What are the responsibilities and job description for the Vendor Management Analyst position at Credit One Bank?
Description
Position Summary
As a, Vendor Risk Governance Analyst, this position will assist with oversee the vendor management policy and procedures, ensuring compliance with appropriate regulations and laws. Additionally, the individual in this role will work with internal partners and external vendors to ensure due diligence data and documents are submitted and reviewed timely.
Summary Of Essential Job Functions
Position Summary
As a, Vendor Risk Governance Analyst, this position will assist with oversee the vendor management policy and procedures, ensuring compliance with appropriate regulations and laws. Additionally, the individual in this role will work with internal partners and external vendors to ensure due diligence data and documents are submitted and reviewed timely.
Summary Of Essential Job Functions
- Coordinates the identification and ranking of vendor risks
- Coordinates the classification and tiering of vendors by risks and risk impacts
- Builds communication and escalation plans around vendor risk management activities within the enterprise
- Understands and applies relevant regulatory and legal compliance requirements
- Oversees vendor management policy and procedures to ensure they meet all appropriate regulations and laws; are communicated and adhered to across all departments
- Develops, monitors, and possibly executes vendor remediation actions, mitigation and contingency plans when risks or events are identified
- Ensures third (and increasingly, fourth) party vendor regulatory compliance
- Coordinates the gathering of vendor risk assessment data and prepares risk assessments for critical-related vendors as needed, to be published and communicated to stakeholders
- Manages and maintains up-to-date vendor due diligence, risk assessment, and other related documents received from internal and external sources
- Tracks and reports identified risks and risk events
- Influences vendors and business partners to ensure compliance with vendor management policies
- Partners with vendor relationship/contract management functions where they are not part of this group to manage vendor behavior
- Collaborates, as appropriate, with information security, finance, compliance and/or disaster recovery and business continuity management and other risk functions to maintain an enterprise risk management program
- Works with regulatory officers and auditors as necessary
- Communicates identified risk requirements and violations to internal stakeholders (and end users within the business) and responsible vendors while supporting the response to and the addressing of these issues
- Develops and coordinates vendor risk management frameworks, policies and processes within a broader enterprise, operational and IT risk management model
- Perform other duties as assigned
- Bachelor’s degree or equivalent years of work experience in a corporate environment
- Advanced Microsoft Applications skills (Word, PowerPoint, Excel, Visio-preferred) with an emphasis on advanced Excel skills
- 5 years of experience in managing risk and compliance issues, or similar experience managing applications, projects or systems that require identification, evaluation and remediation if risk
- Technical background or demonstrable understanding of a range of operational and IT risks and operations
- Strong business background; experience gathering and interpreting risks and associated impacts in the context of financial and operational concerns
- Strong understanding of complex vendor risk-related issues through demonstrated experience managing vendor relationships, information security or regulatory compliance programs, and audits
- Outstanding time management skills and ability to work on multiple projects in parallel
- Highly organized and detail-oriented
- Strong analytical and problem-solving skills
- Program management skills
- Effective communication skills and ability to work well across all levels and functions in the company
- Flexible and open to change
- Proactive, self-starter, willingness to learn
- Certification in Risk Management Assurance (CRMA) preferred
- Certified Information Systems Auditor (CISA)