Job description
General information
Ally and Your Career
The Opportunity
At Ally, you get a startup feel, but experience the benefits of a company that’s worked out the kinks and is fulfilling its purpose. We’re always evolving and see that as a good thing. From owning our work to seeing its impact in the real world, our team is relentless in finding new ways technology can help make experiences better and help people. We are problem solvers, we value diverse thinking, we support one another, and we challenge ourselves to think bigger in the journey to deliver customer-obsessed tech solutions.
To read more about what our tech team does, be sure to visit our tech blog at ally.tech
Ally’s Business Line Risk Governance team is expanding to provide oversight of Ally third Parties in alignment with the All Third Party Risk Management requirements.
This role will work closely with Ally Sourcing and Third Party Risk Management teams to ensure oversight and governance of 3rd parties is done. The role will also work with Relationship Owners make sure proper supplier oversight, documentation, and risks are addressed.
The Third-Party Cyber Risk Specialist, position at Ally is a member of the Business Line Risk Governance (BLRG) team in Information Protection and Risk Management (IPRM).
This Specialist role will be the front line for oversight, monitoring and escalating compliance and IT risks with Ally service providers. This role will monitor numerous suppliers to ensure compliance with our Third Party Risk Management standards and any risk items are documented and escalated when needed. The Senior Specialist will review risks, help create processes to respond to these risks and create metrics to allow Ally to understand their supplier compliance posture and identify risk trends and themes.
The Work Itself
- Review and approve Inherent Product and Service Risk Assessment for completeness and accuracy to ensure Ally captures all risks associated with a particular supplier.
- Oversee the Supplier Performance Evaluation process. Work with Relationship Owners to make sure that Relationship Owners are completing evaluations on time, review results and follow up on questions or non-compliance items.
- Help maintain Third Party Cyber Risk inventory and support Relationship Owners in completion of inventory attestations.
- Be the SME on Ally Third Party Requirements and Third Party Governance requirements.
- Review and Challenge new third party connection requests and assist with annual audit.
- Review SOX and other reports from Third Parties to ensure compliance to Ally standards
- Create and maintain metrics for reporting / dashboards related to risks, performance, and issues and identify emerging risks or trends across reported supplier base.
- Monitor Third Party activities and escalate key concerns to appropriate parties within Ally.
The Skills You Bring
- 1+ years of Information Technology, Risk or Compliance experience including:
- 1+ years of Information Security, Compliance, Risk or Audit experience
- 1+ years of Third Party Management experience.
- 1+ years of general or ‘hands-on’ information technology experience (Network Engineer, System Admin, Database Admin, Programmer, etc.)
- Working knowledge of common information security and technology concepts, risks and best practices related to:
- Risk and vulnerability Management
- Information Technology
- Web and Infrastructure Security
- Consultative skills with the ability to build collaborative relationships within all levels of an organization
- Strong written and oral communication skills including the ability to create organized and articulate reports and presentations from underlying data that are easily understood by teammates and Business Partners
- Ability to take ownership of an initiative/issue through completion
- Experience in the finance / banking industry is a plus
- Security, technology or audit/compliance related certifications are a plus
How We'll Have Your Back
- Time Away: competitive holiday and flexible paid-time-off, including time off for volunteering and voting.
- Planning for the Future: plan for the near and long term with an industry-leading 401K retirement savings plan with matching and company contributions, student loan and 529 educational assistance programs, tuition reimbursement, and other financial well-being programs.
- Supporting your Health & Well-being: flexible health and insurance options including dental and vision, pre-tax Health Savings Account with employer contributions and a total well-being program that helps you and your family stay on track physically, socially, emotionally, and financially.
- Building a Family: adoption, surrogacy, and fertility support as well as parental and caregiver leave, back-up child and adult/elder day care program and childcare discounts.
- Work-Life Integration: other benefits including LifeMatters® Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs.
Who We Are:
Ally Financial is a customer-centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial-services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com.
Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law.
We are committed to working with and providing reasonable accommodation to applicants with physical or mental disabilities. For accommodation requests, email us at work@ally.com. Ally will not discriminate against any qualified individual who is capable of performing the essential functions of the job with or without reasonable accommodation.
seankuhnke.com is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, seankuhnke.com provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, seankuhnke.com is the ideal place to find your next job.