Associate Director, Third Party Risk Governance & Framework

Posted 3 Days Ago
Be an Early Applicant
Tampa, FL, USA
In-Office
Expert/Leader
Financial Services
The Role
Leads the design, governance, and enhancement of DTCC’s enterprise Third Party Risk framework. Responsibilities include managing policies, methodologies, taxonomies, lifecycle requirements, controls, regulatory alignment, critical third-party resilience, contingency planning, and specialized provider governance. Partners with compliance, legal, audit, operational resilience, and business teams to support examinations, remediation, risk assessments, and continuous improvement in a highly regulated financial-services environment.
Summary Generated by Built In
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
 

The Impact You Will Have in This Role

 

As part of Operational Risk & Resilience (ORR), the Associate Director, Third Party Risk Governance & Framework strengthens DTCC's second line of defense (2LoD) by managing and implementing the design, governance, and enhancements of the Third Party Risk framework. The role defines how Third Party Risk is managed across DTCC through policies, standards, methodologies, regulatory alignment, resilience integration, lifecycle requirements, and program governance. In this capacity, you will help strengthen DTCC's Third Party Risk program, control environment, and risk culture.


Primary Responsibilities


Third Party Risk Framework & Lifecycle Governance

  • Maintain Third Party Risk policies, standards, procedures, methodologies, controls, and governance documentation.
  • Define risk-based lifecycle requirements across third-party identification, assessment, management, monitoring, contingency planning, and termination.
  • Drive framework enhancements and work with first line of defense (1LoD) Third Party Management (TPM) to improve program effectiveness, training, operational clarity, regulatory alignment, and responsiveness to emerging risks.

Risk Taxonomy, Methodology & Control Integration

  • Maintain Third Party Risk taxonomies, risk categories, classification criteria, tiering standards, and criticality methodologies.  
  • Promote consistent application of segmentation, assessment, monitoring, oversight, and reporting standards across the enterprise.  
  • Integrate Third Party Risk expectations into enterprise risk processes, including RCSAs, CPRAs, risk scenarios, control expectations, and assessment methodologies.

Regulatory Alignment & Examination Support

  • Maintain awareness of applicable regulatory expectations and translate changes into policy, standards, control, and governance enhancements.
  • Partner with Compliance, Legal, Internal Audit, TPM, and business stakeholders to support regulatory examinations, remediation activities, and ongoing supervisory readiness.


Critical Third Party, Resilience & Dependency Governance

  • Establish governance requirements for critical third parties, including enhanced due diligence, ongoing monitoring, resilience, contingency planning, substitutability, and exit strategies.
  • Partner with Business Continuity and Operational Resilience teams to embed third-party resilience and dependency considerations into lifecycle and governance decisions.

Specialized Third Party Risk Governance

  • Establish enterprise requirements for specialized third-party risk areas, including third party provider types (e.g. technology, market data, staff augmentation, exchange and trading venues, financial market infrastructure, clearing brokers), CriticalPlus+ designations and contingent worker risk management.
  • Define governance controls for onboarding, access, tenure, concentration risk, privileged access, role dependency, supervisor accountability, and regulatory compliance.

Qualifications

  • 8-10 years of experience in Third Party Risk Management, Operational Risk, Enterprise Risk Management, Compliance, Regulatory Affairs, or related disciplines.
  • Bachelor's degree preferred or equivalent experience.
  • Strong understanding of Third Party Risk frameworks, cyber, resiliency, compliance, privacy, governance models, lifecycle requirements, and regulatory expectations.
  • Experience developing or enhancing policies, standards, controls, and risk frameworks in highly regulated environments.
  • Financial services, market infrastructure, banking, or regulatory experience preferred.

Talents Needed for Success

  • Ability to translate complex regulatory expectations into practical, scalable, and risk-based governance requirements.
  • Sound judgement and risk-based decision making.
  • Strong knowledge of risk taxonomy, classification, tiering, segmentation, and assessment methodologies.
  • Experience supporting regulatory examinations, remediation programs, and framework enhancement initiatives.
  • Executive communication, stakeholder management, influencing, strategic thinking, and program execution skills.
  • Collaborative, proactive, and focused on continuous improvement, risk reduction, and regulatory excellence.

Pay and Benefits:
 

  • Competitive compensation, including base pay and annual incentive
  • Comprehensive health and life insurance and well-being benefits, based on location
  • Pension / Retirement benefits
  • Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
  • DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).

The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Skills Required

  • 8-10 years of experience in Third Party Risk Management, Operational Risk, Enterprise Risk Management, Compliance, Regulatory Affairs, or related disciplines
  • Bachelor’s degree or equivalent experience
  • Strong understanding of third-party risk frameworks, cyber, resilience, compliance, privacy, governance models, lifecycle requirements, and regulatory expectations
  • Experience developing or enhancing policies, standards, controls, and risk frameworks in highly regulated environments
  • Experience with risk taxonomy, classification, tiering, segmentation, and assessment methodologies
  • Experience supporting regulatory examinations, remediation programs, and framework enhancement initiatives
  • Executive communication, stakeholder management, influencing, strategic thinking, and program execution skills
  • Financial services, market infrastructure, banking, or regulatory experience

The Depository Trust & Clearing Corporation (DTCC) Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about The Depository Trust & Clearing Corporation (DTCC) and has not been reviewed or approved by The Depository Trust & Clearing Corporation (DTCC).

  • Healthcare Strength — Medical, dental, and vision coverage are comprehensive and include mental health support, in-network preventive care, and company-supported HSA/FSA options. Company HSA contributions plus life, AD&D, and disability coverage further reinforce depth of protection.
  • Retirement Support — A 401(k) with company matching and references to pension-related benefits provide meaningful long-term savings support. Charitable contribution matching and financial-planning resources complement the core retirement offerings.
  • Parental & Family Support — Generous parental leave, adoption assistance, childcare benefits, and dependent care FSAs indicate strong support for families. Back-up care and specialized family health programs are highlighted as part of the package.

The Depository Trust & Clearing Corporation (DTCC) Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Jersey City, NJ
5,075 Employees
Year Founded: 1973

What We Do

With over 45 years of experience, DTCC is the premier post-trade market infrastructure for the global financial services industry. From 21 locations around the world, DTCC, through its subsidiaries, automates, centralizes and standardizes the processing of financial transactions, mitigating risk, increasing transparency and driving efficiency for thousands of broker/dealers, custodian banks and asset managers. Industry owned and governed, the firm simplifies the complexities of clearing, settlement, asset servicing, data management, data reporting and information services across asset classes, bringing increased security and soundness to financial markets. In 2021, DTCC’s subsidiaries processed securities transactions valued at nearly U.S. $2.4 quadrillion. Its depository provides custody and asset servicing for securities issues from 177 countries and territories valued at U.S. $87.1 trillion. DTCC’s Global Trade Repository service, through locally registered, licensed, or approved trade repositories, processes 16 billion messages annually. To learn more, please visit us at www.dtcc.com.

Similar Jobs

Easy Apply
Remote or Hybrid
United States of America
500 Employees
80K-105K Annually

NinjaOne Logo NinjaOne

Solutions Engineer

Information Technology • Productivity • Software • Infrastructure as a Service (IaaS)
Remote or Hybrid
2 Locations
2000 Employees

CSC Logo CSC

Client Service Representative

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Hybrid
Tallahassee, FL, USA
8500 Employees

CrowdStrike Logo CrowdStrike

Engineer III, AI SDLC Engineer (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account