Hiring.Camp

Director- Third Party Risk and Business Continuity

Macu

·

Yesterday

Location
Mountain America Center - Hybrid (0152), United States of America
Workplace
Hybrid, Onsite
Type
Full-time
Seniority
Director
Experience
8+ years
Source
Workday

Description

Please reference the schedule and minimum qualifications listed below before applying.

If you need assistance with filling out our application form or during any phase of the application, interview, or employment process, please notify our Human Resources Team at 801-366-6947 option 1 or email [email protected] and every reasonable effort will be made to accommodate your needs in a timely manner.

Job Summary

The Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union’s Enterprise and Operational Risk function, reporting to the Vice President of Enterprise and Operational Risk. The role is responsible for overseeing the day-to-day execution and continued maturity of the third-party risk management and operational resilience programs, including business continuity, crisis management, operational scenario analysis, and alignment with technology recovery capabilities and disaster recovery dependencies. As part of the second line of defense, the Director partners with business units, Legal, Procurement, Compliance, IT, Information Security, and other stakeholders to align program execution with strategic objectives, regulatory expectations, and enterprise risk standards.

Job Description

LOCATION

Mountain America Center - Hybrid

9800 S Monroe St
Sandy, UT 84070

SCHEDULE

Full Time; this is a hybrid schedule with some weekly in office expectation, based on business need.

To be effective, an individual must be able to perform each job duty successfully.

Business Continuity and Operational Resilience

  • Lead the design, implementation, testing, and continued maturity of the enterprise business continuity and operational resilience program, including business impact analyses, risk assessments, operational scenario analysis, tabletop exercises, and crisis management simulations.
  • Partner with IT and Information Security to align business continuity planning with technology recovery capabilities, disaster recovery dependencies, and business response requirements.
  • Coordinate crisis response governance, escalation protocols, decision rights, leadership communications, situational risk reporting, lessons learned, and prioritized remediation for significant operational events.
  • Monitor emerging threats and trends, including cyber, technology, supply chain, regulatory, physical security, climate, and geopolitical events; maintain related program documentation, reporting, and remediation visibility for operational continuity risks.

Third-Party Risk and Contract Oversight

  • Direct the continued maturity of a scalable third-party risk management program aligned to the credit union’s vendor ecosystem, operational complexity, internal governance standards, and regulatory expectations.
  • Oversee the third-party risk lifecycle, including due diligence, risk assessments, contract risk reviews, ongoing monitoring, issue escalation, remediation tracking, exit planning, and senior-level credible challenge of evidence-based risk conclusions.
  • Partner with business units, Vendor Relationship Owners, Subject Matter Experts, Legal, Procurement, Information Security, Compliance, and other stakeholders to identify, assess, mitigate, monitor, and document third-party risks, contract provisions, controls, and risk mitigation strategies.
  • Monitor third-party performance, control effectiveness, key risk indicators, critical vendor exposure, concentration risk, fourth-party risk, and emerging risk themes, escalating issues when risk exposure exceeds defined thresholds.
  • Lead TPRM responses for regulatory exams, internal audits, and independent reviews, including documentation, analysis, issue remediation, and management responses.
  • Drive the TPRM program maturity roadmap, including process improvements, automation, data quality, GRC optimization, regulatory alignment, and adoption of sound industry practices.
  • Provide executive, committee, and Board-level reporting and recommendations on third-party risk exposure, trends, issues, concentrations, emerging risks, program maturity, remediation priorities, and related governance documentation.

Education and Experience

  • Bachelor’s degree in finance, risk management, business administration, economics, or related field required; advanced degree preferred.
  • Minimum of 8 years of experience in enterprise risk, operational risk, business continuity, third-party risk management, contract management, or related risk disciplines.
  • Minimum of 3 years of experience leading teams, business processes, or cross-functional initiatives with notable risk and complexity.
  • Experience developing or maturing risk, resilience, third-party, or contract management programs in a regulated financial institution preferred.
  • Understanding of ERM frameworks, operational resilience expectations, third-party risk lifecycle practices, contract risk considerations, and regulatory expectations for financial institutions.
  • Understanding of SOC 2, SSAE-18, financial statements, business impact analysis, recovery planning, operational scenario analysis, and crisis response practices.

Certifications

  •  Preferred certifications: CTPRP, ORCE, CRCMP, or similar risk-related credentials.

Skills

  • Strategic thinking with strong analytical, problem-solving, and risk data interpretation capabilities, including the ability to aggregate, interpret, and visualize complex risk information.
  • Demonstrated ability to apply credible challenge, respectfully question assumptions, escalate risks, and influence outcomes using facts, regulatory knowledge, and clear communication.
  • Excellent written and verbal communication skills, with the ability to synthesize risk information, prepare executive-ready materials, and collaborate effectively with cross-functional teams, including Compliance, Internal Audit, and senior leadership.
  • Familiarity with GRC platforms and risk analytics tools, such as Tableau, Power BI, or similar.

Leadership and Organization Development

  • Demonstrates ownership and accountability in delivering high-quality risk governance and reporting outcomes.
  • Fosters a culture of collaboration, transparency, and continuous improvement within the Risk function.
  • Provides mentorship and guidance to junior team members and peers, supporting professional development and knowledge sharing.
  • Aligns team activities and deliverables with operational risk strategy and organizational goals.
  • Effectively manages change and adapts to evolving regulatory, strategic, and operational priorities.
  • Builds strong cross-functional relationships to influence outcomes and promote a unified risk culture.
  • Contributes to succession planning by developing documentation, tools, and processes that support long-term team capability and resilience.

Managerial Responsibility

  • Has supervisory/managerial responsibilities that are direct or through work leaders or assistants, typically with a subordinate group of 2 to 15 employees.  Estimates personnel needs and assigns work to meet these needs.  Supervises, coordinates and reviews the work of assigned staff.  Recommends candidates for employment, conducts performance evaluations and salary reviews for assigned staff, and applies company policy.

Mountain America Credit Union is an EEO/AA/ADA/Veterans employer.

Skills

TableauPower BISOCRisk ManagementContract ManagementComplianceProcurementSOC 2

Similar Jobs

19

Director, Third Party Risk Management – Quality Assurance & Governance (Line 1B)

Manulife and John Hancock Careers · CAN, Ontario, Toronto, 250 Bloor Street East, Canada

Yesterday

Director, Third Party Risk Management

Morgan Stanley · Dallas, TX,US, US

6 days ago

Director, Third Party Risk Management

Ms · Spring Valley Rd, United States of America

6 days ago

Associate Director, Third Party Risk Advisory & Oversight

Rbc · 20 KING ST W:TORONTO, Canada

1 week ago

Director, Third Party Risk Management

BlackRock · NY7 - 50 Hudson Yards, New York, United States of America

1 month ago

Director Third Party Risk Management

Regeneron · SLEEPY HOLLOW, United States of America

1 month ago

Senior Associate Director, Controls, Third Party Management

MUFG Investor Services · Dublin, County Dublin, Ireland

2 weeks ago

Senior Director, Enterprise Third Party Risk

vrtx · 5000 - Vertex US - Fan Pier, United States of America

2 months ago

Associate Director, Procurement Processes & Third-Party Risk Management

Iqvia · London, United Kingdom

1 week ago

Director, Head of Third-Party Claims

Revantage · Revantage - Dallas, United States of America · Hybrid

4 weeks ago

Director Global Procurement - Third Party Risk Management

Regeneron · Uxbridge1, United Kingdom · Remote, Hybrid

4 weeks ago

Cybersecurity Third Party Risk Management Director

Truist · Charlotte NC - 2320 Cascade Pointe Boulevard, United States of America +3

1 month ago

Third Party Risk Management Director (Hybrid)

Hq · Securian Home Office, United States of America

2 months ago

Director of On Air and Third Party Fundraising

KQED · San Francisco, CA · Remote, Hybrid

1 month ago

Senior Director, Category Management and Procurement – API and Third Party Manufacturing

AbbVie · Folsom, NJ, United States · Hybrid

3 weeks ago

Senior Director, Category Management and Procurement – API and Third Party Manufacturing

AbbVie · Irvine, CA, United States · Hybrid

3 weeks ago

Senior Director, Category Management and Procurement – API and Third Party Manufacturing

AbbVie · North Chicago, IL, United States · Hybrid

3 weeks ago

Third Party Program Management (Japan Coverage) : Job Level - Director

Ms · Otemachi Financial City, Japan

2 months ago

Third Party Program Management (Japan Coverage) : Job Level - Director

Morgan Stanley · Tokyo,JP, JP

2 months ago