Назад
Company hidden
11 дней назад

Senior Risk Analyst, Privacy & Third-Party Risk

87 000 - 148 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk Analyst, Privacy & Third-Party Risk (Privacy, TPRM, AI): Providing second-line oversight, independent challenge, and governance reporting across privacy and third-party risk programs with an accent on complex assessments, control effectiveness, incident management, and regulatory readiness. Focus on analyzing emerging AI and technology risks, improving GRC workflows and reporting, and developing risk analytics and automation capabilities.

Location: Baltimore, Maryland, United States; hybrid work with up to one day per week from home

Base salary: $87,000–$148,000 annually for Maryland, Colorado, Washington, and remote workers. Additional salary ranges apply to Washington, D.C., New York, and California.

Company

hirify.global is a global asset management organization providing investment solutions and equity, fixed-income, and multi-asset capabilities.

What you will do

  • Provide independent second-line oversight and effective challenge across privacy and third-party risk activities.
  • Lead reviews of privacy impact assessments, data protection impact assessments, privacy incidents, and elevated-risk assessments involving new technologies, AI, and sensitive data.
  • Review third-party due diligence, control deficiencies, risk responses, outsourced provider performance, concentration risk, and emerging supplier risks.
  • Develop executive-level dashboards, risk reporting, metrics, management information, and regulatory or audit materials.
  • Analyze incidents, assessment results, control weaknesses, and performance data to identify systemic and emerging risks.
  • Translate risk requirements into system enhancements, user stories, workflow automation, analytics, and AI-enabled tools; perform UAT and support remediation tracking.

Requirements

  • Bachelor’s degree in risk management, information systems, finance, business, law, or a related field.
  • At least 5 years of experience in risk management, GRC, information security, privacy, third-party risk, operational risk, technology risk, or a related oversight function.
  • Experience operating independently in a second-line-of-defense or similar independent review and challenge environment.
  • Knowledge of risk management principles, privacy, third-party risk, information security, technology risk, operational risk, or compliance.
  • Experience identifying control weaknesses, assessing risks, challenging remediation plans, and communicating findings to stakeholders.
  • Strong analytical, reporting, issue-management, governance, and stakeholder-management skills.

Nice to have

  • Asset management or broader financial services experience.
  • Experience with control testing, risk and control assessments, root cause analysis, remediation oversight, and risk framework enhancements.
  • Relevant certifications such as CIPP, CISA, CRISC, CTPRP, CIPM, CIPT, or ISO 27001 credentials.
  • Experience with Archer, ServiceNow, OneTrust, IBM OpenPages, Power BI, advanced Excel, Microsoft Copilot, ChatGPT Enterprise, or Power Automate.
  • Familiarity with SEC, FINRA, and global regulatory expectations.

Culture & Benefits

  • Hybrid work schedule with limited weekly office attendance.
  • Annual bonus eligibility and competitive compensation.
  • Retirement plan and health and wellness benefits, including online therapy.
  • Paid time off for vacation, illness, medical appointments, and volunteering.
  • Family care resources, including fertility and adoption benefits.
  • Inclusive, collaborative environment with opportunities for professional development and community impact.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →