GRC Vendor Risk Analyst
Community Financial System, Inc.
Job Description
Job Description
Overview
At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration.
Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.
To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.
Responsibilities
Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
Essential Duties:
- Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
- Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
- Partner with stakeholders across various business lines to gather responses and supporting evidence.
- Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
- Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
- Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
- Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
- Support identity and access management governance, review, and related coordination activities as assigned.
- Track remediation items, follow-up actions, and review outcomes to support timely resolution.
- Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
- Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
- Perform other Information Security, third-party risk, and related governance duties as assigned by management.
Ancillary Duties:
As an integral member of CFSI, this position is responsible to provide assistance wherever necessary to help the Branches and the Bank in achieving their annual goals. This may include traveling to other branches in the area to provide support as needed and to ensure proper staffing and service levels.
Qualifications
Education, Training & Requirements:
- Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered
Skills:
- Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.
Experience:
- 4+ years of experience in Information Security; OR
- 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
- 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
- Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
- Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
- All applicants must be 18 years of age or older.
- ...innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team,... ...our compliance posture current and our risk exposure understood. You will run the... ...review process, conduct risk and vendor assessments, maintain the enterprise risk...SuggestedTemporary workFlexible hours
- ...Computing firm seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support and enhance the organization’s security... ...maintain the enterprise risk register. Lead third-party and vendor risk assessment processes. Develop and maintain information...SuggestedRemote workFlexible hours
- NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join the Information Security team in Dallas. You will own the security change management review, conduct risk and vendor assessments, maintain the enterprise risk register, and manage the policy library. Day...Suggested
- Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8...SuggestedFlexible hours
- Position Summary The Federal Exchange GRC Analyst owns federal Health Insurance Exchange and Enhanced... ...sits within Enterprise Compliance and Risk and serves the health segment,... ...Exchange-related change requests, releases, and vendor dependencies Required Qualifications Bachelor...SuggestedWork at officeLocal area
- Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across... ...will collaborate with cross-functional teams, manage third-party risk, and support incident response, DLP operations, BC/DR exercises,...
- BAL is seeking a senior GRC/InfoSec professional in the United States (Texas - Richardson... ...teams to ensure regulatory compliance and risk visibility. The role requires strong... .... You’ll contribute to incident response, vendor due diligence, BC/DR exercises, and KPI/KRI...
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- NorthMark Compute & Cloud in Dallas, TX is seeking a GRC Analyst to join the Information Security team. You will manage security change reviews, perform risk and vendor assessments, and maintain the enterprise risk register, aligning policies with frameworks to protect...
- ...Act as liaison with onsite, offshore, and vendor teams to document project requirements,... ...ExperienceThe ideal candidate is a highly organized Risk Analyst with strong project management and... ...Governance, Risk, and Controls (GRC) programs in financial services or other...Full timeTemporary workWork at officeRelocation
- Vanguard is seeking a Governance, Risk & Compliance Analyst, Specialist to lead enterprise‑wide information security policies and standards. You will... ...defined risk controls. You will assess the end‑to‑end GRC framework, monitor policy lifecycles, and use data‑driven methods...
- ...corporate Information Security GRC team. A specific focus will be... ..., including governance, risk, and compliance (GRC). This role... ...You have experience with vendor assessments and management... ...A Day In The Life Of a Risk Analyst: Working with a focus...For contractorsFlexible hours
- Goldman Sachs in Dallas seeks a Senior Analyst to join the Lifecycle Management team within Global... ...will act as SME for TPRM policies, advise on vendor onboarding/offboarding, and guide cross-functional stakeholders on risk framework requirements. You will monitor workflows...
- NorthMark Strategies LLC is hiring a GRC Analyst to join the Information Security team in Dallas, TX. You will drive governance processes, risk assessments, policy library management, and cross‑functional coordination with Engineering, Product, Legal, and Operations. You...
- Integrity, headquartered in Dallas, TX, seeks a Federal Exchange GRC Analyst to own compliance for federal Health Insurance Exchange and... ...to manage immovable deadlines within Enterprise Compliance and Risk. The ideal candidate has direct federal Exchange experience and...
- Glocomms, in partnership with a leading IT and Cloud Computing firm, is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support security governance, risk management, and regulatory compliance. You will conduct risk assessments, manage third...Remote work
$116k - $166k
Serve as the primary risk and insurance hub, delivering executive-level insights on exposures, financial performance, and claims trends... ...including working with various internal stakeholders.Financial Analysts ensure that Google makes sound financial decisions. As a...Contract work$55 - $60 per hour
...GorusuCompany: SRI Tech SolutionsTitle: Third Party Risk AnalystLocation: Dallas TXDuration: Contract / Full timeDescription:The Analyst/ Sr Analyst, Cybersecurity Risk is part of... ...across internal systems and third-party vendors • Support and enhance the Third-Party Risk...Hourly payFull timeContract work- ...Leads and performs internal audits using a risk-based methodology; assess IT, InfoSec,... ...inventory, and the development of AI specific vendor due diligence criteria. Supports the Third... .... Development and management of BAL’s GRC metrics and reporting, including defining...
- ...Worth, Austin, Houston, and San Antonio. Weitzman is seeking a Risk Analyst to join its corporate office in the Uptown area of Dallas. The... ...binders, invoicing, and policies Work with brokers, 3rd party vendors, and lenders to issue certificates of insurance, coverage...Contract workWork at officeFlexible hours
- ...The Risk Management & Claims Analyst is responsible for assisting with the overall management of insurance claims and company risk management functions... ...and review certificates of insurance received from vendors and suppliers for compliance with contract requirements....Contract work
- ...SAP GRC Analyst / SAP Security AnalystLocation: Monday - Friday - Onsite in Richardson, TX Position OverviewWe are seeking an experienced... ...environment. This role is responsible for supporting SAP Governance, Risk, and Compliance (GRC) initiatives, conducting security and...Monday to Friday
- ...ABOUT THE ROLE: Join Our Team as Senior Catastrophe Risk Analyst At Orion180, we believe the future of insurance belongs to organizations... ...adoption where appropriate. Partner internal teams and external vendors, data providers, and internal technology partners to develop...Work at officeWorldwide
- ...Asset & Wealth Management, Operational Risk, Issues Management, Associate - Dallas Job Description The Goldman Sachs Group, Inc. is... ...Engage with audit and risk partners to monitor findings Assess vendor risks and issues for themes, and monitor closure Perform reviews...Work experience placement
- ...Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.Designs, implements and supports modernized GRC process and tool capabilities.Participates in special projects and performs...Full timeWork experience placement
- ...to deliver moments that matter. Summary Professional analyst role that supports the Enterprise Risk Management (ERM) program under limited supervision. Identifies... ...workflows and reporting. Acts as SME for RMIS and GRC applications. Performs other duties as assigned....Work at officeLocal area2 days per week3 days per week
$100.8k - $168k
...Perform complex business analysis and build analytical frameworks to support decision-making Evaluate industry trends, emerging risks, and opportunities (including automation and AI) impacting the control environment Facilitate alignment, prioritization, and sequencing...- ...partners and protecting the natural environment. Job Summary The Risk Analyst will build the Risk Management team and will be an integral... ...(LRE) does not accept unsolicited resumes from recruiting vendors or employment agencies. Only recruiting vendors with a current...Full timeWork at officeLocal area
- ...Risk & Compliance AnalystAFF Compliance is seeking a highly motivated Risk & Compliance Analyst to support and enhance our compliance program in alignment with AFF's risk appetite... ...change management, and third-party/vendor risk oversight.Conduct compliance testing...Work at office
- Location: Mockingbird Towers 4th FLR PRIMARY PURPOSE The Vendor Management Analyst supports procurement, vendor contracting, and contract... ...Understanding of contract negotiation, compliance, and risk assessment processes; Strong analytical and problem-solving...Contract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Vendor Risk Analyst. Be the first to apply!


