About the role
from listingLead third-party risk insights that strengthen vendor cybersecurity, data protection, and resilience decisions.
Help shape how we make confident, well-governed decisions about third-party risk across a large, complex vendor ecosystem. You’ll turn technical assessment outputs into clear, executive-ready insights that protect clients, data, and operations. In this role, you will influence how we identify emerging risk patterns, prioritize remediation, and set consistent control expectations. You’ll partner across risk, technology, legal, procurement, and compliance in a highly visible role with meaningful impact. As an Executive Director in Third-Party Risk and Controls Insights within the Commercial and Investment Bank , you will synthesize, challenge, and communicate key risks and control considerations across the third-party lifecycle (onboarding, change, ongoing monitoring, and exit). You will ensure risk conclusions and decision artifacts are consistent, defensible, and aligned to agreed standards, thresholds, and risk appetite. You will translate vendor security evidence into clear risk narratives, business impact, and actionable recommendations. You will help leaders make informed decisions on risk acceptance, remediation prioritization, and safe vendor adoption. Job responsibilities Aggregate and analyze third-party risk signals with a focus on data protection, cybersecurity, and operational resilience, translating findings into business process impacts and operational risk outcomes. Set and govern standards for risk statements, residual risk framing, materiality thresholds, issue taxonomy, and escalation expectations across the third-party lifecycle. Own quality assurance and constructive challenge of third-party assessment and monitoring outputs to ensure completeness, consistency, and defensibility of conclusions and remediation expectations. Identify and elevate themes across the third-party portfolio (recurring control gaps, common failure modes, concentration hot spots) through appropriate governance forums. Produce decision-grade materials that clearly articulate residual risk, recommended mitigations, and defined decision points tailored to business criticality. Review and advise on business cases for new or expanded third-party engagements, including opportunities to reuse existing vendors and standardize controls or contractual levers. Interpret vendor security evidence (for example, SOC 2 reports, ISO 27001 certification, and industry questionnaires such as Standardized Information Gathering (SIG) and the Consensus Assessments Initiative Questionnaire (CAIQ)) and convert it into clear risk narratives and control gap assessments. Evaluate cloud and software-as-a-service architectures to identify material risks (identity and access management, encryption/key management, logging/monitoring, segmentation, data residency, dependency chains, and concentration risk). Define and maintain a risk insights framework, including risk taxonomy mapping, key risk/key performance indicators, thresholds, trends, and executive-ready reporting. Drive consistency in issue management by setting expectations for classification, documentation quality, evidence standards for closure, and transparent reporting of overdue actions and residual risk. Partner and influence across control management, technology, procurement, legal, compliance, and operational risk to maintain a single, consistent narrative and improve decision usefulness. Required qualifications, capabilities and skills 8 years of experience in control management, operational risk, technology risk, cybersecurity risk, or third-party risk within financial services or a similarly regulated industry. Demonstrated experience across the third-party lifecycle (onboarding, assessment, monitoring, issue management, and exit). Proven ability to synthesize assessment outputs into executive-ready insights, including themes, emerging risks, residual risk framing, and clear recommendations. Strong cybersecurity and technology risk fluency, including the ability to challenge vendor security posture using evidence such as SOC 2 and ISO 27001. Working knowledge of cloud and software-as-a-service control domains (identity and access management, encryption, logging/monitoring, vulnerability management, incident response, and secure development controls). Ability to translate technical risk into business decisions , including trade-offs, materiality, and practical mitigation actions. Experience defining and using key risk/key performance indicators , thresholds, and trend interpretation to drive risk visibility and prioritization. Strong stakeholder management skills, with the ability to influence cross-functional partners and challenge constructively when outputs are not decision-useful. Excellent written and verbal communication skills, including producing concise governance materials for senior stakeholders. Preferred qualifications, capabilities and skills Experience building or running third-party risk portfolio reporting and governance routines , including taxonomy design, thresholds, and thematic reporting. Advanced knowledge of operational resilience practices (service mapping concepts, recovery expectations, dependency analysis, and vendor failure-mode translation). Experience using automation, analytics, and/or AI-enabled approaches to improve monitoring, signal detection, and insights generation (subject to approved tools and controls). Strong executive presence and facilitation skills to drive alignment on remediation priorities, timelines, and risk acceptance decisions. Strong quantitative and narrative capability to combine metrics with clear storytelling for senior decision-makers. Experience improving documentation and evidence standards for issue closure and audit-ready reporting.