Jonathan Brito, CISA, CDPSE
Manager of Third Party Risk Management at Synctera- Claim this Profile
Click to upgrade to our gold package
for the full feature experience.
Topline Score
Bio
Credentials
-
Certified Data Privacy Solutions Engineer (CDPSE)
ISACAJul, 2020- Nov, 2024 -
Certified Information Systems Auditor (CISA)
ISACADec, 2013- Nov, 2024
Experience
-
Synctera
-
United States
-
Financial Services
-
100 - 200 Employee
-
Manager of Third Party Risk Management
-
Jul 2021 - Present
- Program Owner for all third party and partnership risk management and oversight activities - Leading FinTechs in the development of InfoSec, AppSec, BCP, DR, and Incident Management programs - Project Manager for Business Continuity and Disaster Recovery exercises - Program Manager for corporate insurance claims and renewal processes - Project Manager for client audit, due diligence, and request for proposal (RFP) - Leader for Diversity, Equality, and Inclusion (DEI) initiatives - Program owner for the design and implementation of scalable processes for third party lifecycle activities - Continuous assessment of the evolving regulatory requirements on effective third party oversight - Tracking, monitoring, and resolving third party and partnership concerns and risks - Collaborating with internal and external partners to ensure effective articulation of risk Show less
-
-
-
Aquanima Grupo Santander
-
Spain
-
Business Consulting and Services
-
400 - 500 Employee
-
Manager of Vendor Risk Assessment Center, Third Party & Outsourcing Oversight
-
May 2019 - Jul 2021
- Division of Groupo Santander, the parent company of Santander Bank N.A. - Mentored, developed, and led a team of six (6) direct reports - Provided internal and external expert guidance in strengthening risk management oversight - Governed comprehensive vendor risk lifecycle processes - 2020 Aquanima Risk Warrior Award recipient for excellent risk awareness and partnerships - Owner of governance, risk management, and compliance (GRC) processes for third party risks - Program Director for sanctions and negative news monitoring of third party relationships - Administrator for vendor risk management (VRM) system Coupa (formerly Hiperos) - Evaluated potential data security risks associated with third parties and affiliates - Ownership and governance of frameworks, standards, policies, and procedures Show less
-
-
-
Santander Bank, N.A.
-
United States
-
Banking
-
700 & Above Employee
-
Vice President, Manager of Risk Management
-
Jun 2014 - May 2019
- Mentored, developed, and led a team of five (5) direct reports - Provided internal and external guidance in strengthening risk management oversight - Administered governance, risk management, and compliance (GRC) system for vendor risks - Mentored 10 associates in developing skills in auditing, risk assessments, and analytics - Administrator for vendor risk management system Coupa (formerly Hiperos) - Effectively led projects resulting in the closure of consent orders and OCC MRAs - Discovered and evaluated data security and privacy risks with business line partners - Co-led quality assurance (QA) process for over 500 reviews conducted by peers and consultants - Delivered assessment tracking for a team of seven (7) full-time employees (FTEs) - Facilitated the onboarding for over 30 FTEs including training of systems and processes - Remediated information security, business resiliency, and regulatory compliance risks - Conducted risk-based information security and business continuity onsite and remote control efficiency evaluations for over 100 third party and affiliate based relationships - Operated control testing for application security, cybersecurity, foreign-based operations, fourth party risk management, and software development lifecycle (SDLC) - Executed complex regulatory-driven projects including time-sensitive deliverables - Developed and evaluated frameworks, standards, policies, and procedures - Managed third party risk management plans and deliverables for Heightened Standards - Managed workload and deliverables with an extensive domestic travel schedule - Managed four (4) consultants and 50 associated assessments during a multiyear engagement - Previous Titles: (i) Senior Third Party Risk Manager, Issue Management and Vendor Oversight, VP and (ii) Senior Third Party Risk Manager, Information Security, and Business Continuity Assessments, VP Show less
-
-
-
Citizens Financial Group, Inc.
-
Banking
-
700 & Above Employee
-
Senior Third Party Assurance Analyst – Onsite, Previously Third Party Assurance Analyst – Deskbased
-
Jul 2012 - Jun 2014
- 2014 Good Banking Award recipient for Embedded Risk Management - Coordinated onsite engagements with subject matter experts at vendor facilities - Led adequacy and effectiveness evaluations of information security and data integrity practices - Engaged in positive relationships with business partners for risk identification and remediation - Translated security risks and communicated effectively with business partners - Analyzed evidence and processes to assess controls enforced at third parties - Applied demonstrated experience in audit, security, and regulatory frameworks - Prepared reports, residual risk statements and gained agreement on information security risks - Managed special projects including the onsite reviews of GLBA hosted vendors - Facilitated a complex global assurance review of an offshore affiliate - Managed a schedule with extensive domestic travel Show less
-
-
-
The Washington Trust Company
-
United States
-
Banking
-
300 - 400 Employee
-
Managed Assets & Risk Management Analyst, Previously Managed Assets Intern
-
Dec 2010 - Jul 2012
- Supported management of real estate owned (REO) properties including expenditure tracking, property management, offers and purchase and sales agreements - Supported workout Loan Officers with the daily management of troubled commercial loans - Assisted with the settlement of debts and maximized potential recoveries from borrowers - Designed a streamlined Small Business Administration (SBA) loan guaranty repurchase process - Assembled and managed demand packages for loans to be repurchased by the SBA - Compiled weekly and monthly filings and reporting - Processed forbearance agreement payments, requests for appraisals, and general payments - Protected lien position's by reviewing and renewing uniform commercial code (UCC) filings Show less
-
-
-
University of Rhode Island
-
Higher Education
-
700 & Above Employee
-
Provost Office - Graduate Research Analyst
-
Sep 2009 - Aug 2010
- Co-chaired task force for the University’s Academic Plan to evaluate strategic goals - Developed metrics to evaluate the success of the University’s Academic Plan - Assembled best practices presentations for the Provost and the Board of Governors - Provided confidential administrative and research support to the Office of the Provost - Focused writing on education trends and projections - Assisted with program report cards that were implemented University-wide - Analyzed statistical databases such as Integrated Postsecondary Education Data Systems (IPEDS) Show less
-
-
Education
-
University of Rhode Island
Master of Business Administration -
University of Rhode Island
Bachelor of Science -
Asia University (TW)