Senior Risk Analyst, Privacy & Third-Party Risk
T. Rowe Price · Maryland
📍 Baltimore, MDvia workdayFirst listed here 2026-09-20
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to T. Rowe Price.
At T. Rowe Price, we identify and actively invest in opportunities to help people thrive in an evolving world. As a premier global asset management organization with more than 85 years of experience, we provide investment solutions and a broad range of equity, fixed income, and multi-asset capabilities to individuals, advisors, institutions, and retirement plan sponsors. We take an active, independent approach to investing, offering our dynamic perspective and meaningful partnership so our clients can feel more confident.
We believe doing the right thing for our clients and our associates is good business . With a career at the firm, y ou can expect opportunities to create real impact at work and in your community. Y ou’ll enjoy resources to support your career path, a s well as compensation , benefits , and flexibility to enrich your life. Here, you’ll find a collaborative culture that respect s and valu e s differences and colleagues who share a spirit of generosity .
Join us for the opportunity to g row and make a difference in ways that matter to you .
Role Summary
The Senior Risk Analyst – Privacy & Third-Party Risk is a Second Line of Defense (2LoD) role and a member of the Global Privacy Office (GPO) and Third-Party Risk Management (TPRM) function. The role provides independent risk oversight, effective challenge, and assurance over first-line activities and outsourced TPRM services, operating with minimal supervision and a high degree of professional judgment.
This position is expected to independently manage complex risk assessments, lead oversight activities, identify emerging risk themes, and deliver clear, actionable insights to senior stakeholders and governance committees. The role also supports the effective operation and continuous improvement of the GPO and TPRM programs through risk reporting, data analysis, issue management, technology enablement, and maintenance of core governance and compliance processes.
Responsibilities
Privacy Risk – Global Privacy Office:
Independently provide 2LoD oversight of privacy risks arising from first-line business activities and serve as a subject matter resource on privacy risk matters.
Lead review and challenge of Privacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments, including assessments involving new technologies, artificial intelligence, sensitive data, and elevated privacy risk.
Evaluate the design and operating effectiveness of privacy controls and recommend enhancements aligned with regulatory expectations and risk appetite.
Independently review privacy incidents, including root cause analyses and remediation plans, and support reconciliation, trend analysis, governance reporting, and escalation of significant privacy incidents.
Provide technical expertise and support the implementation of privacy and data protection processes, controls, and procedures based on enterprise-wide guidance issued by the Global Privacy Office.
Support Privacy and Security by Design activities by evaluating new technologies, systems, products, and business initiatives; assessing privacy risks and control requirements; and providing risk-based guidance to business and technology stakeholders.
Partner with Technology, Information Security, Legal, Compliance, and business stakeholders to support appropriate implementation of privacy requirements and controls.
Identify opportunities to enhance the Global Privacy Office’s technical capabilities; develop, test, and work with technology teams to deploy such capabilities, including workflow automation, reporting, analytics, and AI-enabled solutions.
Support the maintenance of the firm’s required privacy compliance documentation (e.g., Records of Processing Activities, Transfer Impact Assessments, procedures, guides, training, SharePoint sites), privacy inventories, registers, response materials, and supporting program records.
Support the execution of the privacy compliance monitoring program.
Support recurring privacy governance and compliance activities, including regulatory reporting, metrics, management information, periodic reconciliations, annual recertifications, readiness exercises, and regulatory or operational-impact assessments.
Support privacy-related inquiries, due diligence questionnaires, requests for information, and other stakeholder requests by researching issues, coordinating responses, and maintaining reusable response content.
Third-Party Risk Management:
Perform quality assurance and effective challenge of third-party risk outputs produced by external service providers and first-line stakeholders.
Independently review and challenge complex or elevated-risk third-party assessments, including due diligence findings, control deficiencies, risk responses, and recommendations to business stakeholders.
Monitor adherence to SLAs, KPIs, and contractual obligations of outsourced TPRM providers and escalate deficiencies as appropriate.
Identify systemic control gaps, concentration risk, and emerging third-party risk trends across the vendor population.
Evaluate and challenge third-party information security, technology, resiliency, privacy, and other risk considerations, partnering with domain subject matter experts where specialized expertise is required.
Contribute to the ongoing development of fourth-party risk governance and oversight practices.
Identify opportunities to enhance TPRM’s technical capabilities; develop, test, and work with technology teams to deploy such capabilities, including AI-assisted quality assurance, workflow automation, risk analytics, and reporting solutions.
Support the maintenance of the firm’s required TPRM compliance documentation (e.g., Policy, Supplier Management Standards, questionnaire templates, frameworks, training, SharePoint sites).
Support TPRM intake and stakeholder inquiries, including coordination and routing of requests, maintenance of supplier and p
More Maryland jobs
Maryland jobs · Browse all locations