What are the responsibilities and job description for the The Analyst II, Vendor Risk Assessment Control Operations position at Santander Holdings USA Inc?
WHAT YOU WILL BE DOING
The Analyst II, Vendor Risk Assessment Control (VRAC) Operations administers defined procedures and report preparation for the department, ensures conformity to applicable laws, regulations, and policies, analyzes less complex risk management data, and makes recommendations based on findings.
• Assess inherent risk of services (information security, regulatory, operational, strategic, & other risks) outsourced to third parties on behalf of business lines. Prepare appropriate review memorandum summarizing liabilities and recommend follow-up evaluations
• Review reputational risk (including negative news search results) of third parties and work with business lines to address any deficiencies or risks associated with the due diligence
• Perform other duties related to the third party lifecycle such as periodic reviews of risks associated with vendors, termination of services/relationships, etc.
• Interpret and apply procedures, ensure analysis is documented and that records are maintained. Advise internal business partners on risk policies and guidelines to build a risk aware culture and practice across the organization
• Assist, as required, with quality assurance activities of VRAC related work
• Provide procedural guidance and support to more junior teammates in the various functions of the department, and in the methods of tools of analysis
• Research a wide variety of topics and issues including emerging risks and trends and risk management best practices; summarizes and communicates findings with team.
• Influence ongoing development of enterprise-wide third-party assessment practices and systems through outreach and support of key business lines engaged in the procurement function
• Counsel senior management on ad hoc, confidential, and urgent requests for third party assessment needs
• Develop and sustain meaningful relationships through building trust and rapport with internal Santander stakeholders
• Partner with management to ensure accuracy of vendor inventory, report on status of vendor inventory and assessment activities
At Santander, we value and respect differences in our workforce and strive to increase the diversity of our teams. We encourage everyone to apply.
• Bachelor’s Degree Business, Operations, Information Security, Management, or equivalent field preferred
• Industry Sponsored Certification CISA, CRISC, CISSP preferred
• 3-5 Years Risk Management required, Third Party or Vendor Risk Management or Information Security, Data Security, Privacy or Technology experience preferred
• Demonstrated knowledge of basic risk principles, concepts and policies
• Proficient MS Office skills
• Strong verbal and written communication skills
• Strong analytical, problem solving and communication skills
• Ability to summarize, document and communicate information in a clear and concise manner
• Ability to organize and prioritize multiple tasks to meet deadlines
• Ability to work independently as well as collaboratively within a team environment
• Ability to interpret, analyze and apply data/information
• Ability to stay abreast of industry best practices, procedures and techniques
• Ability to build and foster internal relationships
• Ability to read, write and speak Spanish is preferred
• Ability to adhere to policies, procedures, and instructions of management
Employees desiring consideration should complete an online application, utilizing the appropriate process as subscribed by the posting entity. Employees should provide all pertinent information to support their candidacy.
To be considered eligible for internal posting, Santander employees must meet all of the following eligibility requirements:
• Completion of at least one year of active service in Santander
• Completion of at least twelve months in current position
• Be in “Good Standing”
Primary Location: Dallas, Texas, United States of America
Other Locations: Texas-Dallas,Florida-Miami,Massachusetts-Dorchester,Rhode Island-East Providence,Rhode Island-Providence
Organization: NW Services Co
Recommended Skills
- Disaster Recovery
- Microsoft Antivirus
- Data Security
- Incident Management
- Linux
- Public Key Infrastructure