Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
MUFG

IT Third-Party Risk Assessor

MUFG

. Conduct cybersecurity, information security, and technology risk assessments of third-party vendors and service providers .

Posted 9/17/2026full-timeTempe • Arizona • United StatesMid-LevelSenior💰 $125,000 - $164,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Third-Party Risk Management, including conducting risk assessments, evaluating vendor compliance, and managing the vendor risk lifecycle. Proficient in cybersecurity principles and regulatory frameworks, with a strong ability to communicate findings and recommendations to stakeholders.

Highest-signal resume keywords
Third-Party Risk ManagementCybersecurity Risk ManagementVendor Security AssessmentsNIST Cybersecurity FrameworkCISSP Certification

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentVendor Risk Assessment MethodologiesControl Evaluation TechniquesData Protection and EncryptionIncident ResponseVulnerability ManagementOperational RiskBusiness Continuity PlanningRegulatory ComplianceFinancial Regulatory Expectations
Soft Skills
CommunicationCollaborationAnalytical ThinkingProblem SolvingPresentation Skills
Tools & Technologies
Archer GRCAI-Powered Risk PlatformsSOC 1 ReportsSOC 2 ReportsISO 27001
Certifications & Qualifications
CISSPCISMCTPRPCTPRACISACRISCCCSPSecurity+
Industry Keywords
Information SecurityCybersecurityFinancial ServicesHealthcareInsuranceTechnologyRegulated IndustriesSecurity StandardsCompliance RequirementsRisk Mitigation

Tech Stack

Tools & technologies
CloudCyber SecuritySDLC

About the role

Key responsibilities & impact
  • Conduct cybersecurity, information security, and technology risk assessments of third-party vendors and service providers
  • Review vendor security documentation, including SIG questionnaires, SOC 1 and SOC 2 reports, Bridge Letters, and ISO 27001 certifications with SoA reviews
  • Track, document, and manage the end-to-end vendor risk lifecycle within Archer GRC
  • Use AI-powered risk platforms to parse vendor documentation and summarize control gaps
  • Assess inherent and residual risks associated with third-party relationships
  • Evaluate vendor compliance with internal policies, security standards, and regulatory requirements
  • Identify and document control gaps, vulnerabilities, and areas of concern
  • Develop risk ratings and provide recommendations for risk mitigation
  • Prepare concise risk assessment reports and executive-level summaries
  • Present assessment findings to business owners, risk committees, and senior management
  • Perform periodic reassessments of critical and high-risk vendors
  • Monitor vendors for cybersecurity incidents, financial instability, regulatory actions, and emerging risks
  • Track remediation activities and validate corrective actions
  • Maintain vendor risk profiles and assessment documentation
  • Partner with Procurement, Information Security, Legal, Compliance, Privacy, and Business Units throughout the vendor lifecycle
  • Provide guidance regarding security requirements during vendor onboarding and renewals
  • Support contract reviews by recommending security and data protection requirements
  • Assist business partners in understanding and managing third-party technology risks
  • Ensure alignment with regulatory requirements and frameworks including NIST Cybersecurity Framework, NIST CRI, NIST 800-53, NIST 800-171, FFIEC Guidance, ISO 27001, and HIPAA as applicable
  • Support audits, examinations, and regulatory reviews related to third-party risk
  • Contribute to continuous improvements of the Third-Party Risk Management Program

Requirements

What you’ll need
  • Bachelor's degree in Information Technology, Information Security, Cybersecurity, Risk Management, Business Administration, or a related field
  • Equivalent combination of education and experience will be considered
  • 5+ years of experience in Third-Party Risk Management, Information Security, Cybersecurity Risk Management, IT Audit, Technology Risk, Operational Risk, or Business Continuity Planning
  • Experience reviewing vendor security assessments and industry-standard assurance reports
  • Solid understanding of financial regulatory expectations regarding data protection and operational resilience
  • Understanding of cybersecurity principles and security control frameworks
  • Familiarity with access management, network security, cloud security, data protection and encryption, disaster recovery and business continuity, vulnerability management, incident response, Service Level Management, Release Management/SDLC, IT Asset Management, IT Configuration Management, Change Management, Problem Management, and System Capacity and Performance
  • Knowledge of vendor risk assessment methodologies and control evaluation techniques
  • Preferred certifications include CISSP, CISM, CTPRP, CTPRA, CISA, CRISC, CCSP, or Security+ or equivalent cybersecurity certification
  • Experience in regulated industries such as financial services, healthcare, insurance, or technology preferred

Benefits

Comp & perks
  • Hybrid work arrangement: work at an MUFG office or client sites four days per week and remotely one day
  • Minimal travel (0–10%)