Cyber Security & Third Party Due Diligence Senior Associate
DTCC · Tampa, United States +2 · 11h ago
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
Our Risk Management teams work to protect the safety and soundness of our systems and are responsible for identifying, managing, measuring and mitigating a spectrum of key risk types including credit, market, liquidity, systemic, operational and technology in all existing and new products, activities, processes and systems.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
In this role, you will support the Cyber Security Due Diligence SME team within the Cyber Security Risk Office (CSRO), responsible for overseeing technology, cyber security, and operational resilience risk assessments across DTCC's third party ecosystem. Your work will directly contribute to strengthening DTCC's Third Party Risk Management program by ensuring effective identification, assessment, monitoring, and remediation of cyber and technology risks associated with vendors, service providers, and other external partners.
You will work closely with Business, Technology, Legal, Sourcing, Resilience, and Risk Management stakeholders to perform due diligence assessments, third party onboarding activities, control gap remediation, onsite reviews, and specialized assessments, including fourth party risk, NYSDFS cybersecurity reviews, encryption key management, and software supply chain security. The role is also responsible for advancing third party cyber risk reviews, enhancing assessment methodologies, and supporting regulatory compliance.
Your Primary Responsibilities:
• Conduct technology, cyber security, operational resilience, and specialized risk assessments of third parties supporting DTCC's critical services
• Provide subject matter expertise on third-party cyber risk management, emerging regulatory requirements, and industry best practices, including NYSDFS Cybersecurity Regulation, operational resilience requirements, software supply chain risk, fourth-party risk, and encryption key management
• Partner closely with Sourcing, Legal, Enterprise Program Management, Architecture Review Board (ARB), Technology, Resilience, Security, and Business stakeholders to support third-party onboarding, contract reviews, and risk-based decision making
• Perform remediation efforts for identified third party control gaps and assessment findings, ensuring appropriate accountability, transparency, and timely risk reduction
• Build strong relationships with internal and external stakeholders. Partner with other internal stakeholders on third party risk activities. Participate in discussions with internal and external stakeholders to plan and execute on process enhancements
• Demonstrate effective written and verbal communication skills, active engagement in meetings and thought leadership. Provide guidance to internal stakeholders on processes and address issues and inquiries timely.
• Prioritize multiple tasks and initiatives. Lead the execution of Third Party Risk Management frameworks and manage project tasks effectively.
• Demonstrate and apply a thorough understanding of risk management processes and activities, with specific focus on key third party risks. Viewed as a subject matter expert.
• Aligns risk and control processes into day to day responsibilities to monitor and mitigate risk; escalates appropriately
• Ensure third-party cyber risk management activities support DTCC's overall risk ma
Qualifications:
- Minimum of 6 years of related experience
Bachelor's degree preferred or equivalent experience
Talents Needed for Success: