Vendor Risk Manager - Chief Risk Office

  • Posted 12 hours ago | Updated 12 hours ago

Overview

On Site
USD 130,000.00 - 180,000.00 per year
Full Time

Skills

Energy
Trading
Collaboration
Network
Continuous Monitoring
IT Audit
Roadmaps
Management
Inventory
Due Diligence
ERM
Legal
Reporting
Bloomberg
Computer Science
Business Management
Internal Auditing
Regulatory Compliance
NIST 800-53
COBIT
ISO 9000
PCI DSS
NIST SP 800 Series
HIPAA
Artificial Intelligence
Risk Assessment
Software Architecture
Network Security
Identity Management
Information Security
Risk Management
IT Risk Management
IT Risk
Financial Technology
Privacy
Communication
CISSP
CISA
CISM
GSEC
Service Level
Performance Metrics
IT Security
Cloud Computing
Training
Life Insurance

Job Details

Vendor Risk Manager - Chief Risk Office

Location
New York

Business Area
Legal, Compliance, and Risk

Ref #
10044601

Description & Requirements

The energy of a newsroom, the pace of a trading floor, the buzz of a recent tech breakthrough; we work hard, and we work fast - while keeping up the quality and accuracy we're known for. It's what keeps us inventing and reinventing, all the time. Our culture is wide open, just like our spaces. We bring out the best in each other through collaboration. Through our countless volunteer projects, we also help network with the communities around us, too. You can do amazing work here. Work you couldn't do anywhere else.

It's up to you to make it happen.

Vendor Risk Management (VRM) is part of the Chief Risk Office (CRO) and responsible for assisting Bloomberg departments and select subsidiaries of Bloomberg LP in the selection, assessment, mitigation and continuous monitoring of risks introduced by vendors and other third-party service providers.

What's The Role?

We are looking for a Vendor Risk Manager with a strong background in Information Security, Operational Resilience, Technology Audit and/or Risk Management. You will work with Bloomberg departments and subsidiaries to perform the inherent risk assessment of their vendor engagements, create and maintain the risk profile of vendors and vendor products / services, and drive control assessment and risk remediation activities across our vendor population while contributing to strategic initiatives to enhance the overall Vendor Risk program in line with our transformation roadmap. Your work will add value to Bloomberg departments and subsidiaries that use third parties to achieve their goals, by helping them appropriately manage vendor risk throughout the vendor lifecycle.

We'll Trust You To:
  • Liaise with business and technology teams to understand their use of vendor services and products and appropriately assess the inherent risks related to information security, privacy, resiliency, concentration, regulatory compliance, subcontracting, location / geography, among others.
  • Maintain the vendor and vendor engagement inventory and risk profiles
  • Conduct due diligence control assessments, continuously monitor and report on Vendor and vendor engagement risks
  • Coordinate risk mitigation activities with vendors and Bloomberg departments and subsidiaries
  • Interpret, train and enforce compliance with Bloomberg's Vendor Risk Management Policy
  • Cultivate and leverage relationships with CISO, Legal, Compliance, Enterprise Risk Management (ERM) and other control functions to accomplish objectives
  • Lead key VRM activities and demonstrate understanding of the top and material risks affecting Bloomberg, our supply chains, and our clients
  • Act as subject matter expert on VRM matters supporting Bloomberg departments for which you are responsible
  • Provide advisory support to Bloomberg departments on risk
  • Provide and coordinate input to key compliance, legal and regulatory initiatives
  • Demonstrate existing or develop targeted material to deliver actionable risk reporting to Bloomberg departments as needed
  • Participate in select risk committees / working groups

You'll Need to Have:
  • Bachelor's or master's degree in Computer Science, Information Security, Business Management or equivalent industry experience
  • 7+ years of experience working in the field of Risk Assurance, Risk Management, Internal Audit or other Compliance-related experience
  • An understanding of Cloud Computing and how to assess cloud-related risks
  • Familiarity with:
    • International regulations regarding third-party service providers
    • Industry Frameworks (NIST 800-53, COBIT 5, ISO/IEC 27001/2, HITRUST, PCI DSS, CSA CAIQ and CCM, CIS CSC, NIST 800-171) and Data Privacy regulations/standards
    • Data Privacy regulations and industry standards (e.g., GDPR, Schrems II, CCPA, HIPAA)
    • Digital Operational Resilience Act (DORA) and the European Union Artificial Intelligence (EU AI) Act
    • Vendor Risk Assessment Frameworks/Tools (e.g., SIG, VSAQ)
  • Technical knowledge in multiple risk domain areas such as application, architecture, system and network security, identity/access management, etc.
  • Knowledge of current Information Security threats, trends, and mitigations
  • Skilled in risk management, technical risk analysis, and making complex business/risk trade-off recommendations and decisions
  • Understanding of impact of financial, technology and privacy regulations on Fintech products and services
  • Strong interpersonal and written and verbal communication skills
  • Industry certifications (CISSP, CISA, CISM, CTPRP, CIPT/CIPP, GSEC, GIAC, etc.)

We'd Love to See:
  • An understanding of supplier agreements, contractual terms and service level agreements
  • Experience in developing and deploying operational performance metrics to measure IT security effectiveness and operational resilience
  • Experience with Cloud-based IT architectures and security products

Salary Range = 00 USD Annually + Benefits + Bonus

The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.

We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.