Vendor Risk Manager (6 Month Contract) - Chief Risk Office jobs in United States
cer-icon
Apply on Employer Site
company-logo

Bloomberg · 3 months ago

Vendor Risk Manager (6 Month Contract) - Chief Risk Office

Bloomberg is a leading financial services and technology company, and they are seeking a Vendor Risk Manager to join their Chief Risk Office. The role involves assessing and managing risks associated with vendors and third-party service providers, ensuring compliance with risk management policies, and contributing to strategic initiatives to enhance the Vendor Risk program.

AnalyticsBusiness Information SystemsFinancial ServicesInformation ServicesNews
check
Comp. & Benefits
check
H1B Sponsor Likelynote

Responsibilities

Liaise with business and technology teams to understand their use of vendor services and products and appropriately assess the inherent risks related to information security, privacy, resiliency, concentration, regulatory compliance, subcontracting, location / geography, among others
Maintain the vendor and vendor engagement inventory and risk profiles
Conduct due diligence control assessments, continuously monitor and report on Vendor and vendor engagement risks
Coordinate risk mitigation activities with vendors and Bloomberg departments and subsidiaries
Interpret, train and enforce compliance with Bloomberg’s Vendor Risk Management Policy
Cultivate and leverage relationships with CISO, Legal, Compliance, Enterprise Risk Management (ERM) and other control functions to accomplish objectives
Lead key VRM activities and demonstrate understanding of the top and material risks affecting Bloomberg, our supply chains, and our clients
Act as subject matter expert on VRM matters supporting Bloomberg departments for which you are responsible
Provide advisory support to Bloomberg departments on risk
Provide and coordinate input to key compliance, legal and regulatory initiatives
Demonstrate existing or develop targeted material to deliver actionable risk reporting to Bloomberg departments as needed
Participate in select risk committees / working groups

Qualification

Information SecurityRisk ManagementVendor Risk AssessmentCloud ComputingTechnical Risk AnalysisCompliance RegulationsIndustry FrameworksAdvisory SupportContractual KnowledgeLeadership SkillsCommunication SkillsTeamwork SkillsCollaboration Skills

Required

Bachelor's or master's degree in Computer Science, Information Security, Business Management or equivalent industry experience
5+ years of experience working in the field of Risk Assurance, Risk Management, Internal Audit or other Compliance-related experience
An understanding of Cloud Computing and how to assess cloud-related risks
Familiarity with international regulations regarding third-party service providers
Knowledge of international regulations governing third-party service providers
Experience with industry frameworks and standards such as NIST 800-53, COBIT 5, ISO/IEC 27001/2, HITRUST, PCI DSS, CSA CAIQ/CCM, CIS CSC, and NIST 800-171
Understanding of global data privacy laws and regulations, including GDPR, Schrems II, CCPA, and HIPAA
Familiarity with emerging regulatory requirements, such as the Digital Operational Resilience Act (DORA) and the EU Artificial Intelligence Act
Experience working with vendor risk assessment frameworks and tools (e.g., SIG, VSAQ)
Technical knowledge in multiple risk domain areas such as application, architecture, system and network security, identity/access management, etc
Knowledge of current Information Security threats, trends, and mitigations
Skilled in risk management, technical risk analysis, and making complex business/risk trade-off recommendations and decisions
Understanding of impact of financial, technology and privacy regulations on Fintech products and services
Demonstrated ability to lead and influence others
Senior level written and verbal communication skills
Demonstrated leadership, teamwork and collaboration skills
Industry certifications (CISSP, CISA, CISM, CTPRP, CIPT/CIPP, GSEC, GIAC, etc.)

Preferred

An understanding of supplier agreements, contractual terms and service level agreements
Experience in developing and deploying operational performance metrics to measure IT security effectiveness and operational resilience
Experience with Cloud-based IT architectures and security products

Benefits

Merit increases
Incentive compensation (exempt roles only)
Paid holidays
Paid time off
Medical
Dental
Vision
Short and long term disability benefits
401(k) +match
Life insurance
Various wellness programs

Company

Bloomberg

company-logo
Bloomberg provides news, data, analytics, and communication services for the global business and financial world.

H1B Sponsorship

Bloomberg has a track record of offering H1B sponsorships. Please note that this does not guarantee sponsorship for this specific role. Below presents additional info for your reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (496)
2024 (382)
2023 (363)
2022 (426)
2021 (442)
2020 (588)

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
David Rosenberg
Head of Machine Learning Strategy, CTO Office
linkedin
leader-logo
Nabil Bitar
CTO - Head of Network Architecture
linkedin

Recent News

AI-powered learning ecosystems: A guide to workforce upskilling | CIO
Company data provided by crunchbase