GRC Vendor Risk Analyst
Community Financial System, Inc.
Job Description
Job Description
Overview
At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration.
Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.
To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.
Responsibilities
Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
Essential Duties:
- Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
- Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
- Partner with stakeholders across various business lines to gather responses and supporting evidence.
- Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
- Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
- Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
- Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
- Support identity and access management governance, review, and related coordination activities as assigned.
- Track remediation items, follow-up actions, and review outcomes to support timely resolution.
- Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
- Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
- Perform other Information Security, third-party risk, and related governance duties as assigned by management.
Ancillary Duties:
As an integral member of CFSI, this position is responsible to provide assistance wherever necessary to help the Branches and the Bank in achieving their annual goals. This may include traveling to other branches in the area to provide support as needed and to ensure proper staffing and service levels.
Qualifications
Education, Training & Requirements:
- Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered
Skills:
- Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.
Experience:
- 4+ years of experience in Information Security; OR
- 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
- 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
- Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
- Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
- All applicants must be 18 years of age or older.
- ...Business Systems AnalystThe Business Systems Analyst is a critical role in the delivery of... ...manages changes in scope, identifies potential risks, and works with management and... ...resources, business stakeholders and external vendors/partners. Often fills the role of project...SuggestedWork experience placementWork from homeHome office
- Front Line Manager Duties As a Front Line Manager you will: Plan work to be accomplished by subordinates, sets and adjusts short-term priorities and prepares schedules for completion of work. Assign work to subordinates based on priorities, selective consideration...SuggestedTemporary work
- ...a caseload of billable hours alongside supervisory duties Requirements What We're Looking For: Required: Board Certified Behavior Analyst (BCBA) certification OR a Master’s degree with completed ABA coursework Required: Knowledge of ABA and Discrete Trial Training (DTT...SuggestedFull timeFlexible hours
$16 - $40.87 per hour
...POSITION SUMMARY Client Relationship Analysts provide exceptional service to our clients and support Financial Advisor(s) (FAs)/ Private Wealth Advisor(s) (PWAs)/ teams on a daily basis. Through regular interactions with clients, individuals in this role build trusted...SuggestedHourly payTemporary workWork at officeLocal area- Large Business & International WHAT IS LARGE BUSINESS & INTERNATIONAL (LB&I)? A description of the business units can be found at: Position(s) are to be filled in following area(s): LBI - Office of Program and Business Solutions - PBS:TPS:BSP: Compliance Operations...SuggestedWork at office
- ...Client Relationship Analyst Client Relationship Analysts provide exceptional service to our clients and support Financial Advisor(s)/Private Wealth Advisor(s)/teams on a daily basis. Through regular interactions with clients, individuals in this role build trusted relationships...Work at officeLocal area
$74k - $103k
At Utica National Insurance Group, 1,400 employees countrywide take our corporate promise to heart every day: To make people feel secure, appreciated, and respected. Utica National Insurance Group is an "A" rated $2.0B award-winning, nationally recognized property & casualty...Full timeWork experience placementWork at officeHome officeFlexible hours- Job Duties The following are the duties of this position at the full working level. If this vacancy includes more than one grade and you are selected at a lower grade level, you will have the opportunity to learn to perform these duties and receive training to help ...
- Job Title Job Description: Experience in detailed requirement gathering and creation of Business Requirement Document and Functional Requirement Document. Experience in working as an Integration Lead (Techno Functional). Experience in working on Duck Creek Product Suite...
- Job Title Duties The following are the duties of this position at the full working level. If this vacancy includes more than one grade and you are selected at a lower grade level, you will have the opportunity to learn to perform these duties and receive training...
- ...Overview: Roll : Lead Business Analyst Location : NYC, NY Duration : 12+ Months Phone/Video Hire Any Visa is OK ! LOCALS Highly Preferred ! Requirements : Experience working as Business Analyst or Product Owner on Reinsurance AND Property & Casualty...Local area
- ...Payment Integrity Drg Coding & Clinical Validation Analyst The Payment Integrity DRG Coding & Clinical Validation Analyst position has an extensive background in acute facility-based clinical documentation, and/or inpatient coding and has a high level of understanding...Work experience placementRemote work
- ...Description Job Description Description: Job Summary The Business Analyst is responsible for analyzing business processes, gathering... ...with project managers to monitor project progress and manage risks or issues. Stay current with insurance industry trends,...
- Overview Department: Employment Volunteer Position: Data and Marketing Assistant Position Summary: As a Data and Marketing Assistant, the candidate will play a crucial role in organizing and analyzing data within our system. This includes organizing files and ensuring...2 days per week
$20 per hour
...Job Description Job Description Immediate Opening - Sales & Marketing Analyst Openings! $20.00 an hour Staffworks is seeking reliable, hardworking Sales and Marketing Analyst in Utica, NY. What's in it for you? Associates are eligible: Paid sick leave...Seasonal workWork at officeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Vendor Risk Analyst. Be the first to apply!


