Third-Party Risk Consultant, ETX Governance, Risk & Compliance TeamFull-Time, Springfield/BostonThe OpportunityAs a Third-Party Risk Consultant, you will play a crucial role in implementing the third-party risk framework. This position is responsible for executing third-party risk assessments and due diligence activities across the MassMutual's third-party ecosystem. Additionally, you will support the adoption of risk management practices across the ETX organization. As a key member of the ETX Third-Party Technology Assurance team, you will help drive change and enhance operational efficiency throughout the organization.The TeamThe ETX Governance, Risk & Compliance Team is comprised of governance and risk professionals responsible for implementing governance processes and risk management practices for the ETX (Information Technology) organization. We work closely with our business and technology partners and succeed together by designing practical and effective technology governance and risk management solutions to increase operational efficiency.The Impact Analyze third-party services, data flows, and system integrations to identify and recommend inherent and residual risk exposure.Collaborate with issue management teams to ensure identified risks, including vulnerabilities, are appropriately tracked, communicated, and remediatedContribute to status reporting and metrics tracking for ongoing third-party risk activitiesEvaluate, document, communicate, and support breach event and incident response activitiesExecute risk evaluation procedures by reviewing evidence, documenting observations, and recording results in accordance with defined templates and quality standardsIdentify control gaps, weaknesses, or non-compliance issues and clearly document and recommend findings for further review and dispositionPartner with senior practitioners to support risk rating determinations and escalation decisionsApply knowledge and discretion when performing risk assessments to ensure third parties meet security and technology standards in alignment with established practices and proceduresProactively escalate delays, gaps in information, or emerging risks to the team leadResearch and consult with internal subject matter experts to understand and document risk identified through risk assessments and due diligence practices, and communicate the findings to stakeholdersThe Minimum Qualifications2+ years of experience in risk management and/or completing third-party risk assessments2+ years of experience implementing metrics to track status, identify trends, and surface potential issues2+ years of experience working in an enterprise GRC platform, including proficient use of Excel import/export functionsThe Ideal QualificationsBachelor's degree, preferably in technology, cybersecurity, risk management, or business-related field3+ years of experience in third-party risk management, technology risk, cybersecurity, audit, or testing controlsProficiency with SharePoint and related tools used to execute an effective regulatory compliance programExperience communicating regulatory requirements to technical and non-technical audiences, and facilitating discussions between ETX owners, Compliance, and Law to ensure a shared understanding and effective complianceFoundational understanding of third-party risk domains, including:Cybersecurity and data protectionCloud/SaaS risk considerationsIdentity and access management (e.g., SSO vs. standalone access)Business continuity and resiliencyFamiliarity with industry frameworks such as NIST, ISO 27001, SOC 2, or similarAbility to interpret control evidence and assess adequacy relative to riskStrong written and verbal communication skills, with the ability to interact effectively with internal stakeholders and third partiesDemonstrated ability to execute with limited guidance while meeting deadlines in a structured, process-driven environmentStrong attention to detail and documentation disciplineWhat You Can Expe
Not specified in the original listing.
Not specified in the original listing.