize control gaps.
  • Assess inherent and residual risks associated with third-party relationships.
  • Evaluate vendor compliance with internal policies, security standards, and regulatory requirements.
  • Identify and document control gaps, vulnerabilities, and areas of concern.
  • Develop risk ratings and provide recommendations for risk mitigation.
  • Prepare concise risk assessment reports and executive-level summaries.
  • Present assessment findings to business owners, risk committees, and senior management.
  • Perform periodic reassessments of critical and high-risk vendors.
  • Monitor vendors for cybersecurity incidents, financial instability, regulatory actions, and emerging risks.
  • Track remediation activities and validate corrective actions.
  • Maintain vendor risk profiles and assessment documentation.
  • Partner with Procurement, Information Security, Legal, Compliance, Privacy, and Business Units throughout the vendor lifecycle.
  • Provide guidance regarding security requirements during vendor onboarding and renewals.
  • Support contract reviews by recommending security and data protection requirements.
  • Assist business partners in understanding and managing third-party technology risks.
  • Ensure alignment with regulatory requirements and industry frameworks such as: NIST Cybersecurity Framework NIST CRI NIST 800-53 NIST 800-171 FFIEC Guidance ISO 27001 HIPAA (as applicable)
  • Support audits, examinations, and regulatory reviews related to third-party risk.
  • Contribute to continuous improvements of the Third-Party Risk Management Program.

Benefits

  • We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service