Jobs Companies MUFG IT Third-Party Risk Assessor

Über diese IT Third-Party Risk Assessor Stelle bei MUFG

MUFG · Hybrid · Tempe, AZ

Do you want your voice heard and your actions to count?

Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.

With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.

Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.

The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.

The IT Third-Party Risk Assessor is responsible for evaluating, monitoring, and reporting on information technology risks associated with third-party vendors, suppliers, service providers, and other external business partners. This role supports the organization's Third-Party Risk Management (TPRM) program by conducting risk assessments, reviewing cybersecurity controls, identifying potential vulnerabilities, and ensuring third parties comply with organizational policies, industry standards, and regulatory requirements.

The successful candidate will evaluate the information security and technology frameworks of external partners, SaaS providers, and financial technology associates. This position enforces strict alignment with banking regulations, manages risk lifecycles inside Archer, and leverages AI technologies to accelerate due diligence and continuous monitoring. TPRM SME will partner with business stakeholders, procurement / contract management teams, security teams, compliance functions, and vendors to identify and mitigate risks throughout the third-party lifecycle.

Key Responsibilities

Third-Party Risk Assessments

  • Conduct cybersecurity, information security, and technology risk assessments of third-party vendors and service providers.
  • Review vendor security documentation, including:
    • SIG questionnaires
    • SOC 1 and SOC 2 reports (may include Bridge Letter verification)
    • ISO 27001 certifications to include SoA reviews
    • Archer Management: Track, document, and manage the end-to-end vendor risk lifecycle within Archer GRC.
    • AI Tool Integration: Use AI-powered risk platforms to parse vendor documentation and summarize control gaps.
    • Security policies and procedures
  • Assess inherent and residual risks associated with third-party relationships.
  • Evaluate vendor compliance with internal policies, security standards, and regulatory requirements.

Risk Analysis and Reporting

  • Identify and document control gaps, vulnerabilities, and areas of concern.
  • Develop risk ratings and provide recommendations for risk mitigation.
  • Prepare concise risk assessment reports and executive-level summaries.
  • Present assessment findings to business owners, risk committees, and senior management.

Ongoing Monitoring

  • Perform periodic reassessments of critical and high-risk vendors.
  • Monitor vendors for cybersecurity incidents, financial instability, regulatory actions, and emerging risks.
  • Track remediation activities and validate corrective actions.
  • Maintain vendor risk profiles and assessment documentation.

Stakeholder Collaboration

  • Partner with Procurement, Information Security, Legal, Compliance, Privacy, and Business Units throughout the vendor lifecycle.
  • Provide guidance regarding security requirements during vendor onboarding and renewals.
  • Support contract reviews by recommending security and data protection requirements.
  • Assist business partners in understanding and managing third-party technology risks.

Governance, Risk, and Compliance

  • Ensure alignment with regulatory requirements and industry frameworks such as:
    • NIST Cybersecurity Framework
    • NIST CRI
    • NIST 800-53
    • NIST 800-171
    • FFIEC Guidance
    • ISO 27001
    • HIPAA (as applicable)
  • Support audits, examinations, and regulatory reviews related to third-party risk.
  • Contribute to continuous improvements of the Third-Party Risk Management Program.

Required Qualifications

Education

  • Bachelor's degree in Information Technology, Information Security, Cybersecurity, Risk Management, Business Administration, or a related field.
  • Equivalent combination of education and experience will be considered.

Experience

  • 5+ years of experience in:
    • Third-Party Risk Management (TPRM)
    • Information Security
    • Cybersecurity Risk Management
    • IT Audit
    • Technology Risk
    • Operational Risk
    • Business Continuity Planning
  • Experience reviewing vendor security assessments and industry-standard assurance reports.
  • Experience working in regulated industries such as financial services, healthcare, insurance, or technology preferred.
  • Banking Knowledge: Solid understanding of financial regulatory expectations regarding data protection and operational resilience.

Technical Knowledge

  • Understanding of cybersecurity principles and security control frameworks.
  • Familiarity with:
    • Access management
    • Network security
    • Cloud security
    • Data protection and encryption
    • Disaster recovery and business continuity
    • Vulnerability management
    • Incident response
    • Service Level Management (Agreements review & verification)
    • Release Management / SDLC
    • IT Asset Management
    • IT Configuration Management
    • Change Management
    • Problem Management
    • System Capacity and Performance
  • Knowledge of vendor risk assessment methodologies and control evaluation techniques.

Preferred Certifications

One or more of the following certifications are preferred:

  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Third-Party Risk Professional (CTPRP)
  • Certified Third Party Risk Assessor (CTPRA)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Cloud Security Professional (CCSP)
  • Security+ or equivalent cybersecurity certification

Key Competencies

  • Risk assessment and analysis
  • Critical thinking and problem solving
  • TPRM Full Lifecycle
  • Information security knowledge
  • Regulatory and compliance awareness
  • Written and verbal communication
  • Executive reporting and presentation skills
  • Attention to detail
  • Stakeholder relationship management
  • Time management and organization

Success Metrics

  • Timely completion of third-party risk assessments.
  • Quality and accuracy of risk evaluations.
  • Reduction of unresolved vendor control issues.
  • Effectiveness of remediation tracking and closure.
  • Compliance with regulatory and internal TPRM requirements.
  • Positive audit and examination outcomes.
  • Continuous improvement of third-party risk processes and controls.

Reporting Structure

Reports To: Head of Data and Financial Operations Transformation

Individual Contributor: Yes

Travel: Minimal (0-10%)

Comp Range: 125k-164k

Work Arrangement: Hybrid (based on business needs)

This position plays a critical role in protecting the organization from cybersecurity, operational, compliance, and reputational risks arising from third-party relationships while enabling the business to engage vendors safely and effectively.

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.

The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.

We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.

 

Bereit, sich bei MUFG zu bewerben?
Bei MUFG bewerben

Über MUFG

At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them! Our Culture Principles Client Centric People Focused Listen Up. Speak Up. Innovate & Simplify Own & Execute

Alle Jobs bei MUFG ansehen →

Ähnliche Jobs

MUFG
AVP, Financial Risk Management
MUFG
⚡ Früh bewerben Toronto, ON Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 6 Std.
MUFG
FX Sales - VP
MUFG
⚡ Früh bewerben Sydney Branch Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
MUFG
Legal Operations Associate - Administrator
MUFG
⚡ Früh bewerben MUFG Global Service Private Lt... · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
MUFG
AVP - Internal Audit - Risk & Legal
MUFG
⚡ Früh bewerben MUFG Global Service Private Lt... · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
MUFG
Debt Capital Markets - Originator, VP
MUFG
⚡ Früh bewerben Singapore - Marina One East To... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
MUFG
Credit Risk Management Officer (AVP)
MUFG
⚡ Früh bewerben Paris Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
MUFG
Vice President/ Director, Regional Relationship Manager
MUFG
⚡ Früh bewerben Singapore Office Marina One Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
MUFG
Governance & Administrative Support Analyst
MUFG
⚡ Früh bewerben MUFG Global Service Private Lt... · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
MUFG
Lead Application Engineer
MUFG
⚡ Früh bewerben MUFG Global Service Private Lt... · standortgebunden
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei MUFG

Alle Jobs bei MUFG ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos