IT Third-Party Controls Analyst

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
83K-118K Annually
Senior level
Fintech • Real Estate
The Role
Supports governance, monitoring, and IT General Controls for third-party relationships and external users. Responsibilities include due diligence, risk classification, identity and access oversight, least-privilege reviews, access certifications, MFA and DLP monitoring, incident escalation, remediation tracking, audit support, reporting, business continuity and disaster recovery activities, offboarding controls, process documentation, and stakeholder coordination across IT, security, compliance, legal, HR, and vendor management.
Summary Generated by Built In

Guild Mortgage Company, closing loans and opening doors since 1960. As a mortgage banking firm we are dedicated to serving the home owner/buyer. Our goal is to provide affordable home financing for our customers, utilizing the best terms available while providing a level of professionalism and service unsurpassed in the lending industry.

Position Summary

The IT Third-Party Controls Analyst supports the governance, monitoring, and control of Guild's third-party relationships and external business partner access throughout the engagement lifecycle. This includes offshore staffing, SaaS/cloud providers, outsourced service providers, contractors, and non-standard access models where external users may receive elevated or internal-like access to Guild systems.

Under general supervision, the role executes and monitors IT General Controls that reduce third-party and external-user risk, including due diligence support, engagement classification, access and identity oversight, provisioning and deprovisioning controls, data protection, incident response, governance reporting, and remediation tracking. The role partners with IT Governance, Information Security, IT Operations, IAM, Vendor Management, HR, Legal/Compliance, and other stakeholders to ensure access models, least-privilege controls, certifications, monitoring expectations, and onboarding/offboarding processes are appropriately defined, documented, and maintained.

Compensation 

This role is an exempt position with a Targeted Salary Range of $82,506 to $118,344.94 annually.

Compensation at Guild is influenced by a wide array of factors including but not limited to local and federal minimum wage requirements, education, level of experience, and applicant’s geographical location.

Essential Functions

  • Serve as the IT General Controls contact for third-party technology relationships, including offshore staffing, SaaS/cloud providers, outsourced services, contractors, and staff augmentation. 

  • Document third-party due diligence and approval updates and partner with IT and Compliance to keep third-party records current. 
  • Translate completed due diligence and risk assessment findings into operational control requirements, ensuring identified risks are addressed through appropriately designed controls prior to go-live. 
  • Own third-party engagement classification and setup, ensuring new offshore roles, contractor engagements, and outsourced arrangements are properly configured before onboarding. 
  • Review third-party roles and access to confirm they match job function and least-privilege requirements. 
  • Support governance and control oversight for external business partner users with elevated or internal-like access to Guild systems, including validation that access models, approved roles, identity attributes, and monitoring requirements are clearly defined and documented. 
  • Coordinate periodic access certifications for third-party and external business partner users, confirming continued business need, appropriate branch/location segmentation, least-privilege alignment, and timely removal or adjustment of access no longer required. 
  • Monitor virtual desktop and third-party access controls to ensure control effectiveness. 
  • Track MFA enrollment and re-enrollment controls for third-party users, escalating gaps to IT Operations and Information Security as needed. 
  • Oversee controls for external business partner users with elevated or internal-like access, including access models, approved roles, identity attributes, and monitoring requirements. 
  • Coordinate access certifications for third-party and external business partner users, confirming business needs, segmentation, least privilege, and timely access removal or adjustment. 
  • Track remediation for non-standard external access risks, including identity gaps, manual provisioning, over-provisioning, incomplete deprovisioning, and missing enhanced monitoring. 
  • Work with IT and business stakeholders to confirm third-party access, identity, and provisioning controls remain properly scoped throughout the relationship. 
  • Monitor IT General Controls across the third-party lifecycle to confirm vendors, offshore resources, and contractors remain within approved control parameters. 
  • Monitor DLP controls for third-party relationships, including VDI, no-print, no-download, record retention, and data-handling requirements, with IT Governance and Information Security. 
  • Monitor endpoint protection and CASB/Zscaler controls for third-party and offshore endpoints to confirm compliance with security policies. 
  • Coordinate White Room setup and control validation for high-risk third-party engagements requiring enhanced physical or logical security. 
  • Manage third-party role and scope changes, ensuring changes are documented, approved, and communicated to affected teams. 
  • Track control issues, gaps, and remediation activities from monitoring, incidents, or audits. Maintain accurate documentation and coordinate with the IT Third-Party Risk Analyst to align remediation plans. 
  • Plan and facilitate third-party incident tabletop exercises, documenting execution and results. 
  • Own third-party incident escalation and reporting activities, ensuring incidents are logged, escalated, and tracked to resolution. 
  • Prepare periodic third-party risk reporting for oversight and Governance Committees, including control performance, open issues, remediation status, evidence, metrics, and KRI support. 
  • Support third-party Business Continuity Planning (BCP) and Disaster Recovery (DR) planning and annual testing activities. 
  • Support internal and external audits and regulatory examinations related to third-party IT General Controls by providing control documentation, evidence, and walkthrough support. 
  • Monitor third-party offboarding and exit controls, confirming timely removal of system and physical access and closure of contractual and data obligations when engagements end or change. 
  • Track and support remediation of control gaps related to non-standard external access models, including inconsistent identity domains, manual provisioning processes, over-provisioned access, incomplete deprovisioning, or insufficient enhanced monitoring. 
  • Support third-party oversight, governance activities, risk classification, location reviews, contract management, and engagement intake. 
  • Maintain the third-party control library, including process flows, procedure documentation, and control narratives, in coordination with the broader IT team and the IT Third-Party Risk Analyst. 
  • Produce deliverables including process flows, procedure documentation, and specialized assessment reports related to third-party processes, tools, metrics, and communication activities. 
  • Serve as an advisor to the IT General Controls Manager on third-party control matters and act as a liaison between IT Governance, Vendor Management, Corporate Initiatives, IT Operations, Information Security, HR, Legal, Compliance, and other stakeholders. 
  • Assist in maintaining Guild's compliance with applicable regulatory requirements as they relate to third-party staffing, sourcing, and operations. 
  • Champion awareness and understanding of third-party control requirements through training, presentations, and regular communication. 
  • Drive a culture of continuous improvement and customer service excellence, with visible metrics and KPIs specific to third-party control performance. 
  • Monitor industry best practices related to third-party control frameworks and recommend enhancements to the IT General Controls Manager. 
  • Perform other duties as assigned. 

Qualifications

  • Bachelor’s degree in Business Administration, Information Technology, or a related field, or an equivalent combination of education and experience. 
  • Minimum Five Years of Experience in IT Operations, Security, Risk, Audit, Vendor/Third-Party Risk Management, and/or offshore/outsourced staffing program administration. 
  • Ability to work independently and collaboratively within a team environment. 
  • Knowledge of access reviews, third-party/vendor risk management, and IT General Controls audits required.  
  • Experience supporting or coordinating offshore/outsourced staffing, SaaS/cloud vendors, or IT contractor programs strongly preferred. 
  • Ability to partner effectively with risk and governance functions, translating due diligence and risk assessment findings into operational controls. 
  • Technical Project Management and/or Business Analysis experience preferred. 
  • Demonstrated ability to analyze and manipulate data across various sources including Excel, CRMs, GRC platforms, and online repositories. 
  • Ability to create, improve, and maintain IT processes. Process modeling and procedure development experience preferred. 
  • Ability to interpret and explain complex IT systems, third-party relationships, and operations to varied audiences. 
  • Advanced proficiency in Microsoft Word, Excel, and PowerPoint required. 
  • Experience with GRC tools, vendor risk management platforms, project management tools, and IT asset-management platforms preferred. 
  • Understanding of systems development lifecycle and change management concepts. 
  • Understanding of financial institution governance and regulations including SSAE 16/18, FFIEC, and ISACA/COBIT. 
  • Excellent organization and time-management skills. 
  • Strong presentation and communication skills. 
  • Ability to summarize large amounts of information and data for executive audiences. 
  • Willingness to take ownership of processes, projects, and deliverables. 
  • Customer-focused and results-oriented. 
  • Ability to establish and meet critical deadlines. 
  • Ability to prioritize multiple activities and complex projects simultaneously. 
  • Strong research and problem-solving skills. 
  • Commitment to company values.
  • Customer Service - Proactive attention to each person
  • Integrity - Do and say what's right
  • Respect - Treat others with dignity
  • Collaboration - Listen and work together
  • Learning - Seek knowledge and strive for improvement
  • Excellence – Deliver the unexpected

Supervision

  • Job Scope: Plays a key role in area by generating insights and ideas on policies, processes, procedures, and efficiency; contributes ideas to strategic and operational plans to ensure alignment

  • Complexity: Problem solving involves evaluating and resolving discrepancies with people, data, analyses, processes, etc. within prescribed program/project guidelines; may also involve resolving basic resource coordination and availability

  • Impact: Decisions and actions have an impact on the smooth operation and timeframes of the department, programs/projects; impact on the broader organization is generally indirect

  • Interaction/Supervision: Works under broad direction with considerable latitude for independent actions; guided by professional standards, desired outcomes and unit/project/program specifications

Requirements

Physical: Work is primarily sedentary; mobility in an office setting.

Manual Dexterity: Ability to operate standard office equipment and keyboards.

Audio/Visual: Regularly required to accurately perceive, distinguish and interpret information received visually and through audio; e.g., words, numbers and other data broadcasted aloud/viewed on a screen, as well as print and other media.

Environmental: Office environment – moderate noise, no substantial exposure to adverse environmental conditions.

Travel: 5% or less

Mental: Learn new tasks, remember processes, maintain focus, complete tasks independently, and make timely decisions in the context of a workflow.

Schedules: Work is primarily performed during the business week, Monday - Friday

Guild offers a pleasant work environment, competitive compensation and excellent benefits package; including medical, dental, vision, life insurance, AD&D, LTD and 401(k) with employer match.

Guild Mortgage Company is an Equal Opportunity Employer. 

 REQ#: ITTHI018470

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Skills Required

  • Bachelor's degree in Business Administration, Information Technology, or a related field, or equivalent education and experience
  • At least five years of experience in IT operations, security, risk, audit, vendor or third-party risk management, or offshore/outsourced staffing program administration
  • Knowledge of access reviews, third-party/vendor risk management, and IT General Controls audits
  • Ability to work independently and collaboratively
  • Ability to translate due diligence and risk assessment findings into operational controls
  • Ability to analyze and manipulate data across Excel, CRMs, GRC platforms, and online repositories
  • Ability to create, improve, and maintain IT processes
  • Advanced proficiency in Microsoft Word, Excel, and PowerPoint
  • Ability to interpret and explain complex IT systems, third-party relationships, and operations
  • Understanding of systems development lifecycle and change management concepts
  • Understanding of financial institution governance and regulations, including SSAE 16/18, FFIEC, and ISACA/COBIT
  • Strong organization, time-management, presentation, communication, research, and problem-solving skills
  • Ability to summarize large amounts of information and data for executive audiences
  • Ability to establish deadlines and prioritize multiple activities and complex projects
  • Customer-focused and results-oriented approach
  • Experience supporting or coordinating offshore/outsourced staffing, SaaS/cloud vendors, or IT contractor programs
  • Technical project management and/or business analysis experience
  • Process modeling and procedure development experience
  • Experience with GRC tools, vendor risk management platforms, project management tools, and IT asset-management platforms

Guild Mortgage Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Guild Mortgage and has not been reviewed or approved by Guild Mortgage.

  • Parental & Family Support Fully paid parental leave is described as generous, with 12 weeks for medical, non-birthing parent, and caregiving leave from day one, and 18–20 weeks for birthing parents. This indicates strong support for families across different caregiving situations.
  • Leave & Time Off Breadth Paid holidays include a collective week off around July 4 and floating holidays, with PTO that rolls over and a five‑week paid sabbatical after 4.5 years. Additional options include sick leave, volunteer time, bereavement, jury duty, and open PTO for some roles.
  • Healthcare Strength Medical, dental, vision, and mental health coverage are offered alongside life and disability insurance, with options to purchase enhanced policies. Wellbeing perks such as a fitness stipend complement the core health benefits.

Guild Mortgage Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Diego, CA
3,600 Employees
Year Founded: 1960

What We Do

Guild Mortgage has become one of the nation’s leading independent ‭mortgage providers by following a ‭simple rule—doing what’s right for our customers. Since 1960, we’ve grown ‭through every economic cycle. ‭Today, no other mortgage lender ‭has our stability, experience and ‭uncompromising focus on ‭customer service. When you choose Guild, you get: - A commitment closing your loan on time - A wide array of ‭specialized products and programs for every type of homebuyer - Loan officers you can meet face-to-face or online ‭ - A direct lender that tailors each loan to fit the needs of individual borrowers - Long-term relationships—we ‭service the majority of loans we close Guild Mortgage Company; Equal Housing Opportunity; AZ BK #0018883; Licensed by the Department of Financial Protection and Innovation under the California Residential Mortgage Lending Act; MA Mortgage Lender License #MC3274; MA Mortgage Broker License #MC3274; Licensed by the Mississippi Department of Banking and Consumer Finance; Licensed by the N.J. Department of Banking and Insurance; NV Mortgage Company #1141; OR ML-176; Rhode Island Licensed Lender; Rhode Island Licensed Third-Party Loan Servicer; Company NMLS ID 3274. www.nmlsconsumeraccess.org/. All loans subject to underwriter approval. Terms and conditions apply, subject to change without notice. Guild Mortgage Company is an Equal Opportunity Employer. Guild Mortgage Company 5887 Copley Drive, San Diego, CA 92111; For more licensing information, please visit www.guildmortgage.com/licensing.

Similar Jobs

Gusto Logo Gusto

Consultant

Fintech • HR Tech
Easy Apply
Remote or Hybrid
United States
4405 Employees
98K-140K Annually
Remote or Hybrid
2 Locations
289097 Employees

Sprout Social Logo Sprout Social

Director, GTM Strategy & Planning

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
US
1400 Employees
200K-330K Annually

Rubrik Logo Rubrik

Senior Manager, Global Deal Desk

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
Remote
United States
3000 Employees
169K-253K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account