GRC Vendor Risk Analyst
Community Financial System, Inc.
Job Description
Job Description
Overview
At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration.
Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.
To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.
Responsibilities
Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
Essential Duties:
- Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
- Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
- Partner with stakeholders across various business lines to gather responses and supporting evidence.
- Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
- Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
- Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
- Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
- Support identity and access management governance, review, and related coordination activities as assigned.
- Track remediation items, follow-up actions, and review outcomes to support timely resolution.
- Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
- Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
- Perform other Information Security, third-party risk, and related governance duties as assigned by management.
Ancillary Duties:
As an integral member of CFSI, this position is responsible to provide assistance wherever necessary to help the Branches and the Bank in achieving their annual goals. This may include traveling to other branches in the area to provide support as needed and to ensure proper staffing and service levels.
Qualifications
Education, Training & Requirements:
- Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered
Skills:
- Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.
Experience:
- 4+ years of experience in Information Security; OR
- 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
- 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
- Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
- Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
- All applicants must be 18 years of age or older.
- ...Vendor Risk Analyst Hilltop Holdings is looking for a Vendor Risk Analyst to assist in maintaining, executing, and enhancing our Vendor Risk Management Program. Responsibilities Perform functions related to vendor risk management: Assist with due diligence...SuggestedFull timeWork experience placement
- ...innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team,... ...keep our compliance posture current and our risk exposure understood. You will run the... ...management review process, conduct risk and vendor assessments, maintain the enterprise risk...SuggestedTemporary workFlexible hours
- ...information, please visit The Opportunity We are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer... ..., NIST CSF remediation roadmap, security policy library, vendor risk program, and client-facing security questionnaires. You...SuggestedFull timeTemporary workLive outWork at officeRemote work
- ...Computing firm seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support and enhance the organization's security... ...maintain the enterprise risk register. Lead third-party and vendor risk assessment processes. Develop and maintain information...SuggestedRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...corporate Information Security GRC team. A specific focus will be... ..., including governance, risk, and compliance (GRC). This role... ...You have experience with vendor assessments and management... ...A Day In The Life Of a Risk Analyst: Working with a focus...For contractorsFlexible hours
$85k - $110k
...AI And Technology Risk Governance Specialist Execute day-to-day operations of AI and... ...Governance, with primary responsibility for vendor AI governance and detection across The Mutual... ...management ~ Experience with TPRM and GRC tools (like Archer, ServiceNow, OneTrust,...Temporary workWork at officeRemote workHome officeFlexible hours$94k - $123.9k
...compliant, and scalable SAP environment. Perform security and compliance assessments and support the ongoing evolution of the SAP GRC (Governance Risk Compliance) environment, ensuring risks are accurately identified, assessed, and mitigated. Ruleset Governance &...Temporary work- ...Risk Analyst Weitzman is the most respected provider of retail real estate services in Texas. Our team provides a full range of services... ..., invoicing, and policies Work with brokers, third party vendors, and lenders to issue certificates of insurance, coverage summaries...Contract workWork at officeFlexible hours
- ...deliver moments that matter. Summary Professional analyst role that supports the Enterprise Risk Management (ERM) program under limited supervision.... ...workflows and reporting. Acts as SME for RMIS and GRC applications. Performs other duties as assigned....Full timeWork at officeLocal area2 days per week3 days per week
- ...states and Canada while overseeing financial operations, including vendor payments, settlement processing, and cost allocation. The... ...reserve discussions, and financial reporting \n Partner with Risk, HR, Safety, Payroll, AP, Legal and Operations \n \n \n Must...Local area
- ...Weitzman, located in Dallas, is seeking a Risk Analyst to administer the company's insurance programs. The role involves managing operational... ...and ensure compliance while working closely with brokers and vendors. Benefits include competitive compensation, medical insurance,...Contract work
$57 per hour
Cybersecurity & Technology Risk Compliance Analyst (DTC1JP00003425) Location: Tampa or Coppell, TX (Coppell preferred) Experience level: Mid-senior... ...existing controls and their alignment in the enterprise GRC tool. The ideal candidate has done related work for at least...Hourly payVisa sponsorship- ...Job Description Job Description Position: Risk / Fraud Analyst Reports To: Director of Risk Direct Reports: None Description Summary: Under general supervision, the risk analyst position is an individual contributor to a department responsible for the...Work at officeImmediate startWeekend work
- ...Risk Analyst We are seeking a Risk Analyst for a contract position in a hybrid setting within the Southeastern U.S. The role involves supporting a Risk Management and Analytics organization focused on portfolio analytics, forecasting, predictive modeling, and strategic...Contract work
- ...Asset & Wealth Management, Operational Risk, Associate - Irving Irving, TX, United States Job Description How You Will Fulfill Your Potential Manage all aspects of issue identification, analysis, remediation and monitoring & reporting, including collaboration with issue...Full timeWork at office
- ...Lincoln Property Company is seeking a Risk Analyst in Dallas, TX. The role involves supporting clients and leadership in implementing insurance solutions. Key responsibilities include managing insurance programs, monitoring acquisitions, and coaching risk owners. The...
$95k - $110k
...Job Description Risk Analyst - Dallas Who: A growing auto finance company building out its credit risk team. What: Analyze and forecast repossessions, origination risks, servicing exposure, and overall credit performance. When: Newly created position due...Work at office- ...Risk Analyst Dallas, TX The Risk Analyst will support clients and executive/market leadership by implementing insurance solutions for the organization. Successful implementation is based on a deep understanding of the business model of the organization, a clear understanding...
$60.2k - $107.4k
...help us advance health optimization on a global scale. Join us to start Caring. Connecting. Growing together. The Model Risk Analyst will be responsible for executing on model governance and model validations in alignment with the Bank's Model Risk Management...Minimum wageFull timeWork experience placementLive inWork at officeLocal areaRemote workMonday to FridayShift work3 days per week- ...Model Risk Analyst Sunflower Bank is seeking a Model Risk Analyst to join its Enterprise Risk Management Department. The Analyst will be responsible for supporting the bank-wide Model Risk Management (MRM) program, focusing on the annual assessment process, maintaining...
$120k - $160k
The Risk Officer is responsible for a wide variety of supervisory, compliance, and risk functions. In conjunction with the Senior Risk Officer, the Risk Officer has accountability for maintaining a consistent controlled environment through adherence of business ethics...Temporary workLocal area- Job Description Position: Risk / Fraud Analyst Reports To: Director of Risk Direct Reports: None Description Summary: Under general supervision, the risk analyst position is an individual contributor to a department responsible for the protection of financial losses...Work at officeWeekend work
$105.4k - $124k
...from Day One. JOB DESCRIPTION NOTE: This position is not eligible for current or future visa sponsorship. The Fraud Risk Analyst develops data-driven insights and strategies that strengthen fraud prevention, detection, and operational performance across deposits...Full timeTemporary workWork experience placementWork at officeLocal area3 days per week- ...and culture and contribute to our core mission which is enhancing our customer's experience. Position Summary: The Senior Risk Analyst, Commercial Lending Analytics, will support the development, calibration, and ongoing performance monitoring of commercial lending...Work at officeVisa sponsorshipWork visaMonday to FridayWeekend work
- ...to fill the position of a full-time Information Security Risk and Compliance Analyst at our Dallas, TX location. Description: Provides... ...and ad hoc assessments such as user access reviews, vendor due diligence and monitoring, and other control validation...Full time
- ...the Senior Financial Controls Analyst is to work closely with business... ...controls to mitigate key risks. The analyst works closely with... ...regulatory compliance. Maintain the GRC system containing SOX... ...for employees. Coordinate with Vendor Management on the annual third...
- ...Description Summary: The Application System Analyst II serves as a liaison between system end-users (customers), operational leaders, additional support resources and vendors to design, build and optimize their assigned applications in a timely and high-quality...Full time
- ...data-driven decisions in a rapidly evolving risk landscape. Here, you’ll be part of a team... ...Re, we’re looking for an Actuarial Analyst to join our team and help clients navigate... ...discrimination by its managers, employees, vendors or customers based on race, color, religion...Live outWork at officeLocal areaFlexible hours
- ...Weitzman is looking for a Risk Analyst to join its corporate office in Dallas, Texas. The role involves administration of insurance programs, from contract review to coverage analysis and operational management. The ideal candidate has a Bachelor’s degree and 2-5 years...Contract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Vendor Risk Analyst. Be the first to apply!



