Search by job, company or skills

Security Bank Corp

Senior Third Party Risk Officer

5-10 Years
Save
new job description bg glownew job description bg glownew job description bg svg
  • Posted 3 hours ago
  • Be among the first 10 applicants
Early Applicant

Job Description

About the role

The management expects the employee who is part of TPRM Department to provide second line of defense (2LoD) oversight of first line of defense (1LoD) third party risk management processes such as third-party relationship management, due diligence, contract management, eligibility assessment, materiality assessment, on-boarding, performance management, contingency planning, off-boarding and other similar activities. As TPRM subject matter expert (SME), the employee must be successful in performing the following:

  • Establish and oversee the implementation of the overall Third-Party Risk Management Framework that aligns with regulatory requirements, industry standards and best practices.
  • Ensure that TPRM processes align and support the strategic objectives set by the Operational Risk Management Division Head and Risk Management Group Head or by the bank's Chief Risk Officer and ultimately support the objectives of the bank and its subsidiaries.
  • Ensure that risks around engaged third parties are managed within the bank's risk appetite.

How you'll contribute

Demonstrate flexibility in assuming the role of third party risk manager assigned in Risk Advisory Unit or in Control Assurance Unit based on the need as determined by the Third Party Risk Department Head:

  • Facilitate the development, update or review of TPRM-related documents or tools.
  • Independently review 1LoD TPRM-related processes and controls.
  • Perform control testing of third-party controls and internal controls related to TPRM processes to identify control failures, gaps, or lapses.
  • Perform risk advisory during due diligence and accreditation processes for onboarding new third parties or services or for renewing expiring services by identifying risks using appropriate risk assessment tools (e.g., Operational Risk Assessment) and working with the respective 1LoD third party contract owners in preparing action plans to mitigate outstanding third-party risks.
  • Participate as risk steward or third party risk subject matter expert (SME) in different ORM risk management activities during reviews of Risk and Control Self-Assessment (RCSA), Change Risk Assessment (CRA), Key Risk Indicators (KRI), Root Cause Analysis (Incident's RCA), etc.
  • Challenge completion of action plans that were initiated to address control gaps from the third party side or in 1LoD control environment, arising from the result of control testing, compliance testing, internal or external audit, or monitoring of TPRM-related KRIs or incidents.
  • Prepare and submit relevant third-party risk reports to the relevant Senior Management or Board committee/s.
  • Develop or update learning materials related to TPRM topics.

Lead the Risk Advisory Unit or Control Assurance Unit during the absence of the unit head or aid the unit head during the normal course of business based on the need as determined by the Third Party Risk Department Head:

  • Lead the development, update or review of TPRM-related documents or tools.
  • Manage the unit's work assignments in Risk Advisory Unit or Control Assurance Unit.
  • Manage the unit's work assignments in participating as risk steward in different ORM risk management activities.
  • Lead the preparation and submission of relevant third-party risk reports.
  • Review and provide sign off on the unit's work output (e.g., service intake requests, risk profiling, third party and internal control testing, internal control checklist, etc)

Support the Third Party Risk Department Head and the Risk Advisory and Control Assurance Unit Heads in the overall achievement of the department's goals:

  • Assist in providing guidance during the development, update or review of TPRM-related documents or tools.
  • Assist in driving process improvement by recommending and implementing initiatives to improve the conduct of the unit's Business-As-Usual processes.
  • Assist in training the third party risk managers for skills development.
  • Assist in providing guidance during the development or update of learning materials.

What we're looking for

  • 5-10 years of relevant experience
  • Educational background related to Information Technology, Information Security, Information Management, Financial Management, Industrial or Electronics and Communications Engineering
  • Preferred certifications in ISO27001 certifications, CISA , CISM, CRISC, CISSP, CTPRP, CTPRA
  • Possess understanding of common banking processes and technologies and commonly outsourced activities for a bank and risk management practices for engaged third parties
  • Demonstrate proficiency in one or more common third-party risk areas (e.g., information security, technology, physical security, personnel security, business continuity, concentration, fraud, reputation, etc.) and the controls to mitigate third party risks
  • Ability to maintain a good working relationship and collaborate with multiple internal and external stakeholders
  • Effectively communicate with internal and external audiences, including the ability to present a 2LoD oversight perspective from common departmental/division leadership up to the senior management (executive) level using different communication channels
  • With auditing, control testing or risk assessment background/experience and proven ability to employ a risk-based mindset in identifying control gaps and risks as well as to evaluate possible risk remediation solutions to address issues and improve internal control environment by applying best practices and technical expertise
  • With leadership experience in handling experienced risk managers and managing differences in opinions, perspectives, and escalation from both internal and external stakeholders

About Security Bank

Security Bank is one of the Philippines best capitalized private domestic universal banks.

Established in 1951 and publicly listed with the Philippine Stock Exchange (PSE:SECB) in 1995, our major businesses cover retail, corporate, commercial, and business (MSME) banking.

We're recognized as an Employer of Choice in Philippine banking by various award-giving bodies for our values-based culture, industry-leading engagement and benefits, and commitment to work-life balance.

Most recently, we ranked as the #2 best employer in the Philippines and #54 globally on the prestigious Forbes World's Best Employers 2023 list.

At Security Bank, our approach to Human Capital Management (HCM) is embodied by our Employee Value Proposition (EVP): YOU matter.

Start your BetterBanking career with us today.

More Info

Job Type:
Industry:
Function:
Employment Type:

About Company

Job ID: 146790373

Similar Jobs