This role owns the day-to-day operation of the Company’s third-party risk management (TPRM)
program. The Third-Party Risk Manager administers vendor onboarding, risk tiering, due
diligence, periodic reassessment, ongoing monitoring, and termination across the full vendor
lifecycle in accordance with the Third-Party Risk Management Policy (TPRM02).
This position is the primary point of contact for business owners engaging new vendors, for
vendors responding to due diligence requests, and for internal partners - Legal, Compliance,
Information Security, and Finance - who depend on accurate vendor risk information. The role
administers the Company’s vendor management software platform, maintains the authoritative
vendor inventory, and produces reporting consumed by the Risk Management Committee and
senior leadership.
The Third-Party Risk Manager works under the oversight of the Chief Information Officer and
operates within the regulatory expectations of FHFA, CFPB, HUD, state financial regulators,
GSEs, and secondary market investors.

