GRC CareersConnecting Talent and Trust. Post a Job Log in

JobsOhioCincinnatiThird-Party Risk Management Specialist

Third-Party Risk Management Specialist

Fifth Third Bank
Third-Party RiskHybridFull-timeCincinnati, OH

Fifth Third Bank is hiring for the role of Third-Party Risk Management Specialist, Cincinnati, OH (Hybrid). This is a Third-Party Risk role in the governance, risk, and compliance field. Review the full details below and apply directly with Fifth Third Bank.

Organization: Fifth Third BankLocation: Cincinnati, OHWorkplace: HybridFocus: Third-Party RiskPosted: Jul 29, 2026
Fifth Third Bank is hiring for this Third-Party Risk role in Cincinnati, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC roles in Cincinnati →

Performs vendor due diligence reviews, SOC report analyses, and risk evaluations for critical bank vendors and fintech partners. Monitors continuous third-party risk indicators and reports vendor exposure metrics to the Risk Committee. Aligns third-party risk evaluations with OCC and Interagency guidance.

Location and market context

This role is based in Cincinnati on-site. Local candidates benefit from being close to Fifth Third Bank's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About third-party risk roles

Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Roles like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.

How to position yourself for this third-party risk role

Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Fifth Third Bank would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.