**General information**
**Ref #** 22899
**Remote?** No
**Ally and Your Career**
*
Ally Financial only succeeds when its people do - and that's more than some cliché people put on job postings. We live this stuff! We see our people as, well, people - with interests, families, friends, dreams, and causes that are all important to them. Our focus is on the health and safety of our teammates as well as work-life balance and diversity and inclusion. From generous benefits to a variety of employee resource groups, we strive to build paths that encourage employees to stretch themselves professionally. We want to help you grow, develop, and learn new things. You're constantly evolving, so shouldn't your opportunities be, too?
**The Opportunity**
This role is on a hybrid schedule in our Charlotte office, in office a few days weekly with a couple remote days.
The Third Party Risk Management (TPRM) Senior Event Analyst is part of the TPRM Resilience and Response team and plays a key role in the intake, interpretation, analysis, and coordination of third-party cybersecurity and operational events. This role helps assess cyber breaches and security incidents involving Ally's third parties by reviewing event details, understanding the nature and scope of the issue, evaluating potential Ally impact, and helping determine the appropriate risk response. The role works closely with Ally's Information Protection Risk Management, Relationship Owners, Business Line Risk, Fraud, Cyber Compliance, Legal, Contracting, and Privacy teams to support timely assessment, escalation, stakeholder communication, and representation of Third Party Risk Management perspectives across the enterprise.
A primary focus of the role is evaluating third-party cyber event information to identify what happened, which products, services, data, systems, or business processes may be affected, and whether the event creates operational, regulatory, privacy, reputational, or customer impact to Ally. The Senior Event Analyst helps translate technical cyber incident details into business and risk context, supports effective challenge of vendor responses and internal impact assessments, and helps identify themes, control gaps, process improvements, and potential issues requiring escalation or issue management. Candidates with experience in third-party risk, cybersecurity, operational risk, incident response, threat intelligence, information security, or related control functions are encouraged to apply. Familiarity with financial services regulatory expectations, cybersecurity frameworks, incident response practices, and risk analysis methods will help the candidate succeed in this role.
This role participates in daily event triage to support rapid fact-gathering, cyber impact analysis, risk-based escalation, and accurate documentation of key decisions, open questions, vendor commitments, and follow-up actions. It is well suited for someone who is organized, collaborative, comfortable interpreting cyber incident information, and able to work across multiple stakeholders in a fast-moving environment. Strong note-taking, writing, analysis, critical thinking, and presentation skills are important to success in the role.
Additional responsibilities include supporting procedures, reporting, tooling, engagement tracking, and program documentation that help the broader resilience and response function operate effectively and continue to mature over time.
**The Work Itself**
Incident Analysis & Response
* Support end-to-end management of third-party cyber events, including intake, escalation, impact analysis, vendor engagement, and closure activities.
* Participate in cybersecurity incident response activities as a risk and coordination partner.
* Help coordinate post-event reviews to identify issues, gaps, trends, and opportunities for improvement.
* Support remediation planning and follow-up activities for identified issues and process improvements.
* Provide occasional on-call support, as needed, for significant incident response activities.
Stakeholder Engagement & Communication
* Build and maintain strong working relationships with internal stakeholders to support event coordination and follow-up activities.
* Help prepare clear, timely communications for leadership and stakeholders throughout the event lifecycle.
* Partner with cybersecurity, risk, and business teams to support effective and well-coordinated event response.
* Support external engagement routines and stakeholder reporting tied to event management activities.
Process Improvement
* Serve as a second-line challenge partner and support issue identification, escalation, and follow-up where appropriate.
* Help document, standardize, and enhance processes within established organizational frameworks and procedures.
* Support document retention and recordkeeping activities to maintain accurate, audit-ready records.
* Assist the Third Party Risk Manage