Third Party Risk Management Specialist

1St Summit Bank•Johnstown, PA

About The Position

This role is responsible for managing third-party risk throughout the entire lifecycle of vendor relationships, from onboarding and due diligence to ongoing monitoring and offboarding. The specialist will assess inherent risks, analyze control documentation, ensure contractual safeguards, and coordinate secure offboarding processes. They will also conduct periodic reviews, monitor financial viability, manage issue remediation, and assess fourth-party risks. A key responsibility includes leading enterprise-wide disruption drills to test and strengthen the bank's resilience against critical third-party outages. The role also involves maintaining the Third-Party Risk Management (TPRM) framework, preparing executive reports for the Board of Directors, and serving as the primary contact for auditors and examiners.

Requirements

  • Excellent verbal and written communication skills.
  • Strong organizational and time-management skills, with close attention to detail and a demonstrated ability to meet deadlines.
  • Ability to work independently to achieve goals and objectives.
  • Ability to evaluate key contract provisions and propose changes as necessary.
  • Proficient with Microsoft Office Suite or related software.
  • Strong ability to interpret and evaluate information security posture, SOC reports, and financial statements of corporate vendors.
  • High school diploma or equivalent required.
  • In lieu of a bachelor’s degree, a minimum of five (5) years of equivalent experience is required.

Nice To Haves

  • Bachelor’s degree in business or a related field preferred.
  • Experience in using and administering a dedicated vendor management platform is preferred.
  • Knowledge of the Interagency Guidance on Third-Party Relationships, FFIEC IT examination handbooks, and GLBA data privacy expectations preferred.
  • Professional Certifications: CTPRP, CISA, CRISC, or a comparable professional certification is preferred.

Responsibilities

  • Evaluate each proposed vendor relationship and assign the appropriate inherent risk tier.
  • Collect, review, and challenge third-party control documentation, including SOC 1 and SOC 2 Type II reports, audited financials, and business continuity plans.
  • Work with Legal and Procurement to include required regulatory provisions in vendor contracts.
  • Coordinate offboarding for terminated relationships, verifying data destruction, system access removal, and final contract closeout.
  • Maintain the review schedule and conduct formal periodic risk assessments for all third parties.
  • Evaluate the ongoing financial health of critical third parties.
  • Document deficiencies identified during periodic reviews, track corrective actions, and work with vendor contacts to meet remediation deadlines.
  • Identify and monitor concentration risks where primary vendors rely heavily on critical downstream subcontractors.
  • Orchestrate annual, bank wide BCP and Pandemic tabletop exercises centered on critical third-party outages.
  • Maintain and periodically update the Bank’s TPRM framework to reflect current regulatory requirements.
  • Prepare vendor risk summaries, concentration dashboards, and open-issue logs for review by the Board of Directors.
  • Serve as the principal point of contact for internal auditors and examiners regarding the third-party risk management program.
  • Perform other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service