Third Party Risk Manager at Varo

V
Varo

Third Party Risk Manager

Remote

Full Time

#Risk

#Information Security

#Risk Assessment

#Due Diligence

#Incident Response

#Business Continuity

#Disaster Recovery

#NIST CSF

#PCI DSS

#SOC 2

#GRC

Varo is looking for a Third Party Risk Manager

Sign up to unlock quick summaries and profile fit assessments

Varo is an entirely new kind of bank. All digital, mission-driven, FDIC insured and designed for the way our customers live their lives. A bank for all of us.

Varo is building out a world-class Third Party Risk Management (TPRM) team as part of the second line of defense. The TPRM Manager is a critical role at Varo and will be responsible for evaluating and managing third-party technology and security risks. The TPRM Manager will carry out ongoing reviews of all third parties, identify technology risks and requirements, and challenge and monitor third parties’ ability to perform within risk appetite.  This role will be acting as the liaison with first-line teams in order to enhance overall technology supply chain risk and business processes to maximize efficiencies and oversight.

What you'll be doing
  • Manage and enhance Varo’s Third-Party Risk Management Framework to ensure it meets regulatory expectations and Varo’s risk appetite
  • Define and meet SLA expectations for Third Party Risk Assessments, vendor onboarding, proof of concept periods, and retirement
  • Oversee the implementation and adherence to Varo’s policy and procedures regarding third-party risk management, including training internal departments on requirements and managing third-party service providers/vendors on an ongoing basis
  • Collaborate with internal stakeholders to establish and maintain a comprehensive inventory of third-party relationships, applications, and associated risks
  • Collaborate with internal technology and security teams to develop incident response plans and procedures for addressing cybersecurity incidents involving third parties 
  • Work closely with all Varo departments and internal risk groups that are seeking third-party services/vendor relationships to assure that appropriate risk assessment and due diligence are conducted for any new third-party service
  • Prepare and present comprehensive reports and recommendations to senior management regarding third-party risk exposures and mitigation strategies through performance assessments 
  • Partner with internal budget owners to deliver against budgets and work with appropriate stakeholders on contract negotiations for all managed third-party relationships
  • Track compliance with Varo’s third-party policies and procedures, analyze and report on any gaps, and provide recommendations for remediation of such gaps
  • Develop dashboard presentations and reports, and provide periodic updates to various Risk Committees on the status of the third-party risk management program
  • Act as TPRM Lead in any Regulatory and audit matters, including exams and meetings


  • You'll bring the following required skills and experiences
  • 5-7 years of leading third-party risk management experience with a financial institution, a fintech company, or a provider to the financial services business sector
  • Risk assessment and due diligence experience with a particular focus on identifying risks and identifying and implementing solutions to remediate these gaps
  • Ability to conduct and report on testing of applicable controls that are in place regarding third-party service providers
  • Experience designing systems and workflows that support effective prioritization of monitoring Third Parties and work for the team
  • Previous experience reporting to senior management, the Board, and/or Committees of the Board on the status of third-party risk management efforts
  • Experience implementing Third Party Management requirements to comply with various regulatory requirements and industry best practices
  • Business Continuity, Disaster Recovery, NIST CSF, PCI DSS compliance, SOC 2 Type 2, etc.
  • Experience with RSA Archer or similar GRC tools


  • We recognize not everyone will have all of these requirements. If you meet most of the criteria above and you’re excited about the opportunity and willing to learn, we’d love to hear from you!
    About Varo
    Varo launched in 2017 with the vision to bring the best of fintech into the regulated banking system. We’re a new kind of bank – all-digital, mission-driven, FDIC-insured, and designed around the modern American consumer. 
    As the first consumer fintech to be granted a national bank charter in 2020, we make financial inclusion and opportunity for all a reality by empowering everyone with the products, insights, and support they need to get ahead. Through our core product offerings and suite of customer-first features, we aim to address a broad range of consumer needs while profitably serving underserved communities that have been historically excluded from the traditional financial system.
    We are growing quickly in our hub locations of San Francisco, Salt Lake City, and Charlotte along with colleagues located across the country. We have been recognized among Fast Company’s Most Innovative Companies, Forbes’ Fintech 50, and earned the No. 7 spot on Inc. 5000’s list of fastest-growing companies across the country.
    Varo. A bank for all of us.
    Our Core Values
    - Customers First
    - Take Ownership
    - Respect
    - Stay Curious
    - Make it Better
    Learn more about Varo by following us:
    Varo is an equal opportunity employer. Varo embraces diversity and we are committed to building teams that represent a variety of backgrounds, perspectives, and skills. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.
    Beware of fraudulent job postings!
    Varo will never ask for payment to process documents, refer you to a third party to process applications or visas, or ask you to pay costs. Never send money to anyone suggesting they can provide work with Varo.  If you suspect you have received a phony offer, please e-mail [email protected] with the pertinent information and contact information.
    CCPA Notice at Collection for California Employees and Applicants:
    V

    Varo

    9 views

    2 applied

    Company Size

    501-1000

    Markets

    Fintech
    Financial Services
    Consumer Lending

    Social Media

    Visit Varo
    Share this job
    Copy Permalink
    Discover similar jobs
    Planned Parenthood Federation of America logo
    Planned Parenthood Federation of America

    Associate Director, Information Security Engineer

    Remote

    Full Time

    #Information Security

    #Security Operations

    #SIEM

    #Splunk

    #Security Monitoring

    #Vulnerability Assessment

    #Incident Response

    #SIEM Administration

    #Windows Server

    #Firewalls

    #Networking

    Mission Lane logo
    Mission Lane

    Head of Information Security

    216k - 240k USD

    Remote

    Full Time

    #Information Security

    #Fintech

    #Cybersecurity

    #Risk Management

    #Cloud Security

    #AWS

    #GCP

    #SIEM

    #DevSecOps

    #Incident Response

    #PCI DSS

    #ISO 27001

    Finom logo
    Finom

    Credit Risk Manager

    Remote

    Full Time

    #Risk Management

    #Credit Risk

    #Lending

    #Underwriting

    #Risk

    #Monitoring

    #Data Strategy

    #Regulatory Compliance

    E
    Exodus Movement Inc.

    Security Engineer

    130k - 160k USD

    Remote

    Full Time

    #Security Engineering

    #Security

    #AI

    #Detection Engineering

    #Incident Response

    #SIEM

    #AWS Security

    #Scripting Languages

    #MITRE

    #Threat Modeling

    Sword Health logo
    Sword Health

    Governance, Risk & Compliance Analyst

    pt flag
    Portugal

    Remote

    Full Time

    #Information Security

    #Healthcare Technology

    #Compliance

    #ISO 27001

    #SOC 2

    #GDPR

    #HIPAA

    #Risk Management

    #Leadership

    #AI

    Velaa Private Island Maldives logo
    Velaa Private Island Maldives

    Senior Construction Supervisor

    mv flag
    Maldives

    On-site

    Full Time

    #Engineering

    #Management

    #Scheduling

    #Coordination

    #Procurement

    #Contract Management

    #Risk

    #Quality Control

    #Team Leadership

    P
    Paymenttools

    Information Security Manager

    de flag
    Germany

    Hybrid

    Full Time

    #Security

    #Payments

    #Cloud

    #Audit Management

    #ISO 27001

    #PCI DSS

    #Project Management

    #Risk Assessment

    #Compliance Reporting

    #Cloud Native

    T
    THE ICONIC

    Director of Security

    au flag
    Australia

    Hybrid

    Full Time

    #Security

    #E Commerce

    #Retail

    #Risk Management

    #Incident Response

    #Vulnerability Assessment

    #Compliance

    #Cloud Security

    #Application Security

    #DevSecOps

    LetsGetChecked logo
    LetsGetChecked

    Director of Governance Risk and Compliance

    ie flag
    Ireland

    90k - 90k USD

    Hybrid

    Full Time

    #Healthcare

    #Diagnostics

    #Compliance

    #HITRUST

    #ISO 27001

    #HIPAA

    #Risk Management

    #Audit Management

    #Automation

    #Communication

    #Risk

    Siteimprove logo
    Siteimprove

    Governance Risk and Compliance Analyst

    us flag
    United States

    Hybrid

    Full Time

    #Product

    #Security

    #Information Security

    #Cyber Security

    #Stakeholder Management

    #Audit

    #Customer Engagement

    F
    Flagstone Group LTD

    Information Security Team Lead

    gb flag
    United Kingdom

    Hybrid

    Full Time

    #Engineering

    #Information Security

    #Financial Technology

    #Security Frameworks

    #Risk Management

    #Incident Response

    #Cloud Security

    #Security

    #Coaching

    #AI

    Binance logo
    Binance

    Product Manager, Futures backend

    Remote

    Full Time

    #Product

    #Design

    #Trading

    #Financial Products

    #Risk

    #Algorithms

    #Analytical Skills

    Spring Fertility logo
    Spring Fertility

    Business Analyst

    85k - 125k USD

    Remote

    Full Time

    #Health Care

    #Technology

    #Business Analysis

    #Process Improvement

    #user

    #Testing

    #Support

    #Change Management

    #Data

    #Risk Assessment

    #MS Visio

    #Lucidchart

    Z
    Zip Co Limited

    Director Business Management Technology Data AI

    au flag
    Australia

    Hybrid

    Full Time

    #Technology

    #Operations

    #Business Management

    #Leadership

    #Commercial Acumen

    #Workforce Planning

    #Enterprise Architecture

    #Risk Management

    #Audit

    #Incident Response

    Norinchukin logo
    Norinchukin

    Non Financial Risk Manager

    nl flag
    Netherlands

    Hybrid

    Full Time

    #Risk Management

    #GRC

    #Risk Assessment

    #Testing

    Coalfire logo
    Coalfire

    Account Executive - AI, Cloud and Compliance Advisory

    Remote

    Full Time

    #Corporate

    #Sales

    #Cybersecurity

    #GRC

    #AI

    #Cloud Technology

    #Salesforce

    #Solution Selling

    #Management

    #MEDDPICC

    #Outreach

    C
    Circ

    Engineering Cost Controls Manager

    fr flag
    FR, BE, +2 more

    On-site

    Full Time

    #Engineering

    #Project Management

    #Cost Control

    #Cost Management

    #Forecasting

    #Risk Assessment

    #Microsoft Project

    #Communication

    #Data Analysis

    Nsecure logo
    Nsecure

    Information Security Privacy Consultant

    nl flag
    Netherlands

    On-site

    Full Time

    #Information Security

    #Privacy

    #Compliance

    #ISO 27001

    #ISO 27701

    #SOC 2

    #Risk Management

    #Security

    M
    Mews

    Director of Product and Engineering - Fintech Platform

    Hybrid

    Full Time

    #Product

    #Fintech

    #Hospitality

    #Product Strategy

    #Leadership

    #Risk

    #Payment Processing

    #Scalability

    #Security

    #CI CD

    #Testing

    #Stakeholder Management

    Citizant logo
    Citizant

    SQL Database Administrator

    us flag
    United States

    On-site

    Full Time

    #Technology

    #Microsoft SQL

    #Database Architecture

    #Database

    #Backup

    #Disaster Recovery

    #Data Security

    #Performance Optimization

    Your dream job awaits.

    Explore exciting opportunities, connect with top employers, and ignite your career.