Third Party Risk Management Consultant II (Chicago/Remote US)
Third Party Risk Management Consultant II (Chicago/Remote US)
Our Client - Insurance company
- Remote
Job description
Our customer is a large United States insurance company that is backed by more than 100 years of experience and provides insurance products and services for businesses and professionals in the United States., Canada and Europe. Headquartered in Chicago, IL, they have more than 20 US locations.
Our customer is seeking a Third-Party Risk Management Consultant II on a contract basis to support their business needs. This role is 100% Remote or local to Chicago, IL.
TPRM Continuous Monitoring Analyst
The TPRM Continuous Monitoring Analyst is responsible for the ongoing oversight of Client’s critical third-party vendors, ensuring their risk posture remains aligned with the organization’s risk appetite, internal policies, and regulatory expectations throughout the vendor lifecycle. This role plays a key part in safeguarding the organization by conducting periodic reassessments, trigger-based reviews, and continuous monitoring of vendor controls across multiple risk domains -including information security, privacy, business continuity, operational resilience, and compliance. The analyst leverages risk intelligence tooling (e.g., Supply Wisdom and Black Kite) to detect material changes in vendor risk, triage alerts, and drive timely remediation, escalation, and reporting.
Key Responsibilities
- Continuous Monitoring & Ongoing Oversight
- Participate in ongoing monitoring of critical vendors, including periodic reassessments and trigger-based reviews.
- Monitor risk intelligence feeds (Supply Wisdom and Black Kite) daily, reviewing alerts across cyber, financial, operational, geopolitical, compliance, and reputational risk domains.
- Perform initial triage and severity validation of incoming alerts, investigating alert context, vendor history, and existing controls to determine whether escalation is warranted.
- Initiate and conduct targeted assessments based on defined cadence and triggers (e.g., breach disclosures, sanctions/adverse media hits, material CVE exposure, breach notifications).
- Track changes in vendor risk posture and maintain monitoring tiers mapped to inherent risk, data sensitivity, concentration risk, and business criticality.
Risk Assessments & Reassessments
- Perform comprehensive risk assessments and reassessments of third-party vendors using standardized frameworks and questionnaires (IRQ/DDQ).
- Evaluate vendor responses, supporting documentation, and control effectiveness across domains such as cybersecurity, data protection, operational resilience, and regulatory compliance in ProcessUnity.
- Conduct SOC report reviews for suppliers in accordance with the annual review cadence.
- Evaluate updated evidence to identify control improvements or deterioration, newly introduced risks, and persistent or systemic issues.
Due Diligence & Analysis
- Analyze vendor risk posture and identify potential gaps or areas of concern.
- Collaborate with internal subject matter experts (e.g., InfoSec, Privacy, Legal, Compliance, Business Continuity) to validate findings and determine risk impact.
- Document risk trend analysis and provide clear rationale for any changes in inherent or residual risk ratings.
Escalation & Communication
- Escalate Critical and High alerts for Tier 1 and Tier 2 vendors within defined SLA timeframes, notifying the Relationship Manager, TPRM Assessment team, and applicable SMEs (e.g., InfoSec, CSIRT).
- Communicate identified issues with Relationship Managers, InfoSec, Privacy, Legal, Compliance, and Business Continuity, and log outcomes in ProcessUnity.
- Provide internal business support as well as supplier support throughout the reassessment process.
Reporting & Documentation
- Document assessment results, risk ratings, and recommendations in the TPRM platform (ProcessUnity).
- Produce monthly operational dashboards and status reports, and support quarterly executive reporting on top risks, identified findings, and SOC/compliance reviews.
- Maintain accurate, audit-ready records of monitoring activity, escalation records, and reassessment outcomes.
Skills:
Required Qualifications
- Experience in third-party risk, vendor assessments, or IT risk management.
- Familiarity with risk and control frameworks (e.g., NIST, ISO 27001, SOC 2, SIG).
- Working knowledge of risk assessment methodologies and control validation across information security, privacy, business continuity, and compliance domains.
- Strong analytical, communication, and stakeholder management skills.
- Ability to manage multiple priorities and meet deadlines in a fast-paced environment.
- Detail-oriented with a focus on accuracy and completeness.
Key Competencies
- Risk-based judgment and the ability to interpret and prioritize risk signals.
- Sound decision-making under defined thresholds and escalation protocols.
- Collaboration and partnership across cross-functional risk stakeholders.
- Ownership, accountability, and the ability to produce measurable, actionable outputs.
Education:
Education & Experience
1. Bachelor’s degree or equivalent
2. Typically 3 – 5 years of experience in Information Security or Vendor/Third-Party Risk
3. CISSP, CRISC, or CISA highly preferred
We offer a competitive salary range for this position. Most candidates who join our team are hired at the median of this range, ensuring fair and equitable compensation based on experience and qualifications.
Contractor benefits are available through our 3rd Party Employer of Record (Available upon completion of waiting period for eligible engagements)
Benefits include: Medical, Dental, Vision, 401k.
An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
All applicants applying for U.S. job openings must be legally authorized to work in the United States and are required to have U.S. residency at the time of application.
If you are a person with a disability needing assistance with the application, or at any point in the hiring process, please contact us at support@themomproject.com.