Senior Event Analyst, Third Party Risk Management (TPRM)
Ally Financial
- Location
- Posted Jul-29-2026
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 2 approvals (FY2023)
Skills
About this role
This role is on a hybrid schedule in our Charlotte office, in office a few days weekly with a couple remote days.
The Third Party Risk Management (TPRM) Senior Event Analyst is part of the TPRM Resilience and Response team and plays a key role in the intake, interpretation, analysis, and coordination of third-party cybersecurity and operational events. This role helps assess cyber breaches and security incidents involving Ally’s third parties by reviewing event details, understanding the nature and scope of the issue, evaluating potential Ally impact, and helping determine the appropriate risk response. The role works closely with Ally’s Information Protection Risk Management, Relationship Owners, Business Line Risk, Fraud, Cyber Compliance, Legal, Contracting, and Privacy teams to support timely assessment, escalation, stakeholder communication, and representation of Third Party Risk Management perspectives across the enterprise.
A primary focus of the role is evaluating third-party cyber event information to identify what happened, which products, services, data, systems, or business processes may be affected, and whether the event creates operational, regulatory, privacy, reputational, or customer impact to Ally. The Senior Event Analyst helps translate technical cyber incident details into business and risk context, supports effective challenge of vendor responses and internal impact assessments, and helps identify themes, control gaps, process improvements, and potential issues requiring escalation or issue management. Candidates with experience in third-party risk, cybersecurity, operational risk, incident response, threat intelligence, information security, or related control functions are encouraged to apply. Familiarity with financial services regulatory expectations, cybersecurity frameworks, incident response practices, and risk analysis methods will help the candidate succeed in this role.
This role participates in daily event triage to support rapid fact-gathering, cyber impact analysis, risk-based escalation, and accurate documentation of key decisions, open questions, vendor commitments, and follow-up actions. It is well suited for someone who is organized, collaborative, comfortable interpreting cyber incident information, and able to work across multiple stakeholders in a fast-moving environment. Strong note-taking, writing, analysis, critical thinking, and presentation skills are important to success in the role.
Additional responsibilities include supporting procedures, reporting, tooling, engagement tracking, and program documentation that help the broader resilience and response function operate effectively and continue to mature over time.