Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Vendor Risk Analyst

Community Financial System, Inc.

Job Description

Job Description

Overview

At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration.

Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.

To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.

Responsibilities

Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.

Essential Duties:

  • Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
  • Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
  • Partner with stakeholders across various business lines to gather responses and supporting evidence.
  • Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
  • Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
  • Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
  • Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
  • Support identity and access management governance, review, and related coordination activities as assigned.
  • Track remediation items, follow-up actions, and review outcomes to support timely resolution.
  • Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
  • Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
  • Perform other Information Security, third-party risk, and related governance duties as assigned by management.

Ancillary Duties:

As an integral member of CFSI, this position is responsible to provide assistance wherever necessary to help the Branches and the Bank in achieving their annual goals. This may include traveling to other branches in the area to provide support as needed and to ensure proper staffing and service levels.

Qualifications

Education, Training & Requirements:

  • Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered

Skills:

  • Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.

Experience:

  • 4+ years of experience in Information Security; OR
  • 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
  • 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
  • Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
  • Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
  • All applicants must be 18 years of age or older.

Vacancy posted 26 days ago
Similar jobs that could be interesting for youBased on the GRC Vendor Risk Analyst in Syracuse, NY vacancy
  •  ...innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team,...  ...our compliance posture current and our risk exposure understood. You will run the...  ...review process, conduct risk and vendor assessments, maintain the enterprise risk... 
    Suggested
    Temporary work
    Flexible hours

    NorthMark Strategies

    Dallas, TX
    2 days ago
  •  ...Computing firm seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support and enhance the organization’s security...  ...maintain the enterprise risk register. Lead third-party and vendor risk assessment processes. Develop and maintain information... 
    Suggested
    Remote work
    Flexible hours

    Glocomms

    Dallas, TX
    3 hours ago
  • NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join the Information Security team in Dallas. You will own the security change management review, conduct risk and vendor assessments, maintain the enterprise risk register, and manage the policy library. Day... 
    Suggested

    NorthMark Strategies

    Dallas, TX
    5 days ago
  • Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8... 
    Suggested
    Flexible hours

    Crunchyroll

    Dallas, TX
    1 day ago
  • Position Summary The Federal Exchange GRC Analyst owns federal Health Insurance Exchange and Enhanced...  ...sits within Enterprise Compliance and Risk and serves the health segment,...  ...Exchange-related change requests, releases, and vendor dependencies Required Qualifications Bachelor... 
    Suggested
    Work at office
    Local area

    Integrity Windows

    Dallas, TX
    3 days ago
  • Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across...  ...will collaborate with cross-functional teams, manage third-party risk, and support incident response, DLP operations, BC/DR exercises,... 

    Berry Appleman & Leiden

    Richardson, TX
    3 days ago
  • BAL is seeking a senior GRC/InfoSec professional in the United States (Texas - Richardson...  ...teams to ensure regulatory compliance and risk visibility. The role requires strong...  .... You’ll contribute to incident response, vendor due diligence, BC/DR exercises, and KPI/KRI... 

    BAL

    Richardson, TX
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Dallas, TX
    2 days ago
  • NorthMark Compute & Cloud in Dallas, TX is seeking a GRC Analyst to join the Information Security team. You will manage security change reviews, perform risk and vendor assessments, and maintain the enterprise risk register, aligning policies with frameworks to protect... 

    NorthMark Compute & Cloud

    Dallas, TX
    3 days ago
  •  ...Act as liaison with onsite, offshore, and vendor teams to document project requirements,...  ...ExperienceThe ideal candidate is a highly organized Risk Analyst with strong project management and...  ...Governance, Risk, and Controls (GRC) programs in financial services or other... 
    Full time
    Temporary work
    Work at office
    Relocation

    Infosys Technologies

    Richardson, TX
    2 days ago
  • Vanguard is seeking a Governance, Risk & Compliance Analyst, Specialist to lead enterprise‑wide information security policies and standards. You will...  ...defined risk controls. You will assess the end‑to‑end GRC framework, monitor policy lifecycles, and use data‑driven methods... 

    Vanguard Services Inc

    Dallas, TX
    5 days ago
  •  ...corporate Information Security GRC team. A specific focus will be...  ..., including governance, risk, and compliance (GRC). This role...  ...You have experience with vendor assessments and management...  ...A Day In The Life Of a Risk Analyst: Working with a focus... 
    For contractors
    Flexible hours

    Crunchyroll

    Dallas, TX
    5 days ago
  • Goldman Sachs in Dallas seeks a Senior Analyst to join the Lifecycle Management team within Global...  ...will act as SME for TPRM policies, advise on vendor onboarding/offboarding, and guide cross-functional stakeholders on risk framework requirements. You will monitor workflows... 

    Goldman Sachs

    Dallas, TX
    4 days ago
  • NorthMark Strategies LLC is hiring a GRC Analyst to join the Information Security team in Dallas, TX. You will drive governance processes, risk assessments, policy library management, and cross‑functional coordination with Engineering, Product, Legal, and Operations. You... 

    NorthMark Strategies LLC

    Dallas, TX
    3 days ago
  • Integrity, headquartered in Dallas, TX, seeks a Federal Exchange GRC Analyst to own compliance for federal Health Insurance Exchange and...  ...to manage immovable deadlines within Enterprise Compliance and Risk. The ideal candidate has direct federal Exchange experience and... 

    Integrity Windows

    Dallas, TX
    3 days ago
  • Glocomms, in partnership with a leading IT and Cloud Computing firm, is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support security governance, risk management, and regulatory compliance. You will conduct risk assessments, manage third... 
    Remote work

    Glocomms

    Dallas, TX
    3 days ago
  • $116k - $166k

    Serve as the primary risk and insurance hub, delivering executive-level insights on exposures, financial performance, and claims trends...  ...including working with various internal stakeholders.Financial Analysts ensure that Google makes sound financial decisions. As a... 
    Contract work

    Google

    Sunnyvale, TX
    3 days ago
  • $55 - $60 per hour

     ...GorusuCompany: SRI Tech SolutionsTitle: Third Party Risk AnalystLocation: Dallas TXDuration: Contract / Full timeDescription:The Analyst/ Sr Analyst, Cybersecurity Risk is part of...  ...across internal systems and third-party vendors • Support and enhance the Third-Party Risk... 
    Hourly pay
    Full time
    Contract work

    SRI Tech

    Dallas, TX
    2 days ago
  •  ...Leads and performs internal audits using a risk-based methodology; assess IT, InfoSec,...  ...inventory, and the development of AI specific vendor due diligence criteria. Supports the Third...  .... Development and management of BAL’s GRC metrics and reporting, including defining... 

    BAL

    Richardson, TX
    4 days ago
  •  ...Worth, Austin, Houston, and San Antonio. Weitzman is seeking a Risk Analyst to join its corporate office in the Uptown area of Dallas. The...  ...binders, invoicing, and policies Work with brokers, 3rd party vendors, and lenders to issue certificates of insurance, coverage... 
    Contract work
    Work at office
    Flexible hours

    Risk & Insurance Management Society Inc

    Dallas, TX
    4 days ago
  •  ...The Risk Management & Claims Analyst is responsible for assisting with the overall management of insurance claims and company risk management functions...  ...and review certificates of insurance received from vendors and suppliers for compliance with contract requirements.... 
    Contract work

    Coca-Cola Southwest Beverages

    Dallas, TX
    1 day ago
  •  ...SAP GRC Analyst / SAP Security AnalystLocation: Monday - Friday - Onsite in Richardson, TX Position OverviewWe are seeking an experienced...  ...environment. This role is responsible for supporting SAP Governance, Risk, and Compliance (GRC) initiatives, conducting security and... 
    Monday to Friday

    Anveta

    Richardson, TX
    3 days ago
  •  ...ABOUT THE ROLE: Join Our Team as Senior Catastrophe Risk Analyst At Orion180, we believe the future of insurance belongs to organizations...  ...adoption where appropriate. Partner internal teams and external vendors, data providers, and internal technology partners to develop... 
    Work at office
    Worldwide

    Jobless

    Irving, TX
    3 days ago
  •  ...Asset & Wealth Management, Operational Risk, Issues Management, Associate - Dallas Job Description The Goldman Sachs Group, Inc. is...  ...Engage with audit and risk partners to monitor findings Assess vendor risks and issues for themes, and monitor closure Perform reviews... 
    Work experience placement

    Goldman Sachs Group, Inc.

    Dallas, TX
    3 days ago
  •  ...Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.Designs, implements and supports modernized GRC process and tool capabilities.Participates in special projects and performs... 
    Full time
    Work experience placement

    Vanguard

    Dallas, TX
    2 days ago
  •  ...to deliver moments that matter. Summary Professional analyst role that supports the Enterprise Risk Management (ERM) program under limited supervision. Identifies...  ...workflows and reporting. Acts as SME for RMIS and GRC applications. Performs other duties as assigned.... 
    Work at office
    Local area
    2 days per week
    3 days per week

    The Freeman Company

    Dallas, TX
    2 days ago
  • $100.8k - $168k

     ...Perform complex business analysis and build analytical frameworks to support decision-making Evaluate industry trends, emerging risks, and opportunities (including automation and AI) impacting the control environment Facilitate alignment, prioritization, and sequencing... 

    McKesson

    Irving, TX
    2 days ago
  •  ...partners and protecting the natural environment. Job Summary The Risk Analyst will build the Risk Management team and will be an integral...  ...(LRE) does not accept unsolicited resumes from recruiting vendors or employment agencies. Only recruiting vendors with a current... 
    Full time
    Work at office
    Local area

    Leeward Energy

    Dallas, TX
    5 days ago
  •  ...Risk & Compliance AnalystAFF Compliance is seeking a highly motivated Risk & Compliance Analyst to support and enhance our compliance program in alignment with AFF's risk appetite...  ...change management, and third-party/vendor risk oversight.Conduct compliance testing... 
    Work at office

    FIRST CASH FINANCIAL SERVICES INC

    Coppell, TX
    4 days ago
  • Location: Mockingbird Towers 4th FLR PRIMARY PURPOSE The Vendor Management Analyst supports procurement, vendor contracting, and contract...  ...Understanding of contract negotiation, compliance, and risk assessment processes; Strong analytical and problem-solving... 
    Contract work
    Work at office

    Parkland Health and Hospital System

    Dallas, TX
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Vendor Risk Analyst. Be the first to apply!