Third Party Risk Manager

Varo Bank
US Remote, Full Time
POSTED ON 6/7/2023 CLOSED ON 8/9/2023

What are the responsibilities and job description for the Third Party Risk Manager position at Varo Bank?

Varo is an entirely new kind of bank. All digital, mission-driven, FDIC insured and designed for the way our customers live their lives. A bank for all of us.


Varo is building out a world-class Third Party Risk Management (TPRM) team as part of the second line of defense. The TPRM Manager is a critical role at Varo and will be responsible for evaluating and managing third-party technology and security risks. The TPRM Manager will carry out ongoing reviews of all third parties, identify technology risks and requirements, and challenge and monitor third parties’ ability to perform within risk appetite.  This role will be acting as the liaison with first-line teams in order to enhance overall technology supply chain risk and business processes to maximize efficiencies and oversight.

\n


What you’ll be doing
  • Enhance Varo’s Third-Party Risk Management Framework to ensure it meets regulatory expectations and Varo’s risk appetite
  • Define and meet SLA expectations for Third Party Risk Assessments, vendor onboarding, proof of concept periods, and retirement
  • Oversee the implementation and adherence to Varo’s policy and procedures regarding third-party risk management, including training internal departments on requirements and managing third-party service providers/vendors on an ongoing basis
  • Enhance fourth-party oversight including the performance of risk assessments and identification of controls
  • Collaborate with internal stakeholders to establish and maintain a comprehensive inventory of third-party relationships, applications, and associated risks
  • Collaborate with internal security teams to develop incident response plans and procedures for addressing cybersecurity incidents involving third parties 
  • Collaborate with internal technology teams to ensure third parties have the ability to adhere to Varo technology and security requirements
  • Work closely with all Varo departments and internal risk groups that are seeking third-party services/vendor relationships to assure that appropriate risk assessment and due diligence are conducted for any new third-party service
  • Prepare and present comprehensive reports and recommendations to senior management regarding third-party risk exposures and mitigation strategies through performance assessments 
  • Maintain constant awareness of the external marketplace as it relates to third parties and/or relevant internal capabilities
  • Partner with internal budget owners to deliver against budgets and work with appropriate stakeholders on contract negotiations for all managed third-party relationships
  • Track compliance with Varo’s third-party policies and procedures, analyze and report on any gaps, and provide recommendations for remediation of such gaps
  • Lead the implementation of the Governance Risk and Compliance third-party risk management platform covering the life cycle of third-party relationships including on-boarding/off-boarding of third parties and management of proof of concept periods
  • Develop dashboard presentations and reports, and provide periodic updates to various Risk Committees on the status of the third-party risk management program
  • Act as TPRM Lead in any Regulatory and audit matters, including exams and meetings
  • Manage Varo’s Application Lifecycle Management process


You’ll bring the following required skills and experiences
  • 5-7 years of leading third-party risk management experience with a financial institution, a fintech company, or a provider to the financial services business sector
  • Risk assessment and due diligence experience with a particular focus on identifying risks and identifying and implementing solutions to remediate these gaps
  • Ability to conduct and report on testing of applicable controls that are in place regarding third-party service providers
  • Experience designing systems and workflows that support effective prioritization of monitoring Third Parties and work for the team
  • Familiarity in dealing with regulators, particularly OCC, FDIC, and Federal Reserve Board examiners and state examinersFamiliarity with technology and cybersecurity risks related to application development and acquisition including but not limited to maintenance, security, and resiliency
  • Previous experience reporting to senior management, the Board, and/or Committees of the Board on the status of third-party risk management efforts
  • Experience implementing Third Party Management requirements to comply with various regulatory requirements and industry best practices.  E.g. FFIEC IT Examination Handbook, Information Security, Business Continuity, Disaster Recovery, NIST CSF, PCI DSS compliance, SOC 2 Type 2, ect.
  • Experience with RSA Archer or similar GRC tool
  • CTPRP and/or CRISC certifications are highly preferred


\n

#MidSenior


We recognize not everyone will have all of these requirements. If you meet most of the criteria above and you’re excited about the opportunity and willing to learn, we’d love to hear from you!


About Varo

Varo launched in 2017 with the vision to bring the best of fintech into the regulated banking system. We’re a new kind of bank – all-digital, mission-driven, FDIC-insured, and designed around the modern American consumer. 


As the first consumer fintech to be granted a national bank charter in 2020, we make financial inclusion and opportunity for all a reality by empowering everyone with the products, insights, and support they need to get ahead. Through our core product offerings and suite of customer-first features, we aim to address a broad range of consumer needs while profitably serving underserved communities that have been historically excluded from the traditional financial system.


We are growing quickly in our hub locations of San Francisco, Salt Lake City, and Charlotte along with colleagues located across the country. We have been recognized among Fast Company’s Most Innovative Companies, Forbes’ Fintech 50, and earned the No. 7 spot on Inc. 5000’s list of fastest-growing companies across the country.


Varo. A bank for all of us.


Our Core Values

- Customers First

- Take Ownership

- Respect

- Stay Curious

- Make it Better


Learn more about Varo by following us:

Facebook - https://www.facebook.com/varomoney

Instagram - www.instagram.com/varobank

LinkedIn - https://www.linkedin.com/company/varobank

Twitter - https://twitter.com/varobank

Engineering Blog - https://medium.com/engineering-varo

SoundCloud - https://soundcloud.com/varobank




Varo is an equal opportunity employer. Varo embraces diversity and we are committed to building teams that represent a variety of backgrounds, perspectives, and skills. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.


Beware of fraudulent job postings!

Varo will never ask for payment to process documents, refer you to a third party to process applications or visas, or ask you to pay costs. Never send money to anyone suggesting they can provide work with Varo.  If you suspect you have received a phony offer, please e-mail careers@varomoney.com with the pertinent information and contact information.


CCPA Notice at Collection for California Employees and Applicants:

https://varomoney.box.com/s/q7eockvma9nd2b0utwryruh4ze6gf8eg

Third-Party Risk Oversight Manager
Needham Bank -
Wellesley, MA
Cybersecurity Third party Risk Manager
Sentara Health -
Virginia, VA
IT Manager, Third Party Risk
Brookfield Properties (USA II) LLC -
New York, NY

For Employer
Looking for Real-time Job Posting Salary Data?
Keep a pulse on the job market with advanced job matching technology.
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

Sign up to receive alerts about other jobs with skills like those required for the Third Party Risk Manager.

Click the checkbox next to the jobs that you are interested in.

  • Disaster Recovery Planning Skill

    • Income Estimation: $149,032 - $188,459
    • Income Estimation: $147,608 - $189,837
  • Business Continuity Execution Skill

    • Income Estimation: $147,608 - $189,837
    • Income Estimation: $171,465 - $238,786
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Varo Bank

Varo Bank
Hired Organization Address Salt Lake, UT Full Time
Varo is an entirely new kind of bank. All digital, mission-driven, FDIC insured and designed for the way our customers l...
Varo Bank
Hired Organization Address Charlotte, NC Full Time
Varo is an entirely new kind of bank. All digital, mission-driven, FDIC insured and designed for the way our customers l...
Varo Bank
Hired Organization Address Charlotte, NC Full Time
Varo is an entirely new kind of bank. All digital, mission-driven, FDIC insured and designed for the way our customers l...
Varo Bank
Hired Organization Address Salt Lake, UT Full Time
Varo’s Project Portfolio Management Office (PMO) is looking for an Associate Program Manager and change agent to help le...

Not the job you're looking for? Here are some other Third Party Risk Manager jobs in the US Remote, area that may be a better fit.

Third Party Security Risk Manager

Yoh, A Day & Zimmermann Company, Miami, FL

Senior Risk Manager - Third Party

DWS Group, Jacksonville, FL