Job Closed

This listing is no longer active.

Builders FirstSource logo
Builders FirstSource

Builders FirstSource is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status or status as an individual with a disability.

Third-Party Risk Lead Analyst

Location

United States

Posted

39 days ago

Salary

0

Seniority

Lead

No structured requirement data.

Job Description

Third-Party Risk Lead Analyst

Builders FirstSource

Role Description The Third-Party Risk Lead is responsible for leading the end-to-end technology third-party risk lifecycle for BFS. This role partners with Procurement, Legal, IT Architecture, Information Security, Privacy, and Business Owners to evaluate and manage risk for IT vendors and service providers. - Establishes clear, risk-based decisioning (approve / approve with conditions / defer / reject). - Defines governance expectations (tiering, control requirements, monitoring cadence, and remediation tracking). - Drives outcomes through influence rather than direct authority. - Leverages external security ratings and internal risk data to continuously monitor vendors. - Ensures vendors are integrated and governed in a manner consistent with BFS security standards and target architecture. Qualifications - 5+ years of experience in third-party risk management, cybersecurity risk, or technology risk. - Bachelor’s degree in Information Security, Information Systems, Risk Management, Business, or a related field (or equivalent practical experience). - Proven ability to write clear, defensible risk assessments and executive-ready summaries. - Strong organizational skills with the ability to manage multiple vendor workstreams and deadlines. - Proficiency with common productivity and reporting tools (Excel, Word, PowerPoint, SharePoint; Power BI preferred). - Hands-on experience with third-party risk tooling and/or external security ratings. - Excellent communication and interpersonal skills. - Ability to operate with ambiguity, take initiative, and drive program outcomes in a fast-paced environment. - Strong analytical and critical thinking skills. - Experience performing vendor due diligence and documenting gaps. - Working knowledge of incident management and third-party incident/breach response expectations. - Hands-on experience creating or operating risk tiering models and assessment methodologies. - Strong understanding of the full third-party lifecycle. - Experience aligning vendor risk requirements to frameworks/standards. - Experience implementing or optimizing third-party risk workflows in platforms. - Experience in audit, compliance, or a related control function; relevant certifications are a plus. Requirements - Leads architecture development for small projects and supports architectural efforts for medium to large projects. - Owns and continuously improves the IT Third-Party Risk Management (TPRM) program. - Partners with Business Owners and Procurement to confirm the business use case and intended modules/functional scope. - Leads vendor due diligence using questionnaires and evidence. - Partners with Legal and Procurement to define and negotiate security, privacy, and technology contract requirements. - Coordinates technical and architecture compatibility reviews with IT and Security Architecture. - Documents findings in a consistent risk format and tracks remediation actions to completion. - Maintains vendor risk inventory, risk registers, and dashboards/KRIs. - Executes ongoing continuous monitoring activities and conducts periodic reassessments. - Defines and maintains TPRM policies, standards, and procedures. - Facilitates cross-functional reviews and decision meetings. - Develops and maintains TPRM playbooks, questionnaire templates, and executive-ready communications. Benefits - Medical, dental, vision, and disability insurance plans. - 401(k) retirement savings plan. - PTO (including paid sick time). - 8 paid holidays per year (for salaried and hourly team members). - Annual bonus eligibility subject to company success and other terms.

Related Categories

Related Job Pages

More Risk Jobs

Kraken logo

Product and Regional Risk Manager

Kraken

Kraken describes itself as one of the oldest, largest, and most secure crypto platforms in the world, on a mission to accelerate the global adoption of crypto s

Risk39 days ago

• Conduct and maintain risk assessments and RCSAs across Kraken's core and emerging product lines, identifying key risk exposures and recommending appropriate controls and mitigants • Perform risk assessments for Kraken's regional entities, working with regional and global stakeholders to understand the regulatory, operational, and market risk environment • Contribute to the development and ongoing maintenance of Kraken's enterprise risk taxonomy, risk appetite framework, and key risk indicator (KRI) reporting • Own and oversee the regulated entity risk management framework, including risk appetite setting, risk taxonomy, and governance structures. Lead the identification, assessment, monitoring, and reporting of all material risk types, including operational, regulatory, liquidity, safeguarding, outsourcing, ICT, and conduct risks. Ensure alignment with applicable regulatory frameworks, including MiCAR, E-Money Regulations, and DORA. • Partner with Product and Engineering teams to embed risk considerations early in the product development lifecycle, providing guidance on risk implications of new features, products, and initiatives • Drive proactive identification and escalation of emerging risks, ensuring timely visibility for senior management and relevant governance bodies • Leverage GRC tooling and data analytics to support risk monitoring, reporting, and the automation of risk program activities at scale • Monitor the risk environment for developments — including MiCAR and broader digital asset regulatory obligations — that may affect Kraken's product or regional risk profile • Serve as the primary point of contact for risk-related engagement with the Central Bank of Ireland and other relevant regulators. Lead the preparation and delivery of risk reporting to the Board and its committees, and support regulatory submissions, reviews, and inspections as required. • Prepare clear, concise risk reporting for senior leadership, risk committees, and relevant governance bodies that articulates the key drivers of Kraken's risk landscape • Operate independently across a broad range of risk activities, adding meaningful value while maintaining a collaborative working style with PCFs and senior management • Foster a culture of risk awareness across the organization by collaborating with cross-functional partners and contributing to risk training and education efforts

Ireland
SOFTSWISS logo

Junior Sport Risk Manager

SOFTSWISS

Winning combination of software products for iGaming

Risk39 days ago
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

• Setting up and adjusting templates • Monitoring and controlling events in real time • Removing and suspending events as required • Adjusting coefficients and working with betting lines • Setting up bookmakers for leagues and sports • Calculating events and markets • Checking participant names and translations • Interacting with other betting departments • Maintaining the knowledge base • Interacting with operators • Managing bet control processes • Conducting initial player analysis • Analyzing product performance across sports and leagues • Conducting competitive analysis • Testing and participating in the development of new Sportsbook products.

Poland
Job Closed
Upstart logo

Director of Enterprise Risk Management

Upstart

Our mission is to enable effortless credit based on true risk.

Risk39 days ago
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Define and maintain the Bank's enterprise risk management framework, including risk appetite statement, risk assessment methodology, and aggregated risk reporting • Lead the ERM Program team in executing enterprise risk assessments; maintaining risk and control inventories and gap tracking; and measuring risk quantitatively via key risk indicators for all risk categories • Ensure consistent quantitative and qualitative risk identification, assessment, and measurement methodologies • Direct the team's work on risk committee and board reporting, policy management, and ERM program maintenance and execution • Direct the Operational Risk Program activities, ensuring consistent assessment methodology is applied across all product lines and providing actionable analysis and insights on high risk areas requiring action • Serve as a senior point of escalation and relationship manager for external stakeholders including OCC examiners, internal and external auditors, capital markets partners, and lending partners • Develop, manage, and hire for the ERM Program and Operational Risk Program teams

United States
$18.9K - $334.2K / year
Upstart logo

Director of Treasury Risk

Upstart

Our mission is to enable effortless credit based on true risk.

Risk39 days ago
Full TimeRemoteTeam 1,001-5,000H1B Sponsor

• Establish the Bank's treasury risk oversight program, including frameworks, policies, risk metrics, limits, and monitoring processes for liquidity, interest rate, price, and capital management risk • Provide independent second-line review, challenge, and oversight of the first-line Bank Treasury team’s activities — including cash flow management, ALM, balance sheet positioning, stress testing, and investment portfolio management • Deliver credible challenge to the Bank Treasury team’s assumptions, methodologies, stress scenario designs, and risk limits, consistent with the risk appetite and risk profile of the organizationPrepare and deliver ALCO and board and board risk oversight committee reporting on treasury risk exposures, trends, and stress testing outcomes; serve as escalation point for treasury risk issues to the CRO • Hire and develop support for the treasury risk oversight team, defining team objectives, roles and responsibilities, and professional development goals • Serve as primary second-line point of contact for OCC examiners, external auditors, and other senior external stakeholders on treasury risk topics

United States
$189K - $334K / year