Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
National Trust

Junior Analyst, Third-Party Risk Management

National Trust

Third-Party Risk Management Junior Analyst supporting regulatory compliance in banking industry. Conducting vendor assessments, monitoring risks, and collaborating across teams to manage cybersecurity.

Posted 7/27/2026full-timeRemote • New York • 🇺🇸 United StatesJuniorWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Third-Party Risk Management (TPRM) within a regulated banking environment, focusing on cybersecurity, data protection, and compliance with frameworks such as NIST Cybersecurity Framework and ISO 27001. Proficient in conducting risk assessments, vendor due diligence, and preparing risk reports for leadership.

Highest-signal resume keywords
Third-Party Risk Management (TPRM)NIST Cybersecurity FrameworkISO 27001Risk Assessment MethodologiesVendor Due Diligence

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentCybersecurityData ProtectionVendor ManagementRegulatory ComplianceRisk Mitigation StrategiesIncident ResponseBusiness Continuity PlanningDisaster RecoveryCloud Risk Management
Soft Skills
Analytical ThinkingCommunicationCollaborationProblem SolvingAttention to Detail
Tools & Technologies
TPRM PlatformsAWSSaaS Environments
Industry Keywords
OCC-Regulated Financial InstitutionVendor Security ProgramsSOC 2 Type IIRisk-Based Decision MakingDocumentation Management

Tech Stack

Tools & technologies
AWSCloudCyber Security

About the role

Key responsibilities & impact
  • Support its Third-Party Risk Management program within a highly regulated banking environment.
  • Conduct initial and ongoing risk assessments for new and existing vendors, with emphasis on cybersecurity and data protection.
  • Evaluate vendor due diligence responses, including information security, security architecture, and cloud environments.
  • Identify control gaps and recommend risk mitigation strategies.
  • Assess vendors handling sensitive data, critical systems, or customer information.
  • Support vendor due diligence, concentration risk, fourth-party risk, and business continuity assessments.
  • Assist with preparation for regulatory examinations and internal audits.
  • Maintain documentation demonstrating regulatory compliance and risk-based decision making.
  • Support updates to TPRM policies, procedures, and standards.
  • Assess vendor security programs against recognized frameworks, including: NIST Cybersecurity Framework, ISO 27001, SOC 2 Type II.
  • Support monitoring of critical and high-risk vendors.
  • Track vendor performance, compliance, and remediation activities.
  • Prepare risk summaries and reporting materials for leadership.
  • Escalate significant risks in a timely manner.
  • Review vendor incident response and breach notification processes.
  • Evaluate business continuity and disaster recovery capabilities.
  • Prepare concise risk reports for senior leadership and risk committees.
  • Maintain accurate documentation within the TPRM system.
  • Partner with Information Security, Compliance, Legal, Procurement, and business units.

Requirements

What you’ll need
  • Bachelor's degree in business, Information Security, Cybersecurity, Risk Management, Finance, or related field.
  • 1-3 years of experience in TPRM and Information security risk
  • Experience working in an OCC-regulated financial institution (preferred)
  • Exposure to cloud risk management (AWS, SaaS environments) (preferred)
  • Experience using TPRM platforms (preferred)
  • Working Knowledge of Risk assessment methodologies (inherent vs. residual risk)
  • NIST Cybersecurity Framework
  • ISO 27001
  • SOC 2 reports

Benefits

Comp & perks
  • Medical, Dental, and Vision insurance
  • 401(k)
  • life and disability insurance