Third Party Risk Management Analyst
Burke & Herbert Bank & Trust
Job Description
Job Description
CLASSIFICATION: Non-exempt
REPORTS TO: Program Manager, Third Party Risk Management
JOB DESCRIPTION
Summary/Objective
Under the direction of the Program Manager, Third Party Risk Management, the Third‑Party Vendor Risk Analyst supports the execution of the Bank’s Third‑Party Risk Management (TPRM) Program by performing day‑to‑day operational, analytical, and facilitation activities. In partnership with the Program Manager, the Analyst helps strengthen and sustain effective vendor review cadence by coordinating stakeholder inputs, producing complete and traceable documentation, and preparing exam‑ready artifacts. This role ensures vendor risk activities—including due diligence, ongoing monitoring, documentation, and issue tracking—are executed in a timely, consistent, and examination‑defensible manner.
Essential Functions
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Execute day‑to‑day third‑party risk management activities for new and existing vendors in accordance with the Bank’s TPRM Program, with heightened focus on critical and GLBA‑High risk relationships. Support initial due diligence and ongoing risk assessments by collecting, validating, and documenting required artifacts and supporting materials for higher‑risk vendors to facilitate effective review, challenge, and approval by the Program Manager.
- Maintain and manage the rolling vendor review schedule established by the Program Manager, ensuring critical and high‑risk third‑party relationships are prioritized and reviewed in accordance with established cadence and monitoring requirements. Coordinate with internal stakeholders, including Information Security, IT, Compliance, Finance, and Accounting, to obtain required risk assessment inputs and documentation necessary to support vendor reviews, providing enhanced facilitation for critical and GLBA‑High risk vendors.
- Track vendors review progress, outstanding action items, and remediation activities, maintaining visibility into reviews, documentation gaps, and issue resolution. Proactively escalate aging, overdue, or at‑risk items to the Program Manager to support timely awareness, decision‑making, and risk mitigation.
- Prepare, maintain, and organize comprehensive vendor review documentation, including executive summaries, evidence inventories, and issue tracking materials, with enhanced rigor applied to files associated with critical and GLBA‑High risk vendors. Ensure that vendor risk conclusions and assigned risk ratings are clearly, consistently, and defensibly supported by documented evidence prior to Program Manager review and sign‑off.
- Assist in documenting risk acceptance decisions and remediation status under the direction of the Program Manager, ensuring alignment with TPRM program standards, internal governance expectations, and applicable regulatory requirements.
- Identify procedural gaps, workflow inefficiencies, and documentation issues encountered during third‑party risk management execution, particularly those impacting oversight of critical and GLBA‑High risk vendors. Escalate observations and improvement opportunities to the Program Manager for program‑level evaluation and continuous improvement.
- Support ad hoc projects, process enhancements, and targeted initiatives led by the Program Manager to strengthen third‑party risk governance, operational effectiveness, and overall program maturity.
Other Duties
- Contract and Procurement Support
Support the Program Manager by tracking vendor‑related review milestones (including onboarding, renewals, and amendments). Ensure required vendor review documentation is complete, accurate, and available to support informed contractual decisions prior to execution.
- Governance, Metrics, and Reporting Support
Compile and maintain program metrics, status reports, and supporting materials used to measure and monitor Third‑Party Risk Management (TPRM) program performance. Assist, as directed by the Program Manager, in preparing materials for internal governance forums, audits, and regulatory examinations.
- Audit and Examination Readiness
Support internal and external audits and regulatory examinations by organizing vendor files, maintaining evidence mappings, and assembling response documentation under Program Manager guidance. Maintain vendor records in an exam‑ready state to support Program Manager interactions with auditors, regulators, and risk committees.
Skills/Abilities
- Working knowledge of third-party risk management practices and regulatory expectations within a regulated financial services environment.
- Strong analytical skills with the ability to assess risk data, identify trends, and support informed decision-making.
- Excellent organizational and documentation skills with high attention to detail.
- Ability to collaborate effectively with cross‑functional stakeholders while operating under Program Manager direction.
- Strong written and verbal communication skills to support clear documentation, issue analysis, and timely escalation.
- Proficiency with Microsoft Office (Excel, Word, PowerPoint) and risk management or workflow tracking tools.
Supervisory Responsibility
This position does not have supervisory responsibilities.
Work Environment
This job operates in an office setting, the opportunity to telework is not available. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. Office environment with job duties conducted via telephone, face to face meetings, and on the computer.
Physical Demands
This position requires manual dexterity, the ability to lift files and open cabinets. This position requires bending, stooping, or standing, as necessary.
Travel
Limited local travel may be required for this position.
Education and Experience
Education
- Requires a bachelor’s degree in business, Finance, Risk Management, Information Systems, Compliance, or a related field or equivalent professional experience supporting risk management functions in a regulated environment.
Experience
- Requires a minimum of 1 year of experience supporting third‑party vendor management, operational risk, compliance, information security, or a related risk discipline within a regulated industry.
- Requires hands‑on experience supporting vendor due diligence, ongoing monitoring, documentation, and issue tracking activities.
- Experience coordinating with cross‑functional stakeholders (e.g., Information Security, IT, Compliance, Finance) to collect and organize risk assessment inputs.
- Experience producing or maintaining clear, well‑organized, and evidence‑based documentation to support management review, audit, or regulatory examination.
Equal Employment Opportunity/M/F/disability/protected veteran status.
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
$90.78k
...The Sr. Analyst - Supply Chain Risk Management (SCRM) Analyst supports enterprise and program stakeholders in ensuring Maximus, Maximus Federal, and third-party relationships meet U.S. federal and DoD contractual and regulatory obligations. This role helps translate requirements...SuggestedContract workFor subcontractorWork at office$76.21k - $125.76k
...insurance. We are an industry-leading specialty insurer, with job opportunities in much of the contiguous United States. Senior Risk Management Consultant This position supports our workers' compensation line of business, Eastern Alliance. Based on candidate...SuggestedWork at officeRemote workLong distance- ...Job Title: Technical Security Risk & Governance Analyst Location: Harrisburg, PA Position Summary: The... ..., and risk registers. Vulnerability & Third-Party Risk: Establish governance for vulnerability management (SLAs, exception management, risk...Suggested
- ...seeking a qualified and motivated candidate for the position of Management/Program Analyst. Labor Category: Management / Program Analyst |... ...individual training schedules. Conduct current and future risk assessments and provide brief(s) on alternatives to support...Suggested
- ...Role: PMO Analyst Location: Mechanicsburg, PA (Onsite) Full-time with Apexon (W2) PMO - Jira Tracking & Reportin gManage project... ...presentations .Coordinate with project teams to monitor risks, issues, action items, and ensure adherence to PMO standards and...SuggestedFull timeWork at office
- ...experienced Senior Business Analyst to support and enhance our client... ...supporting documentation, manages review and approval workflows... ...boarding of loans purchased from third-party financial institutions. The... ...efficiency improvements, and risk reduction. ~ Support...3 days per week
- ...Senior Business Analyst It's fun to work in a company where people... ...supporting documentation, manages review and approval workflows... ...boarding of loans purchased from third-party financial institutions. The... ...efficiency improvements, and risk reduction. Support Agile,...
- ...is a US-based leading institutional fund manager and real estate partner with over $13... ...PUE, WUE). ~ Experience with project risk management and mitigation strategies.... ...identifiable candidate information from third-party recruiters. Any unsolicited information...Contract workTemporary workFor contractorsWork experience placementWork at officeLocal areaFlexible hours
- ...Lead Business Analyst / Quality Assurance Anywhere Type: Contract... ...impact analysis and identify risks for migration from Data... ...testing strategy, and defect management. ~ Ability to translate requirements... ...such as APIs, SSO, and third-party tools. ~ Ability to...Hourly payContract workLocal areaRemote work
- ...Telework Eligible Yes Major Duties Conducts studies, analyzes and evaluates overall management objectives Analyzes the effectiveness of resource allocations in meeting established goals and objectives Maintains computer-generated briefing charts and other...Full timeWork at officeRemote work
$77.38k - $117.5k
...****@*****.*** THE POSITION The Vulnerability Management Analyst position with the Office of Administration offers a chance to... ...in actions that reduce the threat landscape and help reduce risk to the Commonwealth and its data. You will join a team that works...Permanent employmentFull timePart timeWork at officeLocal areaRemote workWork from homeMonday to Friday2 days per week- ...monthly, quarterly, and annual sales target for Americas. Manage the entire sales pipeline from lead generation to closing the... ...responsible for an application that may be submitted by or through a third-party and candidates should proceed with extreme caution if a third-...Full timeTemporary workLocal areaRemote workFlexible hours
$92.5k - $120k
...professional journey. To support the continued growth of our Risk Advisory for State & Local Government practice, an opportunity... ...internal controls and the application of controls to effectively manage risks. This position will provide hybrid/remote flexibility,...Work experience placementWork at officeLocal areaRemote work$75k - $85k
...Analyst, Office Print Business Commercial Strategy The Office Print Business Analyst... ...delivering deep analytical insights that uncover risks and opportunities, identified... ...Commercial Strategy, Sales, Marketing, Portfolio Management, Supply Chain, Finance, and Global teams...Full timeWork at officeWorldwideRelocationRelocation packageFlexible hoursShift work- ...Job Title: Business analyst Location: Harrisburg, PA Duration: 2-month contract with extension Interview Type: Onsite... ...and stakeholder documentation. 9. Collaborates with project managers, technical teams, and business stakeholders to ensure documentation...Contract work
- ...Business Analyst The Business Analyst is responsible for the set of tasks and techniques used to work as a liaison among stakeholders... ..., assisting with calls from end-users, setting up facility management roles, mapping out system processes and new requirements,...
- ...insurance Health insurance Paid time off Vision insurance Wellness resources Momentum is often in need of Business Analysts in the Harrisburg, PA area. Please Note: This is not a Data Analyst or data-heavy role. This position is focused on business processes...Work from homeFlexible hours
$68k - $82.3k
...opportunities to drive growth, our Business Analyst position could be the next great career... ...00 technician accounts, reporting to the Manager, Operational Strategy & Support. The... ...trends, root causes, opportunities, and risks. Build and maintain dashboards, reports...Summer workCasual workWork at officeLocal areaImmediate startRemote work$59.35k - $90.21k
...Code: 00087400 Bureau / Division: Transportation Program Management Office Worksite Address: 1101 S. Front Street City: Harrisburg... ...(PennDOT) is excited to welcome a detail oriented Business Analyst 2 to oversee system enhancements, analyze data, and help solve...Permanent employmentFull timePart timeFor contractorsTraineeshipWork experience placementWork at officeLocal areaRemote workWork from homeMonday to FridayFlexible hours- ...Job Title Adept Consulting Services is a growing Pennsylvania IT consulting firm. We manage stable, long-term projects and have been successfully doing so since 1994. We maintain 100% customer satisfaction throughout our client base by engaging skilled, senior consultants...
- ...Info-Matrix is hiring!! We are looking for a Senior Business Analyst with significant MMIS experience specifically within a client-... ...products. Key Responsibilities Requirements Management & Analysis ~ Identify, gather, and document business...Temporary workWork at office2 days per week3 days per week
$51.97k - $79.06k
...Division Code 00087400 Bureau / Division Program Management Office Worksite Address 1101 S Front Street Worksite... ...-****@*****.*** THE POSITION As a Business Analyst 1 with the Department of Transportation, you will step into a...Permanent employmentFull timePart timeFor contractorsWork at officeLocal areaRemote workWork from homeMonday to Friday$90k - $100k
...Business Solutions Analyst As a member of the Project Management Office (PMO) within the Knowledge Management (KM) Department, the Business Solutions Analyst... .... Help monitor adoption, effectiveness and risks if AI tools. Support feedback loops for continuous...Work at office$100k - $140k
...Business Analyst Location: Remote Company: K2 Insurance Services Reports to: Senior Technology Product Owner Position Type:... ...confirming readiness for release. Communicate decisions, impacts, risks, and timelines; create stakeholder-facing updates and user...Full timeRemote work- ...Senior Business Analyst (BA) Hybrid - Harrisburg, PA $40hr - W2 Contract The Senior Business Analyst (BA) will collaborate with... ...development team members, the Bureau of Business and Service Management (BBSM), and the Project Manager (PM) within PennDOT's Project...Contract workWork at office
- ...Business Analyst Harrisburg, PA ( Must be local ) 100% Onsite Responsible for producing structured requirements... ...and stakeholder documentation. Collaborates with project managers, technical teams, and business stakeholders to ensure...Local area
- ...Consulting Services is a growing Pennsylvania IT consulting firm. We manage stable, long-term projects and have been successfully doing so... ...and rewards success. We are looking for a Business Analyst with experience in insurance , medical , and/or insuretech...Remote work
- ...Business Analyst G DC IT Solutions is currently seeking a Business Analyst to support... ...technical solutions. • Conduct gap analysis, risk assessments, and impact analyses related... ..., presentations, and reports for management and stakeholder review. • Support application...Temporary work
$40k
...position, and receipt of authorization to proceed. The Business Analyst supports the contract team by updating and maintaining... ...accordance with DHS standards. Participate in incident and problem management activities, including facilitating and documenting root cause...Contract workRemote work- ...Sr. Business Analyst (complete use case include with submission) Mechanicsburg, PA ASAP - 06/30/2026 100% Onsite... ...during the interview. ~8 AM - 4 PM (40 hours per week). Management is flexible with regards to if a contractor wishes to start...For contractorsLocal areaImmediate startFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third Party Risk Management Analyst. Be the first to apply!



