The Assistant Vice President, Third-Party Risk Management ("TPRM") is responsible for leading key ... Vendor Relationship Owners, and Subject Matter Experts to identify, assess, and mitigate risks ...
The Assistant Vice President, Third-Party Risk Management ("TPRM") is responsible for leading key ... Vendor Relationship Owners, and Subject Matter Experts to identify, assess, and mitigate risks ...
Contract Administration - Paralegal
Newark, DE · On-site
$53K - $88K/yr
Monitor, maintain and support vendor and clients records including renewals, expirations, insurance requirements, compliance obligations, insurance and risk assessments. * Serve as the primary legal ...
Contract Administration - Paralegal
Newark, DE · On-site
$53K - $88K/yr
Monitor, maintain and support vendor and clients records including renewals, expirations, insurance requirements, compliance obligations, insurance and risk assessments. * Serve as the primary legal ...
Contract Administration - Paralegal
Newark, DE · On-site
$53K - $88K/yr
Monitor, maintain and support vendor and clients records including renewals, expirations, insurance requirements, compliance obligations, insurance and risk assessments. * Serve as the primary legal ...
Contract Administration - Paralegal
Newark, DE · On-site
$53K - $88K/yr
Monitor, maintain and support vendor and clients records including renewals, expirations, insurance requirements, compliance obligations, insurance and risk assessments. * Serve as the primary legal ...
Contract Administration - Paralegal
$53K - $88K/yr
Monitor, maintain and support vendor and clients records including renewals, expirations, insurance requirements, compliance obligations, insurance and risk assessments. * Serve as the primary legal ...
Contract Administration - Paralegal
$53K - $88K/yr
Monitor, maintain and support vendor and clients records including renewals, expirations, insurance requirements, compliance obligations, insurance and risk assessments. * Serve as the primary legal ...
Implementing and managing Third-Party Risk Management (TPRM) frameworks, including vendor due diligence, risk assessments, and ongoing monitoring. * Track and report on vendor spend, savings ...
Implementing and managing Third-Party Risk Management (TPRM) frameworks, including vendor due diligence, risk assessments, and ongoing monitoring. * Track and report on vendor spend, savings ...
Implementing and managing Third-Party Risk Management (TPRM) frameworks, including vendor due diligence, risk assessments, and ongoing monitoring. * Track and report on vendor spend, savings ...
Implementing and managing Third-Party Risk Management (TPRM) frameworks, including vendor due diligence, risk assessments, and ongoing monitoring. * Track and report on vendor spend, savings ...
... model risk management, data governance, information security, vendor risk, and regulatory ... assessment, business case development, funding alignment, benefits estimation, and executive ...
... model risk management, data governance, information security, vendor risk, and regulatory ... assessment, business case development, funding alignment, benefits estimation, and executive ...
... model risk management, data governance, information security, vendor risk, and regulatory ... assessment, business case development, funding alignment, benefits estimation, and executive ...
... model risk management, data governance, information security, vendor risk, and regulatory ... assessment, business case development, funding alignment, benefits estimation, and executive ...
... model risk management, data governance, information security, vendor risk, and regulatory ... assessment, business case development, funding alignment, benefits estimation, and executive ...
... model risk management, data governance, information security, vendor risk, and regulatory ... assessment, business case development, funding alignment, benefits estimation, and executive ...
Director, Credit Risk/First Party Fraud Oversight, Consumer Lending (2nd LOD)
Wilmington, DE · On-site
Assess vendor and third-party risk related to fraud tools, data providers, and service partners Fraud Loss & Performance Monitoring * Monitor fraud trends, loss rates, and emerging threats across the ...
Director, Credit Risk/First Party Fraud Oversight, Consumer Lending (2nd LOD)
Wilmington, DE · On-site
Assess vendor and third-party risk related to fraud tools, data providers, and service partners Fraud Loss & Performance Monitoring * Monitor fraud trends, loss rates, and emerging threats across the ...
Director, Credit Risk/First Party Fraud Oversight, Consumer Lending (2nd LOD)
Wilmington, DE · On-site
Assess vendor and third-party risk related to fraud tools, data providers, and service partners Fraud Loss & Performance Monitoring * Monitor fraud trends, loss rates, and emerging threats across the ...
Director, Credit Risk/First Party Fraud Oversight, Consumer Lending (2nd LOD)
Wilmington, DE · On-site
Assess vendor and third-party risk related to fraud tools, data providers, and service partners Fraud Loss & Performance Monitoring * Monitor fraud trends, loss rates, and emerging threats across the ...
Director, Credit Risk/First Party Fraud Oversight, Consumer Lending (2nd LOD)
Wilmington, DE · On-site
Assess vendor and third-party risk related to fraud tools, data providers, and service partners Fraud Loss & Performance Monitoring * Monitor fraud trends, loss rates, and emerging threats across the ...
Director, Credit Risk/First Party Fraud Oversight, Consumer Lending (2nd LOD)
Wilmington, DE · On-site
Assess vendor and third-party risk related to fraud tools, data providers, and service partners Fraud Loss & Performance Monitoring * Monitor fraud trends, loss rates, and emerging threats across the ...
Serve as a trusted technical advisor to executives and architects; embed security into technology roadmaps, M&A due diligence, and vendor risk assessments. People Management Responsibilities * Builds ...
Serve as a trusted technical advisor to executives and architects; embed security into technology roadmaps, M&A due diligence, and vendor risk assessments. People Management Responsibilities * Builds ...
IT Audit Manager
Wilmington, DE · Remote
Assess vendor due diligence, monitoring, and risk management processes. * Evaluate risks associated with critical vendors and fintech partnerships. * Serve as primary IT Audit liaison with IT ...
IT Audit Manager
Wilmington, DE · Remote
Assess vendor due diligence, monitoring, and risk management processes. * Evaluate risks associated with critical vendors and fintech partnerships. * Serve as primary IT Audit liaison with IT ...
IT Audit Manager
Wilmington, DE · Remote
Assess vendor due diligence, monitoring, and risk management processes. * Evaluate risks associated with critical vendors and fintech partnerships. * Serve as primary IT Audit liaison with IT ...
IT Audit Manager
Wilmington, DE · Remote
Assess vendor due diligence, monitoring, and risk management processes. * Evaluate risks associated with critical vendors and fintech partnerships. * Serve as primary IT Audit liaison with IT ...
Compliance Risk Management Lead - Vice President
$122K - $164K/yr
... and vendor, insurance carrier and/or third party arrangements. * Partner with business leaders to ... Conduct ongoing compliance risk assessments; design and oversee monitoring and testing routines ...
Compliance Risk Management Lead - Vice President
$122K - $164K/yr
... and vendor, insurance carrier and/or third party arrangements. * Partner with business leaders to ... Conduct ongoing compliance risk assessments; design and oversee monitoring and testing routines ...
Compliance Risk Management Lead - Vice President
Wilmington, DE · On-site
$122K - $164K/yr
... and vendor, insurance carrier and/or third party arrangements. * Partner with business leaders to ... Conduct ongoing compliance risk assessments; design and oversee monitoring and testing routines ...
Compliance Risk Management Lead - Vice President
Wilmington, DE · On-site
$122K - $164K/yr
... and vendor, insurance carrier and/or third party arrangements. * Partner with business leaders to ... Conduct ongoing compliance risk assessments; design and oversee monitoring and testing routines ...
Compliance Risk Management Lead - Vice President
Wilmington, DE · On-site
$122K - $164K/yr
... and vendor, insurance carrier and/or third party arrangements. * Partner with business leaders to ... Conduct ongoing compliance risk assessments; design and oversee monitoring and testing routines ...
Compliance Risk Management Lead - Vice President
Wilmington, DE · On-site
$122K - $164K/yr
... and vendor, insurance carrier and/or third party arrangements. * Partner with business leaders to ... Conduct ongoing compliance risk assessments; design and oversee monitoring and testing routines ...
Coordinate internal audits and external assessment engagements, as needed * Centralize and maintain ... Experience with third party and vendor management preferable Summary of Qualifications:
Coordinate internal audits and external assessment engagements, as needed * Centralize and maintain ... Experience with third party and vendor management preferable Summary of Qualifications:
Purchasing Director
Wilmington, DE · On-site
Oversee Vendor/Manufacturer Rebate Programs. * Contract Review: Review existing contracts with ... Perform risk assessments on potential contracts and agreements, identifying and mitigating ...
Quick apply
Purchasing Director
Wilmington, DE · On-site
Oversee Vendor/Manufacturer Rebate Programs. * Contract Review: Review existing contracts with ... Perform risk assessments on potential contracts and agreements, identifying and mitigating ...
Vendor Risk Assessment information
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?
What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?
What is a Vendor Risk Assessment?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 4 days ago
CardWorks rating
9.1
Based on 8 frontline employees who took The Breakroom Quiz
1st of 20 rated payment service providers
Job description
Join our team and build your career with momentum as we champion your growth, elevate your ideas and engage you in purpose-driven work that makes a real difference every day.
Who we are
Founded in 1997, Merrick Bank is an FDIC-insured financial institution headquartered in South Jordan, Utah, with over $10 billion in assets. A wholly owned subsidiary of CardWorks Financial Group, Merrick Bank serves roughly five million cardmembers and more than 100,000 merchant customers nationwide.
What we do
We provide credit cards, recreational loans, deposit accounts, merchant services and bank sponsorships to consumers and businesses. As a leader in non-prime lending and merchant acquiring, we combine innovative technology with data-driven insights to help underserved consumers build and strengthen credit while delivering integrated, scalable payment solutions for businesses.
Merrick Bank ranks among the top 20 FDIC-insured credit card issuers in the U.S. and among the top 15 merchant acquirers by transaction volume.
The Assistant Vice President, Third-Party Risk Management ("TPRM") is responsible for leading key components of the execution, oversight, and strategic enhancement of Merrick Bank's ("Bank") Third-Party Risk Management Program. This role partners across the first and second lines of defense to ensure risks arising from third-party relationships are effectively identified, assessed, monitored, and reported in alignment with regulatory requirements, internal policies, and the Bank's risk appetite.
The AVP serves as a senior program leader responsible for advancing enterprise TPRM strategy, strengthening risk governance, driving consistent risk practices, and delivering actionable insights to senior management and risk governance committees.
Essential Functions:
- Lead the execution and ongoing enhancement of the Bank's Third-Party Risk Management framework, ensuring alignment with regulatory expectations and internal governance standards.
- Oversee risk-based third-party due diligence, risk assessments, and ongoing monitoring activities across the full third-party lifecycle, ensuring consistent, defensible, and risk-informed outcomes.
- Partner with business units, Vendor Relationship Owners, and Subject Matter Experts to identify, assess, and mitigate risks associated with third-party relationships.
- Provide senior level review and challenge of third-party risk assessments, ensuring conclusions are evidence-based, appropriately documented, and escalated when risk exposure exceeds defined thresholds.
- Monitor third-party performance, control effectiveness, and risk indicators, escalating issues, control gaps, and emerging risks in accordance with established governance protocols.
- Lead the design, development, and maintenance of TPRM policies, procedures, standards, and workflows to support a consistent enterprise-wide operating model.
- Define and Deliver executive, committee, and Board-level reporting that provides clear visibility into third-party risk exposure, trends, issues, concentrations, and emerging risks.
- Collaborate with Legal, Procurement, Information Security, Compliance, and business stakeholders to ensure appropriate contract provisions, controls, and risk mitigation strategies are implemented.
- Lead TPRM responses for regulatory exams, internal audits, and independent reviews, including documentation, analysis, issue remediation, and management responses.
- Drive the TPRM program maturity roadmap, including process improvements, automation, data quality, GRC optimization, regulatory alignment, and adoption of industry best practices.
- Leads, develops, and mentors TPRM teams, promoting strong risk culture, accountability, high performance, and continuous improvement.
- Partner with ERM leadership to establish TPRM priorities, roadmap initiatives, governance routines, and success measures aligned to enterprise risk strategy and business objectives.
- Identify and escalate third-party concentration risk, critical vendor risk, fourth-party risk, control gaps, and emerging risk themes to appropriate governance forums.
- Delivers executive, committee, and Board level risk reporting, including dashboards and risk insights that support informed decision making and effective oversight.
- Owns continuous improvement of TPRM tools, data, workflows, reporting, and GRC system capabilities to improve efficiency, transparency, data integrity, and regulatory readiness.
- Performs other duties as assigned.
Requirements for Success:
Education & Experience:
- Bachelor's degree in Risk Management, Finance, Business Administration, Accounting, or a related field required; advanced degree or professional certification, such as CTPRP, CTPRA, CRVPM, CRMA, FRM, CPA, OR CIA preferred.
- Minimum of 8 years of progressive experience in Third-Party Risk Management, Enterprise Risk Management, Operational Risk, or a related risk discipline within a financial services or regulated environment, including experience leading program initiatives, risk governance routines, and team members
Knowledge, Skills and Capabilities:
- Strong expertise in enterprise risk reporting, including development of executive and Board level materials, risk dashboards, metrics, and written risk summaries.
- In-depth knowledge of third-party risk regulatory requirements and industry standards, including full TPRM lifecycle.
- Demonstrated experience aggregating and synthesizing complex risk information into clear, concise, and decision useful reporting for senior management and Boards.
- Solid understanding of ERM frameworks, risk governance practices, and regulatory expectations applicable to banking and financial services organizations.
- Proven ability to work cross functionally, influence stakeholders, and partner effectively with both first and second line teams.
- Excellent written and verbal communication skills, with a strong attention to detail and the ability to translate technical risk concepts into business focused insights.
- Experience with ERM systems and risk data repositories (e.g., risk assessment tools, issue management systems, reporting platforms) strongly preferred.
Compliance with Laws & Regulations
- Responsible for complying with all the Bank's internal control policies and procedures.
- Responsible for understanding and complying with all laws and regulations to which the Bank is subject.
- Responsible for communicating problems in operations, noncompliance with the code of conduct, noncompliance with laws and regulations, policy violations, or illegal acts.
#INDHP1
Why join us
We believe in putting people first by supporting our customers, employees and our partners while creating opportunities for everyone to reach their potential. From fostering work-life balance to rewarding good work and innovative ideas, we invest in what matters most, our people.
At Merrick Bank, you'll be part of a collaborative, customer-focused team where you can grow your career while making a meaningful impact.
Our Employee Value Proposition
- Competitive Pay, including a Bonus Target or Variable Pay Incentive Program
- Benefits Package -Medical, Dental, and Vision (plus much more)
- 401(k) Plan with Company Match
- Short- & Long-Term Disability
- Wellness Programs
- Group Life and AD&D Insurance
- Paid Vacation, Sick Days and bank Holidays
- Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition
We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
We are proud to be an equal opportunity employer. All qualified applicants will receive consideration without regard to age, race, color, sex, or gender identity/expression (including pregnancy, childbirth, transgender status, or sexual orientation), religion or creed, ancestry, citizenship, national origin, disability, military or veteran status, marital status, genetic information, or any other characteristic protected by applicable law.
We do not tolerate discrimination, harassment, or retaliation. Employment decisions are based solely on qualifications, merit, and business needs. Everyone is welcome here, and we hire based on your ability to do the job, not any protected characteristics.
If you need help or reasonable accommodation during the application or hiring process, please let your TA Partner know.
What CardWorks employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom