IT Third Party Risk Management Associate

Freddie Mac
McLean, VA
Aug 22, 2019
Aug 28, 2019
Full Time
Information Technology Operational Risk Management (ITRM) is responsible for providing oversight of operational risks associated with all operating activities of Freddie Mac's Information Technology division. The primary responsibilities of ITRM include providing risk management, risk advisory, third party IT risk management, regulatory liaison, and policy/standards governance for the Information Technology division. This could include managing the review and publication of divisional policies and standards, defining and implementing risk management frameworks, monitoring and reporting risks and risk response, performing risk reviews and evaluations, and driving continuous improvement of risk management capabilities across IT. ITRM is led by the Vice President, IT Operational Risk & Governance.

ITRM is looking for an risk associate to support 1st line Third Party IT Risk Management team that will assist with the development, implementation and execution of an IT third party risk management program. Areas of support will include Risk Advisory, Risk Assessment, Third Party IT Risk Management, and Polices and Standards. This position requires that the applicant have a strong understanding of the risk frameworks, operational risks, and the execution of risk management processes and governance within a large institution.

Your Work Falls into Three Primary Categories:

Risk Assessment and Identification
  • Executing Third Party IT Risk Management program functions
  • Identification, understanding and management of Information and Technology risk associated with the operational processes for the IT division
  • Apply sound judgment in evaluating risks and controls; effectively challenge the business on the identification and acceptance of risks and the adequacy of controls.
  • Perform risk assessments to reassess current risks and to identify emerging key risks (operational, compliance, technology, third party, etc.); Identify and assess control effectiveness and/or gaps.

Risk Advisory and Communication
  • Advise the IT 'customers' on means and methods to drive remediation of risk related issues and operational events

Risk Reporting, Metrics and Ongoing Due Diligence
  • Reporting of IT risk metrics and data
  • Providing transparency of risk exposures through implementing sound reporting for risk-based decision making
  • Identify, assess and communicate risks as required for periodic third party assessments

Estimated Travel: 15% to vendor locations as required


  • Bachelor's Degree
  • Experience working with risk management - methods and techniques for the assessment and management of risk.
  • Ability to operate as a self-motivated, pro-active, and result-driven problem solver with excellent analytical and communication skills
  • Ability to understand IT business processes, management objectives, risk appetite and tolerances and impact of changes to risk profiles
  • Experience in IT governance and controls, including governance frameworks, COBIT, FFIEC, COSO, ISO-31000, etc.

Keys to Success in this Role
  • Self-starter and self-motivated.
  • Ability to work & collaborate effectively in a team environment.
  • Sense of urgency and able to apply risk-based approach to prioritize work.
  • Ability to communicate clearly, effectively, persuasively with technology and business stakeholders.
  • Motivated to learn new technologies and identify process improvements and efficiencies.
  • Ability to adapt to change while continuing to deliver on assigned objectives.
  • Strong verbal and written communication skills.

Top 3 Personal Competencies to Possess
  • Drive for Execution - Be accountable for strong individual and team performance
  • Partnership - Build trust and strong partnerships through your own and team's actions
  • Growth and Development - Know or learn what is needed to deliver results and successfully compete

Preferred Skills

Preferred Skills
  • CISA, CPA, CIA, PMP, CISSP or other relevant professional certification
  • Financial Services experience
  • IT Risk management experience
  • Knowledge and skills across:
    • COSO
    • ISACA Risk IT framework
    • ISACA COBIT 5.0
    • ISO 31000-series and 27000-series
    • 13335

Today, Freddie Mac makes home possible for one in four home borrowers and is one of the largest sources of financing for multifamily housing. Join our smart, creative and dedicated team and you'll do important work for the housing finance system and make a difference in the lives of others. Freddie Mac is an equal opportunity and top diversity employer. EOE, M/F/D/V.

Similar jobs