The Assistant Vice President, Third-Party Risk Management ("TPRM") is responsible for leading key components of the execution, oversight, and strategic enhancement of Merrick Bank's ("Bank") Third ...
The Assistant Vice President, Third-Party Risk Management ("TPRM") is responsible for leading key components of the execution, oversight, and strategic enhancement of Merrick Bank's ("Bank") Third ...
AVP, Third-Party Risk Management
South Jordan, UT · On-site
$140 - $190/hr
## AVP, Third-Party Risk ManagementApplylocations: South Jordan: Wilmington: Virtual Easttime type: Full timeposted on: Posted 6 Days Agojob requisition id: JR101058**Join our team and build your career ...
AVP, Third-Party Risk Management
South Jordan, UT · On-site
$140 - $190/hr
## AVP, Third-Party Risk ManagementApplylocations: South Jordan: Wilmington: Virtual Easttime type: Full timeposted on: Posted 6 Days Agojob requisition id: JR101058**Join our team and build your career ...
Conduct risk reviews and identify potential vulnerabilities across a variety of risk domains for Adobe's third-party ecosystem * Assist in project delivery of the TPRM module within Global Source to ...
Quick apply
Conduct risk reviews and identify potential vulnerabilities across a variety of risk domains for Adobe's third-party ecosystem * Assist in project delivery of the TPRM module within Global Source to ...
Job Summary The Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union's Enterprise and Operational Risk function, reporting to the Vice President ...
Job Summary The Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union's Enterprise and Operational Risk function, reporting to the Vice President ...
Job Summary The Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union's Enterprise and Operational Risk function, reporting to the Vice President ...
Job Summary The Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union's Enterprise and Operational Risk function, reporting to the Vice President ...
Affiliate Transactions and Third-Party Risk Management Lead
Salt Lake City, UT · On-site
$90 - $130/hr
Collaborate in the development and implementation of the Bank's Third-party and Affiliate Transaction risk management programs to align with the Bank's risk appetite and comply with regulatory ...
Affiliate Transactions and Third-Party Risk Management Lead
Salt Lake City, UT · On-site
$90 - $130/hr
Collaborate in the development and implementation of the Bank's Third-party and Affiliate Transaction risk management programs to align with the Bank's risk appetite and comply with regulatory ...
GRC Security Manager
West Valley City, UT · On-site
$150K - $165K/yr
Oversee third-party security evaluations, including due diligence reviews, risk assessments, and collaboration on contract-related security requirements. * Identify cybersecurity concerns associated ...
Quick apply
GRC Security Manager
West Valley City, UT · On-site
$150K - $165K/yr
Oversee third-party security evaluations, including due diligence reviews, risk assessments, and collaboration on contract-related security requirements. * Identify cybersecurity concerns associated ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
Create approval, risk review, and assessment procedures before AI solutions move into production ... Evaluate AI agents, autonomous workflows, and third-party AI platforms for security, privacy ...
Create approval, risk review, and assessment procedures before AI solutions move into production ... Evaluate AI agents, autonomous workflows, and third-party AI platforms for security, privacy ...
Director of Cyber Security
Draper, UT · On-site
$200K - $250K/yr
This leader will work closely with executives and cross-functional teams to strengthen risk ... Proven success leading and mentoring security professionals, contractors, and third-party service ...
Quick apply
Director of Cyber Security
Draper, UT · On-site
$200K - $250K/yr
This leader will work closely with executives and cross-functional teams to strengthen risk ... Proven success leading and mentoring security professionals, contractors, and third-party service ...
The position also supports broader enterprise risk management efforts by aligning third-party reviews with organizational risk standards and preparing clear, well-supported risk documentation. If you ...
New
The position also supports broader enterprise risk management efforts by aligning third-party reviews with organizational risk standards and preparing clear, well-supported risk documentation. If you ...
New
Senior Vendor Risk Analyst - Remote
Draper, UT · On-site +1
The position also supports broader enterprise risk management efforts by aligning third-party reviews with organizational risk standards and preparing clear, well-supported risk documentation. If you ...
New
Senior Vendor Risk Analyst - Remote
Draper, UT · On-site +1
The position also supports broader enterprise risk management efforts by aligning third-party reviews with organizational risk standards and preparing clear, well-supported risk documentation. If you ...
New
... Systems, Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of ... Experience assessing third-party/vendor risk, including AI vendors and cloud service providers.
... Systems, Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of ... Experience assessing third-party/vendor risk, including AI vendors and cloud service providers.
Claims & Risk Manager
Midvale, UT · On-site +1
The Claims and Risk Manager plays a pivotal role in identifying, analyzing and mitigating risks ... Manage relationships with third party service providers including brokers, insurers and other TPAs.
Quick apply
Claims & Risk Manager
Midvale, UT · On-site +1
The Claims and Risk Manager plays a pivotal role in identifying, analyzing and mitigating risks ... Manage relationships with third party service providers including brokers, insurers and other TPAs.
Familiarity with interagency third-party risk management guidance and partner governance expectations. * Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations ...
Familiarity with interagency third-party risk management guidance and partner governance expectations. * Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations ...
Familiarity with interagency third-party risk management guidance and partner governance expectations. * Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations ...
Familiarity with interagency third-party risk management guidance and partner governance expectations. * Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations ...
Compliance & Risk Manager (On-site/Hybrid/Remote)
Ogden, UT · On-site
$74K - $145K/yr
Collaborate with IT on cybersecurity policy development, employee training, and annual third-party assessments or penetration tests. * Support the implementation and monitoring of supplier risk ...
Quick apply
Compliance & Risk Manager (On-site/Hybrid/Remote)
Ogden, UT · On-site
$74K - $145K/yr
Collaborate with IT on cybersecurity policy development, employee training, and annual third-party assessments or penetration tests. * Support the implementation and monitoring of supplier risk ...
Enterprise Risk Manager
Lehi, UT · On-site
... Systems, Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of ... Experience assessing third-party/vendor risk, including AI vendors and cloud service providers.
Enterprise Risk Manager
Lehi, UT · On-site
... Systems, Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of ... Experience assessing third-party/vendor risk, including AI vendors and cloud service providers.
Java Web Developer
Salt Lake City, UT · On-site
... third-party services and APIs into the application. • Troubleshoot, debug, and enhance existing ... Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management.
Java Web Developer
Salt Lake City, UT · On-site
... third-party services and APIs into the application. • Troubleshoot, debug, and enhance existing ... Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management.
Third Party Cybersecurity Risk information
What is the difference between Third Party Cybersecurity Risk vs Cybersecurity Analyst?
| Aspect | Third Party Cybersecurity Risk | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CompTIA Security+, CEH |
| Work Environment | Vendor assessments, risk management teams, client organizations | Security operations centers, IT departments, consulting firms |
| Industry Usage | Supply chain, vendor management, compliance | Network security, incident response, vulnerability assessment |
Third Party Cybersecurity Risk professionals focus on evaluating and managing risks from external vendors and partners, ensuring compliance and reducing supply chain vulnerabilities. Cybersecurity Analysts primarily monitor, analyze, and respond to security threats within an organization’s own systems. While both roles require security certifications and involve risk assessment, their focus areas and work environments differ significantly.
What are popular job titles related to Third Party Cybersecurity Risk jobs in Utah?
For Third Party Cybersecurity Risk jobs in Utah, the most frequently searched job titles are:
What job categories do people searching Third Party Cybersecurity Risk jobs in Utah look for?
The top searched job categories for Third Party Cybersecurity Risk jobs in Utah are:
What cities in Utah are hiring for Third Party Cybersecurity Risk jobs?
Cities in Utah with the most Third Party Cybersecurity Risk job openings:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 16 days ago
CardWorks rating
9.1
Based on 8 frontline employees who took The Breakroom Quiz
1st of 21 rated payment service providers
Job description
Join our team and build your career with momentum as we champion your growth, elevate your ideas and engage you in purpose-driven work that makes a real difference every day.
Who we are
Founded in 1997, Merrick Bank is an FDIC-insured financial institution headquartered in South Jordan, Utah, with over $10 billion in assets. A wholly owned subsidiary of CardWorks Financial Group, Merrick Bank serves roughly five million cardmembers and more than 100,000 merchant customers nationwide.
What we do
We provide credit cards, recreational loans, deposit accounts, merchant services and bank sponsorships to consumers and businesses. As a leader in non-prime lending and merchant acquiring, we combine innovative technology with data-driven insights to help underserved consumers build and strengthen credit while delivering integrated, scalable payment solutions for businesses.
Merrick Bank ranks among the top 20 FDIC-insured credit card issuers in the U.S. and among the top 15 merchant acquirers by transaction volume.
The Assistant Vice President, Third-Party Risk Management ("TPRM") is responsible for leading key components of the execution, oversight, and strategic enhancement of Merrick Bank's ("Bank") Third-Party Risk Management Program. This role partners across the first and second lines of defense to ensure risks arising from third-party relationships are effectively identified, assessed, monitored, and reported in alignment with regulatory requirements, internal policies, and the Bank's risk appetite.
The AVP serves as a senior program leader responsible for advancing enterprise TPRM strategy, strengthening risk governance, driving consistent risk practices, and delivering actionable insights to senior management and risk governance committees.
Essential Functions:
- Lead the execution and ongoing enhancement of the Bank's Third-Party Risk Management framework, ensuring alignment with regulatory expectations and internal governance standards.
- Oversee risk-based third-party due diligence, risk assessments, and ongoing monitoring activities across the full third-party lifecycle, ensuring consistent, defensible, and risk-informed outcomes.
- Partner with business units, Vendor Relationship Owners, and Subject Matter Experts to identify, assess, and mitigate risks associated with third-party relationships.
- Provide senior level review and challenge of third-party risk assessments, ensuring conclusions are evidence-based, appropriately documented, and escalated when risk exposure exceeds defined thresholds.
- Monitor third-party performance, control effectiveness, and risk indicators, escalating issues, control gaps, and emerging risks in accordance with established governance protocols.
- Lead the design, development, and maintenance of TPRM policies, procedures, standards, and workflows to support a consistent enterprise-wide operating model.
- Define and Deliver executive, committee, and Board-level reporting that provides clear visibility into third-party risk exposure, trends, issues, concentrations, and emerging risks.
- Collaborate with Legal, Procurement, Information Security, Compliance, and business stakeholders to ensure appropriate contract provisions, controls, and risk mitigation strategies are implemented.
- Lead TPRM responses for regulatory exams, internal audits, and independent reviews, including documentation, analysis, issue remediation, and management responses.
- Drive the TPRM program maturity roadmap, including process improvements, automation, data quality, GRC optimization, regulatory alignment, and adoption of industry best practices.
- Leads, develops, and mentors TPRM teams, promoting strong risk culture, accountability, high performance, and continuous improvement.
- Partner with ERM leadership to establish TPRM priorities, roadmap initiatives, governance routines, and success measures aligned to enterprise risk strategy and business objectives.
- Identify and escalate third-party concentration risk, critical vendor risk, fourth-party risk, control gaps, and emerging risk themes to appropriate governance forums.
- Delivers executive, committee, and Board level risk reporting, including dashboards and risk insights that support informed decision making and effective oversight.
- Owns continuous improvement of TPRM tools, data, workflows, reporting, and GRC system capabilities to improve efficiency, transparency, data integrity, and regulatory readiness.
- Performs other duties as assigned.
Requirements for Success:
Education & Experience:
- Bachelor's degree in Risk Management, Finance, Business Administration, Accounting, or a related field required; advanced degree or professional certification, such as CTPRP, CTPRA, CRVPM, CRMA, FRM, CPA, OR CIA preferred.
- Minimum of 8 years of progressive experience in Third-Party Risk Management, Enterprise Risk Management, Operational Risk, or a related risk discipline within a financial services or regulated environment, including experience leading program initiatives, risk governance routines, and team members
Knowledge, Skills and Capabilities:
- Strong expertise in enterprise risk reporting, including development of executive and Board level materials, risk dashboards, metrics, and written risk summaries.
- In-depth knowledge of third-party risk regulatory requirements and industry standards, including full TPRM lifecycle.
- Demonstrated experience aggregating and synthesizing complex risk information into clear, concise, and decision useful reporting for senior management and Boards.
- Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations applicable to banking and financial services organizations.
- Proven ability to work cross functionally, influence stakeholders, and partner effectively with both first and second line teams.
- Excellent written and verbal communication skills, with a strong attention to detail and the ability to translate technical risk concepts into business focused insights.
- Experience with ERM systems and risk data repositories (e.g., risk assessment tools, issue management systems, reporting platforms) strongly preferred.
Compliance with Laws & Regulations
- Responsible for complying with all the Bank's internal control policies and procedures.
- Responsible for understanding and complying with all laws and regulations to which the Bank is subject.
- Responsible for communicating problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts.
#INDHP1
Why join us
We believe in putting people first by supporting our customers, employees and our partners while creating opportunities for everyone to reach their potential. From fostering work-life balance to rewarding good work and innovative ideas, we invest in what matters most, our people.
At Merrick Bank, you'll be part of a collaborative, customer-focused team where you can grow your career while making a meaningful impact.
Our Employee Value Proposition
- Competitive Pay, including a Bonus Target or Variable Pay Incentive Program
- Benefits Package -Medical, Dental, and Vision (plus much more)
- 401(k) Plan with Company Match
- Short- & Long-Term Disability
- Wellness Programs
- Group Life and AD&D Insurance
- Paid Vacation, Sick Days and bank Holidays
- Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition
We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
We are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to age, race, color, sex, or gender identity/expression (including pregnancy, childbirth, transgender status, or sexual orientation), religion or creed, ancestry, citizenship, national origin, disability, military or veteran status, marital status, genetic information, or any other characteristic protected by applicable law.
We do not tolerate discrimination, harassment, or retaliation. Employment decisions are based solely on qualifications, merit, and business needs. Everyone is welcome here, and we hire based on your ability to do the job, not any protected characteristics.
If you need help or reasonable accommodation during the application or hiring process, please let your TA Partner know.
What CardWorks employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom