Summary
Administers Sunward’s third-party / vendor risk management program, as an individual contributor within the enterprise risk function, providing independent second-line oversight of vendor relationships and ensuring consistent, compliant execution across the vendor risk lifecycle.
The role supports and executes the third-party risk management lifecycle — vendor inventory and tiering, risk-based due diligence, ongoing monitoring, fourth party and concentration risk, and contract/SLA risk review — partnering closely with vendor relationship owners (VROs), Legal, Information Security, and Compliance. It coordinates day-to-day program activities across business units, advises stakeholders on program requirements, ensures adherence to established procedures, and escalates concerns appropriately.
Operating with general guidance within established policy, the Third Party & Vendor Risk Specialist resolves routine to moderately complex issues within authority, and escalates higher-risk, ambiguous, or cross-departmental situations to the Manager, Enterprise Risk.
Essential Functions:
Third-Party / Vendor Risk Management
- Maintains Sunward’s third-party risk management policy and program, including program documentation; ensures activities are performed and records retained in compliance with applicable laws, regulations, and Sunward policies, escalating concerns as necessary.
- Maintains a complete vendor inventory and risk tiering framework; conducts risk-based due diligence at onboarding and through ongoing monitoring cadences by tier, including SOC report review, financial-condition tracking, cybersecurity posture, and adverse-news monitoring, and maintains the resulting risk scores and registers.
- Coordinates vendor offboarding and contract termination activities, including confirmation of data return or destruction, access revocation, and closeout documentation, to ensure risks are appropriately managed through the end of the vendor relationship.
- Supports assessment of fourth party (subcontractor) and concentration risk, helping identify key dependencies and potential points of failure across the vendor portfolio, and escalating higher-risk findings for guidance.
- Engages Legal and IT to review technical and legal vendor documents and coordinates with VROs and/or counsel to close gaps in confidentiality, subcontracting, regulatory compliance, service levels, data requirements, and breach liability.
- Supports VROs in evaluating vendor diligence documents (financial statements, SOC reports, etc.), ensuring reviews are completed accurately and consistently, and follows up to resolve inconsistencies and close documentation gaps.
- Administers the systems used for vendor, contract, and business continuity management (e.g., Tandem), helping ensure data integrity and supporting front-line adoption of system changes.
- Partners across Compliance, Procurement, IT Security, and Legal to manage third-party relationships and escalate risk issues throughout the vendor lifecycle.
Program Support, Reporting & Examinations
- Provides reporting and analysis on program performance — vendor risk, VRO adherence, business continuity readiness, and issue status — informing operational decision-making and feeding the Manager’s ROC and Board reporting.
- Supports the risk acceptance and issue management programs — helping ensure processes are followed, tracking documentation and follow-up actions, and escalating exceptions appropriately.
- Assists with regulatory examinations (e.g., NCUA), audits, and similar inquiries — supporting documentation requests and helping prepare and execute management responses.
- Looks for opportunities to improve processes across the third-party management and business continuity lifecycles, recommending refinements and supporting program updates to enhance accuracy and efficiency.
- Performs other duties and responsibilities as assigned in support of departmental and organizational objectives.