Familiarity with interagency third-party risk management guidance and partner governance expectations. * Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations ...
Familiarity with interagency third-party risk management guidance and partner governance expectations. * Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations ...
Oversee vendor management, third-party relationships, and technology spend to maximize value and efficiency. Cybersecurity, Risk & Compliance * Own and evolve Bridge's global cybersecurity strategy ...
Oversee vendor management, third-party relationships, and technology spend to maximize value and efficiency. Cybersecurity, Risk & Compliance * Own and evolve Bridge's global cybersecurity strategy ...
Oversee vendor management, third-party relationships, and technology spend to maximize value and efficiency. Cybersecurity, Risk & Compliance * Own and evolve Bridge's global cybersecurity strategy ...
Oversee vendor management, third-party relationships, and technology spend to maximize value and efficiency. Cybersecurity, Risk & Compliance * Own and evolve Bridge's global cybersecurity strategy ...
Compliance & Risk Manager (On-site/Hybrid/Remote)
Ogden, UT · On-site
$74K - $145K/yr
Collaborate with IT on cybersecurity policy development, employee training, and annual third-party assessments or penetration tests. * Support the implementation and monitoring of supplier risk ...
Quick apply
Compliance & Risk Manager (On-site/Hybrid/Remote)
Ogden, UT · On-site
$74K - $145K/yr
Collaborate with IT on cybersecurity policy development, employee training, and annual third-party assessments or penetration tests. * Support the implementation and monitoring of supplier risk ...
Experience evaluating business, merchants, dealer, or third-party risk * Strong analytical and problem-solving skills with the ability to assess information and make sound recommendations * Ability ...
Experience evaluating business, merchants, dealer, or third-party risk * Strong analytical and problem-solving skills with the ability to assess information and make sound recommendations * Ability ...
Enterprise Risk Manager
Lehi, UT · On-site
... Systems, Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of ... Experience assessing third-party/vendor risk, including AI vendors and cloud service providers.
New
Enterprise Risk Manager
Lehi, UT · On-site
... Systems, Cybersecurity, or a related field, or equivalent practical experience. * 5+ years of ... Experience assessing third-party/vendor risk, including AI vendors and cloud service providers.
New
Java Web Developer
Salt Lake City, UT · On-site
... third-party services and APIs into the application. • Troubleshoot, debug, and enhance existing ... Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management.
Java Web Developer
Salt Lake City, UT · On-site
... third-party services and APIs into the application. • Troubleshoot, debug, and enhance existing ... Cybersecurity & Risk management, Testing, Forensics & Fraud services and human capital management.
Senior Enterprise Cybersecurity Policy Writer
Ogden, UT · On-site
$120K - $170K/yr
Experience with Governance, Risk, and Compliance (GRC) tools and platforms. * Familiarity with ... We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this ...
Senior Enterprise Cybersecurity Policy Writer
Ogden, UT · On-site
$120K - $170K/yr
Experience with Governance, Risk, and Compliance (GRC) tools and platforms. * Familiarity with ... We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this ...
Senior Enterprise Cybersecurity Policy Writer
Ogden, UT · On-site
$120K - $170K/yr
Experience with Governance, Risk, and Compliance (GRC) tools and platforms. * Familiarity with ... We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this ...
Senior Enterprise Cybersecurity Policy Writer
Ogden, UT · On-site
$120K - $170K/yr
Experience with Governance, Risk, and Compliance (GRC) tools and platforms. * Familiarity with ... We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this ...
Senior Enterprise Cybersecurity Policy Writer
$120K - $170K/yr
Experience with Governance, Risk, and Compliance (GRC) tools and platforms. * Familiarity with ... We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this ...
Quick apply
Senior Enterprise Cybersecurity Policy Writer
$120K - $170K/yr
Experience with Governance, Risk, and Compliance (GRC) tools and platforms. * Familiarity with ... We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this ...
IT Governance Analyst
Salt Lake City, UT · On-site
$81K - $129K/yr
... and risk mitigation associated with third-party vendors and suppliers. This role serves as a ... focus on technology, cybersecurity, data privacy,and regulatory risks * Provides support to ...
New
IT Governance Analyst
Salt Lake City, UT · On-site
$81K - $129K/yr
... and risk mitigation associated with third-party vendors and suppliers. This role serves as a ... focus on technology, cybersecurity, data privacy,and regulatory risks * Provides support to ...
New
Oversee and perform technology security risk assessments * Perform due diligence reviews and manage ... Evaluate and manage privacy risks associated with third-party vendors, business partners, and data ...
Oversee and perform technology security risk assessments * Perform due diligence reviews and manage ... Evaluate and manage privacy risks associated with third-party vendors, business partners, and data ...
Third Party Risk Management (TPRM) Oversight * Oversee the Bank's adherence to Nelnet Inc.'s Third Party Risk Management program, including risk tiering, due diligence, contract review, and ongoing ...
Third Party Risk Management (TPRM) Oversight * Oversee the Bank's adherence to Nelnet Inc.'s Third Party Risk Management program, including risk tiering, due diligence, contract review, and ongoing ...
Third Party Risk Management (TPRM) Oversight * Oversee the Bank's adherence to Nelnet Inc.'s Third Party Risk Management program, including risk tiering, due diligence, contract review, and ongoing ...
New
Third Party Risk Management (TPRM) Oversight * Oversee the Bank's adherence to Nelnet Inc.'s Third Party Risk Management program, including risk tiering, due diligence, contract review, and ongoing ...
New
Compliance Specialist (Sandy, UT)
$30.29 - $37.98/hr
... cybersecurity, regulatory, and reputational risks associated with vendors Support internal ... Vendor Risk Management and third-party risk oversight Internal auditing and regulatory compliance ...
Compliance Specialist (Sandy, UT)
$30.29 - $37.98/hr
... cybersecurity, regulatory, and reputational risks associated with vendors Support internal ... Vendor Risk Management and third-party risk oversight Internal auditing and regulatory compliance ...
Compliance Specialist (Sandy, UT)
Sandy, UT · On-site
$30.29 - $37.98/hr
Conduct vendor due diligence and ongoing risk assessments for third-party vendors and referral ... Evaluate operational, financial, cybersecurity, regulatory, and reputational risks associated with ...
Compliance Specialist (Sandy, UT)
Sandy, UT · On-site
$30.29 - $37.98/hr
Conduct vendor due diligence and ongoing risk assessments for third-party vendors and referral ... Evaluate operational, financial, cybersecurity, regulatory, and reputational risks associated with ...
Compliance Specialist (Sandy, UT)
Sandy, UT · On-site
$30.29 - $37.98/hr
... ongoing risk assessments for third-party vendors and referral partners • Monitor vendor ... cybersecurity, regulatory, and reputational risks associated with vendors • Support internal ...
Compliance Specialist (Sandy, UT)
Sandy, UT · On-site
$30.29 - $37.98/hr
... ongoing risk assessments for third-party vendors and referral partners • Monitor vendor ... cybersecurity, regulatory, and reputational risks associated with vendors • Support internal ...
Oversee and perform technology security risk assessments * Perform due diligence reviews and manage ... Evaluate and manage privacy risks associated with third-party vendors, business partners, and data ...
Oversee and perform technology security risk assessments * Perform due diligence reviews and manage ... Evaluate and manage privacy risks associated with third-party vendors, business partners, and data ...
Risk Director
Salt Lake City, UT · On-site
Serve as the company's primary liaison with brokers, insurers, and third-party administrators. * Evaluate and improve risk allocation across contracts to align with business objectives. Claims and ...
Risk Director
Salt Lake City, UT · On-site
Serve as the company's primary liaison with brokers, insurers, and third-party administrators. * Evaluate and improve risk allocation across contracts to align with business objectives. Claims and ...
Risk Director
Salt Lake City, UT · On-site
Serve as the company's primary liaison with brokers, insurers, and third-party administrators. * Evaluate and improve risk allocation across contracts to align with business objectives. Claims and ...
Risk Director
Salt Lake City, UT · On-site
Serve as the company's primary liaison with brokers, insurers, and third-party administrators. * Evaluate and improve risk allocation across contracts to align with business objectives. Claims and ...
Third Party Cybersecurity Risk information
What is the difference between Third Party Cybersecurity Risk vs Cybersecurity Analyst?
| Aspect | Third Party Cybersecurity Risk | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CompTIA Security+, CEH |
| Work Environment | Vendor assessments, risk management teams, client organizations | Security operations centers, IT departments, consulting firms |
| Industry Usage | Supply chain, vendor management, compliance | Network security, incident response, vulnerability assessment |
Third Party Cybersecurity Risk professionals focus on evaluating and managing risks from external vendors and partners, ensuring compliance and reducing supply chain vulnerabilities. Cybersecurity Analysts primarily monitor, analyze, and respond to security threats within an organization’s own systems. While both roles require security certifications and involve risk assessment, their focus areas and work environments differ significantly.

Senior Risk Analyst, Enterprise Risk Management (Bank Origination)
South Jordan, UT • On-site
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 27 days ago
CardWorks rating
9.1
Based on 8 frontline employees who took The Breakroom Quiz
1st of 21 rated payment service providers
Job description
Join our team and build your career with momentum as we champion your growth, elevate your ideas and engage you in purpose-driven work that makes a real difference every day.
Who we are
Founded in 1997, Merrick Bank is an FDIC-insured financial institution headquartered in South Jordan, Utah, with over $10 billion in assets. A wholly owned subsidiary of CardWorks Financial Group, Merrick Bank serves roughly five million cardmembers and more than 100,000 merchant customers nationwide.
What we do
We provide credit cards, recreational loans, deposit accounts, merchant services and bank sponsorships to consumers and businesses. As a leader in non-prime lending and merchant acquiring, we combine innovative technology with data-driven insights to help underserved consumers build and strengthen credit while delivering integrated, scalable payment solutions for businesses.
Merrick Bank ranks among the top 20 FDIC-insured credit card issuers in the U.S. and among the top 15 merchant acquirers by transaction volume.
Essential Functions:
- Supports the execution of the ERM program across the Bank, ensuring consistency in risk identification, assessment, monitoring, and reporting practices.
- Contributes to the development and enhancement of risk reporting and governance processes for Bank Origination and other key risk programs.
- Supports second-line oversight of risks arising from Bank Origination programs through aggregation and analysis of risk related data.
- Assists in monitoring risk exposures, including identification of emerging risks, trends, and concentration risks.
- Partners with first and second-line stakeholders and subject matter experts to collect, validate, and challenge risk inputs.
- Aggregates and analyzes risk information from multiple sources, including risk assessments and risk monitoring activities, to support Bank-level reporting.
- Supports risk appetite monitoring processes, including identification and escalation of threshold breaches or adverse trends.
- Prepares and maintains risk dashboards, key risk indicators (KRIs), and trend analyses for management review.
- Supports the development and maintenance of enterprise risk profiles and supporting documentation.
- Produces concise, decision-useful reporting for senior management and risk governance committees.
- Ensures alignment with internal governance standards, policies, and regulatory expectations.
- Performs other duties as assigned.
Compliance with Laws & Regulations:
- Responsible for complying with all of the Bank's internal control policies and procedures.
- Responsible for understanding and complying with all laws and regulations to which the Bank is subject.
- Responsible for communicating problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts.
Education and Experience:
- Bachelor's degree in Risk Management, Finance, Business Administration, Accounting, or a related field required; advanced degree or professional certification (e.g., CRMA, FRM, CPA, CIA) preferred.
- Minimum of 3-5 years of progressive experience in Enterprise Risk Management, Operational Risk, Third-Party Risk Management or a related risk discipline within a financial services or regulated environment..
Summary of Qualifications:
- Experience supporting Bank Origination, fintech partnership, or third-party risk oversight activities.
- Familiarity with interagency third-party risk management guidance and partner governance expectations.
- Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations applicable to banking and financial services organizations.
- Proven ability to work cross functionally, influence stakeholders, and partner effectively with both first and second line teams.
- Excellent written and verbal communication skills, with a strong attention to detail and the ability to translate technical risk concepts into business focused insights.
- Experience with ERM systems and risk data repositories (e.g., risk assessment tools, issue management systems, reporting platforms) is strongly preferred.
Work Environment/Physical Demands: Light
The physical requirements described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
This is largely a sedentary role; however, some filing is required. This would require the ability to lift files, open filing cabinets, and bend or stand on a stool as necessary.
Security Responsibilities - General:
This classification requires heightened security awareness to safeguard the Bank's data, including customer non-public personal information. This security level means that the job includes exposure to all categories of Bank data, including customer non-public personal information.
General Disclosure:
The above statements reflect the general information considered necessary to describe the principal functions of the job and should not be considered as a detailed description of all work requirements that may be inherent to the position. In addition, the incumbent may be called upon to personally handle projects or assignments not usually related to the position's day-to-day activities. Understand and comply with laws and regulations that are applicable to my job function. Understand and comply with company policies and procedures that are applicable to my job function.
#INDHP1
Why join us
We believe in putting people first by supporting our customers, employees and our partners while creating opportunities for everyone to reach their potential. From fostering work-life balance to rewarding good work and innovative ideas, we invest in what matters most, our people.
At Merrick Bank, you'll be part of a collaborative, customer-focused team where you can grow your career while making a meaningful impact.
Our Employee Value Proposition
- Competitive Pay, including a Bonus Target or Variable Pay Incentive Program
- Benefits Package -Medical, Dental, and Vision (plus much more)
- 401(k) Plan with Company Match
- Short- & Long-Term Disability
- Wellness Programs
- Group Life and AD&D Insurance
- Paid Vacation, Sick Days and bank Holidays
- Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition
We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
We are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to age, race, color, sex, or gender identity/expression (including pregnancy, childbirth, transgender status, or sexual orientation), religion or creed, ancestry, citizenship, national origin, disability, military or veteran status, marital status, genetic information, or any other characteristic protected by applicable law.
We do not tolerate discrimination, harassment, or retaliation. Employment decisions are based solely on qualifications, merit, and business needs. Everyone is welcome here, and we hire based on your ability to do the job, not any protected characteristics.
If you need help or reasonable accommodation during the application or hiring process, please let your TA Partner know.
What CardWorks employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom