Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Risk Analyst, Privacy & Third-Party Risk

$87k - $185k
Full-time

T. Rowe Price

At T. Rowe Price, we identify and actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.

We believe doing the right thing for our clients and our associates is good business. With a career at the firm, you can expect opportunities to create real impact at work and in your community. You’ll enjoy resources to support your career path, as well as compensation, benefits, and flexibility to enrich your life. Here, you’ll find a collaborative culture that respects and values differences and colleagues who share a spirit of generosity.

Join us for the opportunity to grow and make a difference in ways that matter to you.

Role Summary

The Senior Risk Analyst – Privacy & Third-Party Risk is a Second Line of Defense (2LoD) role and a member of the Global Privacy Office (GPO) and Third-Party Risk Management (TPRM) function. The role provides independent risk oversight, effective challenge, and assurance over first-line activities and outsourced TPRM services, operating with minimal supervision and a high degree of professional judgment.

This position is expected to independently manage complex risk assessments, lead oversight activities, identify emerging risk themes, and deliver clear, actionable insights to senior stakeholders and governance committees. The role also supports the effective operation and continuous improvement of the GPO and TPRM programs through risk reporting, data analysis, issue management, technology enablement, and maintenance of core governance and compliance processes.

Responsibilities

Privacy Risk – Global Privacy Office:

  • Independently provide 2LoD oversight of privacy risks arising from first-line business activities and serve as a subject matter resource on privacy risk matters.
  • Lead review and challenge of Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments, including assessments involving new technologies, artificial intelligence, sensitive data, and elevated privacy risk.
  • Evaluate the design and operating effectiveness of privacy controls and recommend enhancements aligned with regulatory expectations and risk appetite.
  • Independently review privacy incidents, including root cause analyses and remediation plans, and support reconciliation, trend analysis, governance reporting, and escalation of significant privacy incidents.
  • Provide technical expertise and support the implementation of privacy and data protection processes, controls, and procedures based on enterprise-wide guidance issued by the Global Privacy Office.
  • Support Privacy and Security by Design activities by evaluating new technologies, systems, products, and business initiatives; assessing privacy risks and control requirements; and providing risk-based guidance to business and technology stakeholders.
  • Partner with Technology, Information Security, Legal, Compliance, and business stakeholders to support appropriate implementation of privacy requirements and controls.
  • Identify opportunities to enhance the Global Privacy Office’s technical capabilities; develop, test, and work with technology teams to deploy such capabilities, including workflow automation, reporting, analytics, and AI-enabled solutions.
  • Support the maintenance of the firm’s required privacy compliance documentation (e.g., Records of Processing Activities, Transfer Impact Assessments, procedures, guides, training, SharePoint sites), privacy inventories, registers, response materials, and supporting program records.
  • Support the execution of the privacy compliance monitoring program.
  • Support recurring privacy governance and compliance activities, including regulatory reporting, metrics, management information, periodic reconciliations, annual recertifications, readiness exercises, and regulatory or operational-impact assessments.
  • Support privacy-related inquiries, due diligence questionnaires, requests for information, and other stakeholder requests by researching issues, coordinating responses, and maintaining reusable response content.

Third-Party Risk Management:

  • Perform quality assurance and effective challenge of third-party risk outputs produced by external service providers and first-line stakeholders.
  • Independently review and challenge complex or elevated-risk third-party assessments, including due diligence findings, control deficiencies, risk responses, and recommendations to business stakeholders.
  • Monitor adherence to SLAs, KPIs, and contractual obligations of outsourced TPRM providers and escalate deficiencies as appropriate.
  • Identify systemic control gaps, concentration risk, and emerging third-party risk trends across the vendor population.
  • Evaluate and challenge third-party information security, technology, resiliency, privacy, and other risk considerations, partnering with domain subject matter experts where specialized expertise is required.
  • Contribute to the ongoing development of fourth-party risk governance and oversight practices.
  • Identify opportunities to enhance TPRM’s technical capabilities; develop, test, and work with technology teams to deploy such capabilities, including AI-assisted quality assurance, workflow automation, risk analytics, and reporting solutions.
  • Support the maintenance of the firm’s required TPRM compliance documentation (e.g., Policy, Supplier Management Standards, questionnaire templates, frameworks, training, SharePoint sites).
  • Support TPRM intake and stakeholder inquiries, including coordination and routing of requests, maintenance of supplier and program data, and development of reusable due diligence and client-response content.
  • Support risk-based prioritization, supplier tiering, and methodology enhancements by testing proposed approaches and analyzing their impact on the third-party population.

Risk Governance, Reporting & Analytics:

  • Independently develop and deliver executive-level risk reporting, dashboards, and management information.
  • Prepare and coordinate recurring management and governance reporting, including metrics, risk trends, control issues, incident information, and other program performance indicators.
  • Assist with monitoring and reporting emerging AI and technology risks across privacy and third-party risk, contributing to oversight of controls, assessments, and reporting.
  • Leverage AI-enabled tools and advanced analytics to identify trends, emerging risks, and control weaknesses.
  • Analyze assessment results, incidents, performance data, and other risk indicators to identify systemic weaknesses, recurring issues, concentration or dependency risks, and emerging themes requiring management attention.
  • Lead preparation for regulatory examinations, internal audits, and management assurance activities related to privacy and third-party risk oversight.
  • Maintain accurate, complete documentation in GRC, privacy, and TPRM systems and ensure audit-ready artifacts.
  • Identify, document, and escalate risk and control deficiencies; assess the adequacy of remediation plans; and monitor significant issues through resolution.

Technology, Process Improvement & Program Enablement:

  • Translate business and risk requirements into functional requirements and user stories for GRC, privacy, TPRM, reporting, and workflow solutions.
  • Perform user acceptance testing and validation of system implementations, enhancements, and fixes; document defects and support retesting through resolution.
  • Partner with technology, enablement, and program teams to develop and enhance dashboards, reporting, workflow automation, AI-enabled tools, and other capabilities that improve risk visibility and program efficiency.
  • Identify opportunities to improve Privacy and TPRM frameworks, processes, controls, operating models, and supporting technology, and lead or support implementation of prioritized enhancements.
  • Support data quality and stewardship activities necessary to maintain reliable program inventories, supplier information, business-process information, reporting, and risk records.

Qualifications

Required:

  • Bachelor’s degree in Risk Management, Information Systems, Finance, Business, Law, or a related field.
  • 5+ years of experience in risk management, GRC, information security, privacy, third-party risk, operational risk, technology risk, or a related oversight function, preferably within financial services, asset management, or another highly regulated industry.
  • Demonstrated ability to operate independently with minimal guidance in a 2LoD environment or in a risk function requiring independent review, challenge, and escalation.
  • Strong knowledge of risk management principles and demonstrated expertise in one or more relevant domains, such as privacy, third-party risk, information security, technology risk, operational risk, or compliance, with the ability to develop expertise across both Privacy and TPRM.
  • Demonstrated experience identifying control weaknesses, assessing risk, developing or challenging remediation plans, and communicating findings to stakeholders.
  • Strong analytical skills and experience working with risk data, metrics, reporting, or management information.

Preferred:

  • Experience leading or independently managing 2LoD privacy or TPRM oversight activities.
  • Asset management or broader financial services experience.
  • Experience spanning multiple risk domains, such as operational risk, information security, technology risk, privacy, resiliency, compliance, or third-party risk.
  • Experience with control testing, risk and control assessments, issue management, root cause analysis, remediation oversight, or similar risk-management activities.
  • Experience supporting or implementing risk-management frameworks, policies, standards, or program enhancements.
  • ISO 27001 Lead Implementer, Auditor, or other relevant risk, security, privacy, or third-party risk certifications.
  • Familiarity with SEC, FINRA, and global regulatory expectations.

Tools & Technology – Preferred

  • Advanced experience with GRC, privacy, and TPRM platforms (e.g., Archer, ServiceNow, OneTrust, IBM OpenPages).
  • Strong proficiency with reporting and analytics tools (e.g., Power BI, advanced Excel).
  • Practical experience using AI-enabled risk, compliance, or data analytics tools to enhance oversight and reporting (e.g., Microsoft Copilot, ChatGPT Enterprise).
  • Ability to automate reporting and improve risk visibility.
  • Experience developing business requirements, user stories, test scenarios, or performing UAT for risk-management technology solutions is preferred.
  • Familiarity with workflow and automation tools such as Power Automate or similar technologies is a plus.

Certifications

Relevant professional certification or demonstrated equivalent experience preferred. Candidates actively pursuing a relevant certification will also be considered. Examples include:

  • Certified Information Privacy Professional (CIPP/US, CIPP/E)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Third Party Risk Professional (CTPP/CTPRP)
  • Certified Information Privacy Manager (CIPM)
  • Certified Information Privacy Technologist (CIPT)

Key Competencies

  • Strong independent judgment and risk-based decision-making.
  • Ability to provide credible, effective challenge at senior levels.
  • Excellent written and verbal communication skills.
  • Strong issue management, quality assurance, and governance discipline.
  • Comfort operating autonomously in a global, regulated environment.
  • Ability to manage both complex analytical work and recurring operational responsibilities with accuracy and discipline.
  • Strong stakeholder-management skills and ability to collaborate across business, Technology, Information Security, Legal, Compliance, Procurement, and other risk functions while maintaining appropriate 2LoD independence.
  • Continuous-improvement mindset with the ability to translate risk-management needs into practical process and technology enhancements.

FINRA Requirements

FINRA licenses are not required and will not be supported for this role.

Work Flexibility

This role is eligible for hybrid work, with up to one day per week from home.

Base Salary Ranges

Please review the job posting for the location of this specific opportunity.

$87,000.00 - $148,000.00 for the location of: Maryland, Colorado, Washington and remote workers
$95,500.00 - $163,000.00 for the location of: Washington, D.C.
$108,000.00 - $185,000.00 for the location of: New York, California

Placement within the range provided above is based on the individual’s relevant experience and skills for the role. Base salary is only one component of our total compensation package. Employees may be eligible for a discretionary bonus, which is determined upon company and individual performance.

Commitment to Diversity, Equity, and Inclusion

At T. Rowe Price, our associates are our greatest asset. We thrive because our company culture is built on inclusion and because we sustain a work environment where associates can bring their best selves to work every day. The backgrounds, talents, and experiences of our global associates allow us to embrace new ideas and perspectives that move our business priorities forward and enable us to deliver strong client outcomes. Here, you can expect equal opportunity and fair and consistent treatment for all.

Benefits

We value your goals and needs, at work and in life. As an associate, you’ll be supported with resources, benefits, and work-life balance so you can thrive in ways that matter to you.

Featured employee benefits to enrich your life:

  • Competitive compensation

  • Annual bonus eligibility

  • A generous retirement plan

  • Hybrid work schedule

  • Health and wellness benefits, including online therapy

  • Paid time off for vacation, illness, medical appointments, and volunteering days

  • Family care resources, including fertility and adoption benefits

Learn more about our benefits.

T. Rowe Price is an equal opportunity employer and values diversity of thought, gender, and race. We believe our continued success depends upon the equal treatment of all associates and applicants for employment without discrimination on the basis of race, religion, creed, color, national origin, sex, gender, age, mental or physical disability, marital status, sexual orientation, gender identity or expression, citizenship status, military or veteran status, pregnancy, or any other classification protected by country, federal, state, or local law.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Senior Risk Analyst, Privacy & Third-Party Risk in Baltimore, MD vacancy
  • $105.4k - $207.8k

    Position Summary As a Senior Consultant in Deloitte’s Digital Trust & Privacy practice, you will support the design...  ...integrating technologies with third-party tools and APIs.Configure,...  ...incident response, third-party risk, etc.Knowledge of Data Privacy Laws... 
    Senior
    Local area

    Deloitte

    Baltimore, MD
    3 days ago
  • $165k - $195k

     ...Finance, People and Places, General Counsel, Risk, Internal Audit, Strategy and...  ...as a key member of a dynamic and growing privacy team, providing legal counsel on complex...  ...records of processing activities (RoPAs), and third-party privacy risk management Draft, review,... 
    Senior
    Full time
    Contract work
    Work at office
    Remote work
    Work from home
    Worldwide

    Transamerica

    Baltimore, MD
    2 days ago
  • $105.4k - $207.8k

    Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte Cyber team understands the unique challenges and opportunities...  ..., Project Management Professional (PMP), or Certified in Privacy Information Management (CIPM)Experience in banking and... 
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Baltimore, MD
    14 hours ago
  • Senior Commercial UnderwriterYou’ll be joining an innovative market with very strong Broker...  ...which are proving beneficial for both parties and also…..You'll be joining an innovative...  ...need, recommend and evaluate additional risk assessment informationMaintain and develop... 
    Senior

    Employment Specialists

    Essex, MD
    3 days ago
  • $93k - $191k

     ...driving growth. The Tax Innovation Senior Consultant manages incoming...  ...through established risk, legal, and compliance workflows...  ...various other technology and third-party relationship related agreements...  ...Office of General Counsel (OGC), Privacy and Confidentiality, Cyber... 
    Senior
    Contract work
    Work at office
    Local area
    Visa sponsorship

    Deloitte

    Baltimore, MD
    3 days ago
  •  ...Baltimore, MD Full time R5013839 As a Senior Safety Manager, you will ensure the safety...  ...upon upcoming work activities or recent at-risk trends + Drive and create a safety vision...  ...safe workplace for everyone + Facilitate third party safety reviews including OSHA + Understand... 
    Senior
    Full time
    Temporary work
    For subcontractor
    Work at office
    Local area

    Clark Construction Group

    Baltimore, MD
    2 days ago
  • $180.2k - $355.1k

     ...Summary Our Human Capital practice is adding an Actuarial Senior Manager to our Insights, Innovation & Operate Offering....  ...apply trend forecasting, predictive modeling, underwriting, and risk analysis methodologies to support client decision-making Advise... 
    Senior
    Local area
    Visa sponsorship

    Deloitte

    Baltimore, MD
    4 days ago
  •  ...GRC Analyst As a GRC Analyst, your role on the team will include leveraging your knowledge...  ...with others in the firm and inform on risk to systems and data. You will be...  ...and disaster recovery Participate in Third Party Risk Management Program activities Compliance... 
    Permanent employment

    ICE Miller LLP

    Baltimore, MD
    3 days ago
  • $165k - $200k

     ...Corporate, which includes Finance, People and Places, General Counsel, Risk, Internal Audit, Strategy and Development, and Corporate Affairs...  ..., visit transamerica.com.  Job Description SummaryThe Senior Actuary will report to the Director, Actuarial and have significant... 
    Senior
    Full time
    Contract work
    Work at office
    Remote work
    Worldwide
    Visa sponsorship
    Relocation package
    3 days per week

    Transamerica

    Baltimore, MD
    21 hours ago
  • $91k - $321.5k

     ...At PwC, our people in risk and compliance focus on maintaining regulatory compliance and...  ...Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in...  ...internal stakeholders and external contract parties;? Driving process improvement by analyzing... 
    Senior
    Contract work
    H1b

    PwC

    Baltimore, MD
    1 day ago
  • $173.08k - $276.47k

     ...to; scheduling, estimating, cost control, risk management, document control and project...  ...of project controls staff.RISK FOCUS The Senior Risk Manager provides risk management leadership...  ...within the state.......NOTICE TO THIRD-PARTY AGENCIES:HNTB does not accept unsolicited... 
    Senior
    Full time
    Contract work
    For contractors

    HNTB Companies

    Baltimore, MD
    5 days ago
  • $200k - $270k

     ...-house construction attorney to serve as Senior Legal Counsel supporting the Mid-Atlantic...  ...dispute avoidance, and dispute resolution, risk management, compliance, training, and...  ...employee. Gilbane will not pay fees to any third party agency or firm and will not be responsible... 
    Senior
    Contract work
    For contractors
    For subcontractor
    Work at office

    Gilbane Building Company

    Baltimore, MD
    14 hours ago
  • $120k - $150k

    The Senior Project Manager is responsible for the end-to-end execution of capital projects...  ..., cost and schedule control, and risk management. This is a hybrid role.As a Senior...  ...agency resumes and will not pay fees to any third-party agency or company that does not have a signed... 
    Senior
    Full time
    For contractors
    Work at office
    Flexible hours

    EN Engineering

    Linthicum Heights, MD
    4 days ago
  • $129k - $186k

     ...and address areas of concern regarding potential liabilities and risk, including understanding the concepts of risk and compliance...  ...with the specific requirements of the role you're pursuing.JLL Privacy NoticeJones Lang LaSalle (JLL), together with its subsidiaries and... 
    Senior
    Full time
    For contractors
    Work at office
    Local area

    Jones Lang LaSalle

    Baltimore, MD
    21 hours ago
  •  ...Senior Project Manager Location: Remote; Nashville, TN area We are seeking aSenior Project...  ...and maintain project budgets/estimates Risk management: Create and Manage Risk...  ...communicate to the other groups, customer, and third -party consultants; manage all communications... 
    Senior
    Contract work
    Remote work

    GrabJobs

    Baltimore, MD
    2 days ago
  •  ...**Greetings from My3Tech*** Position: Senior Technical Project Manager Location...  ...stakeholders, and vendors. Conduct risk management within the CMMI framework....  ...effectively with internal and external clients, third party vendors, and Senior Management in... 
    Senior
    For contractors

    My3Tech Inc

    Baltimore, MD
    4 days ago
  • $113.1k - $208.3k

     ...organization within Deloitte, is seeking a Senior Manager to lead the Vendor Management...  ...optimization, performance management, and risk alignment across a complex portfolio of strategic...  ..., and AI-enabled capabilities.Own the third-party risk framework and partner across... 
    Senior
    Contract work
    Work at office
    Remote work
    Work from home

    Deloitte

    Baltimore, MD
    1 day ago
  •  ...Senior Firewall Analyst / CheckPoint Engineer Hours of work per week: 32 - 40 (Budget 1880 hours...  ...Intrusion Prevention devices. Coordinate third-party maintenance for network and cyber...  ...performance/throughput issue and develop risk mitigation solutions. Provide... 
    Senior
    Local area
    Remote work
    Weekend work

    Zortech Solutions

    Gwynn Oak, MD
    3 days ago
  •  ...Job Description Job Description Our client is hiring a Full-Time Contract Risk Assessment & Technical Documentation Analyst for a full-time contract project through the end of the year to address FDA 483 audit findings and support CAPA-102537, CAPA-102539, and ICP-... 
    Full time
    Contract work

    Workforce Genetics

    Baltimore, MD
    21 days ago
  •  ..., recommendations, and briefings to CMS senior leadership, application owners, cybersecurity...  ..., and Federal partners on SaaS security risks, compliance posture, and remediation...  ...vendors. Evaluate SaaS platforms, third-party providers, and application integrations... 

    Department of Health and Human Services

    Gwynn Oak, MD
    5 days ago
  • $135k - $175k

     ...sound judgment, partnering across security, technology, legal, privacy, risk, and business teams to identify, contain, and mitigate threats...  ...effectiveness and response capabilities. Serve as a senior escalation point for complex and high-priority security incidents... 
    Senior
    Monday to Friday
    Afternoon shift
    Early shift

    Hogan Lovells

    Baltimore, MD
    1 day ago
  • $120k - $205.2k

     ...s why there’s nowhere like RSM.A Finance Senior Project Manager is responsible for leading...  ...scope and objectives.Maintain project risk, assumption, issue, and decision (RAID) logs...  ...with IT teams, business units, and third-party vendors to maintain progress on project activities... 
    Senior
    Full time
    Work experience placement
    Internship
    Work at office
    Local area

    RSM International

    Baltimore, MD
    3 days ago
  • $104.8k - $192.2k

     ...Successful deployment of identity verification and passwordless authentication solutions Reduction in account takeover and impersonation risks. Improved onboarding user experience. High identity proofing completion rates. Compliance with security and regulatory... 
    Senior
    For contractors
    Summer holiday
    Flexible hours

    EY

    Baltimore, MD
    2 days ago
  •  ...Job Description Job Description CyberLinx Solutions, LLC is looking for a Digital Risk Protection (DRP) Analyst to be responsible for protecting the organization’s brand, executives, and digital footprint. The DRP Analyst monitors, detects, and mitigates external... 

    CyberLinx Solutions LLC

    Baltimore, MD
    12 days ago
  •  ...Essential Duties and Responsibilities: - Serve as the Risk, Quality, and Performance Analyst, ensuring compliance with service quality, performance...  ...external market and internal value analysis including seniority and merit systems, as well as internal pay alignment.... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Remote work

    MAXIMUS

    Baltimore, MD
    1 day ago
  •  ...closely related security and risk-based fields - from accessibility...  ...highly skilled and motivated Senior Engineer to lead Emergency...  ...compliance with all relevant data privacy laws in all areas where we do...  ...purpose.*Policy on use of 3rd party recruiting agency for direct placementsJensen... 
    Senior
    Temporary work

    Jensen Hughes

    Baltimore, MD
    2 days ago
  •  ...Job Description Job Description Apply now: Compliance & Risk Analyst (Audit & Controls), location is Owings Mills, MD. The start date is ASAP for this 6-month contract position. Job Title: Compliance & Risk Analyst (Audit & Controls) Location-Type: Hybrid (Owings... 
    Contract work
    Immediate start
    2 days per week

    Mondo

    Owings Mills, MD
    21 days ago
  •  ...use case registry, executing risk assessments, coordinating mitigation...  ...through internal and third-party assessments. Key Responsibilities...  ...teams (Risk, Compliance, Privacy, Information Security) to...  ...of experience as a business analyst, governance analyst, or risk/... 

    Ampcus

    Owings Mills, MD
    5 days ago
  • $115k - $180k

     ...The Opportunity Senior Financial Planning & Analysis (FP&A) Analyst Partner with Leaders. Drive Strategy. Make...  ...projections, and identifying financial risks and opportunities with actionable...  ...It is the responsibility of all third-party recruiting and employment... 
    Senior

    RS&H

    Lutherville Timonium, MD
    4 days ago
  • $53.63 - $85.83 per hour

     ...Senior Project ManagerThe Johns Hopkins Health System Corporation is a not-for-profit organization...  ...independently on projects with highest risk, complexity, and scale. With minimal...  ...direction and oversight to the work of third-party project manager firms, consultants, and other... 
    Senior
    Apprenticeship
    Work experience placement
    Local area

    Johns Hopkins Medicine

    Baltimore, MD
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Risk Analyst, Privacy & Third-Party Risk. Be the first to apply!