Web Analytics Made Easy - Statcounter

Event Analyst II, Third Party Risk Management

Job Description

General information

Career area
Risk

Work Location(s)
601 S. Tryon Street, NC

Remote?
No

Ref #
22413

Posted Date
06-01-26

Working time
Full time

Ally and Your Career

Ally Financial only succeeds when its people do - and that's more than some cliché people put on job postings. We live this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion. From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You're constantly evolving, so shouldn't your opportunities be, too?

Work Schedule: Ally designates roles as (1) fully on-site, (2) hybrid, or (3) fully remote. Hybrid roles are generally expected to be in the office a certain number of days per week as indicated by your manager. Your hiring manager will discuss this role's specific work requirements with you during the hiring process. All work requirements are subject to change at any time based on leader discretion and/or business need.

The Opportunity

This role is on a hybrid schedule in our Charlotte office, with a few days in office with some remote work.

The Third Party Risk Management (TPRM) Event Analyst II is part of the TPRM Resilience and Response team and supports the analysis and coordination of third-party risk activities related to cybersecurity and operational events. This role works closely with Ally's Information Protection Risk Management, Relationship Owners, Business Line Risk, Fraud, Cyber Compliance, and Privacy teams to understand events, support timely assessment and escalation, and contribute Third Party Risk Management perspectives across the enterprise.

A primary focus of the role is reviewing event details, identifying themes, and helping improve coordination across teams. The Event Analyst II supports second-line oversight activities and may assist with issue identification, documentation, and follow-up. Candidates with experience in third-party risk, cybersecurity, operational risk, incident response, or related control functions are encouraged to apply. Familiarity with financial services regulatory expectations, cybersecurity frameworks, and risk analysis practices will help the candidate succeed in this role.

This role participates in daily event triage to support impact analysis, escalation, and accurate documentation of key details. It is well suited for someone who is organized, collaborative, and comfortable working across multiple stakeholders in a fast-moving environment. Strong note-taking, writing, analytical, and communication skills are important to success in the role.

Additional responsibilities include supporting procedures, reporting, tooling, engagement tracking, and program documentation that help the broader resilience and response function operate effectively and continue to mature over time.

The Work Itself

Incident Analysis & Response

  • Support management of third-party cyber events, including intake, escalation, impact analysis, vendor engagement, and closure activities.
  • Participate in cybersecurity incident response activities as a support partner.
  • Assist with post-event reviews to identify issues, gaps, trends, and opportunities for improvement.
  • Assist with remediation tracking and follow-up activities for identified issues and process improvements.
  • Provide occasional on-call support, as needed, for significant incident response activities.

Stakeholder Engagement & Communication
  • Build working relationships with internal stakeholders to support event coordination and follow-up activities.
  • Assist with preparing clear, timely communications for leadership and stakeholders throughout the event lifecycle.
  • Partner with cybersecurity, risk, and business teams to support effective event response and coordination.
  • Support external engagement routines and stakeholder reporting tied to event management activities.

Process Improvement
  • Support second-line oversight activities and assist with issue identification, escalation, and follow-up where appropriate.
  • Help document, standardize, and enhance processes within established frameworks and procedures.
  • Support document retention and recordkeeping activities to maintain accurate, audit-ready records.
  • Assist the Third Party Risk Management program in audit and regulatory exam preparation, as needed.

Resilience and Response Program Support
  • Support the coordination for third-party response activities.
  • Provide support to the Third Party Risk Management team and contribute risk and cybersecurity perspective where needed.
  • Assist with additional Third Party Resilience and Response activities as priorities evolve.

Reporting & Metrics
  • Support regular and ad hoc reporting to help inform team priorities and management insights.
  • Help establish and maintain metrics that support program objectives and ongoing performance monitoring.
  • Support executive reporting, event analytics, and presentation materials.

The Skills You Bring

Minimum Qualifications:

  • 1 year of experience
  • High School Diploma or GED Equivalent

Preferred Qualifications:
  • Two or more years of experience in third-party risk, cybersecurity, information security, operational risk, incident response, or a related field
  • Foundational knowledge of cybersecurity controls, risk management, incident response, or related control environments
  • Awareness of current security threats, evolving risks, and the broader cybersecurity landscape, with a willingness to continue learning
  • Strong analytical and problem-solving skills, with the ability to apply sound judgment and collaborate effectively
  • Ability to build productive relationships and work effectively across business lines, risk partners, and support functions
  • Strong oral and written communication skills, including the ability to present information clearly to different audiences
  • Experience conducting research or analysis related to cybersecurity, third-party risk, regulatory change, or industry practices is helpful
  • Strong organizational skills with the ability to manage competing priorities in a fast-paced environment
  • Ability to work both independently and collaboratively across Third Party Risk Management and enterprise teams
  • Progress toward Security+, CISSP, CISM, CISA, or similar certifications is a plus, but not required
  • Experience with tools such as ServiceNow, Excel, PowerPoint, Power BI, or similar reporting platforms is helpful
  • Familiarity with frameworks such as NIST, FFIEC, or other relevant industry guidance is preferred
  • Background in incident management, cyber security risk, third-party risk, or related program support is beneficial

How We'll Have Your Back

Ally's compensation program offers market-competitive base pay and pay-for-performance incentives (bonuses) based on achieving personal and company goals. Our Total Rewards program includes industry-leading compensation and benefits plus additional incentives that are designed to meet your needs and those of your family so you can get the most out of your career and your life, including:
  • Time Away: Program starts at 20 paid time off days in addition to 11 paid holidays and 8 hours of volunteer time off yearly (time off days are prorated based on start date and program varies based on full or part-time status and management level).
  • Planning for the Future: plan for the near and long term with an industry-leading 401K retirement savings plan with matching and company contributions, student loan pay downs and 529 educational save up assistance programs, tuition reimbursement, employee stock purchase plan, and financial learning center and financial coach access.
  • Supporting your Health & Well-being: flexible health and insurance options including medical, dental and vision, employee, spouse and child life insurance, short- and long-term disability, pre-tax Health Savings Account with employer contributions, Healthcare FSA, critical illness, accident & hospital indemnity insurance, and a total well-being program that helps you and your family stay on track physically, socially, emotionally, and financially.
  • Building a Family: adoption, surrogacy and fertility assistance as well as paid parental and caregiver leave, Dependent Day Care FSA back-up child and adult/elder care days and childcare discounts.
  • Work-Life Integration: other benefits including Mentally Fit Employee Assistance Program, subsidized and discounted Weight Watchers® program and other employee discount programs.
  • Other compensations: depending on the role for which you are considered, you may be eligible for travel allowances, relocation assistance, a signing bonus and/or equity.
  • To view more detailed information about Ally's Total Rewards, please visit this link: https://www.ally.com/content/dam/pdf/corporate/ally-total-rewards-snapshot.pdf

Who We Are:

Ally Financial is a customer-centric, leading digital financial services company with passionate customer service and innovative financial solutions. We are relentlessly focused on "Doing it Right" and being a trusted financial-services provider to our consumer, commercial, and corporate customers. For more information, visit www.ally.com.

Ally is an equal opportunity employer committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to age, race, color, sex, religion, national origin, disability, sexual orientation, gender identity or expression, pregnancy status, marital status, military or veteran status, genetic disposition or any other reason protected by law.

We are committed to working with and providing reasonable accommodation to applicants with physical or mental disabilities. For accommodation requests, email us at hrpolicy@ally.com. Ally will not discriminate against any qualified individual who is capable of performing the essential functions of the job with or without reasonable accommodation.

Base Pay Range : $55000 - $95000 USD

An individual's position in the range is determined by the specific role, the scope and responsibilities of the role, work experience, education, certification(s), training, and additional qualifications. We review internal pay, the competitive market, and business environment prior to extending an offer.

Incentive Compensation: This position is eligible to participate in our annual incentive plan.