1

Director Third Party Risk Management Jobs in California

Preference will be given to applicants with demonstrated experience in third party or vendor risk management, and to applicants with direct supply chain, procurement, or subcontracts experience.

... into third-party engagements. * Prepare risk assessment reports to inform risk treatment decisions. * Track and monitor remediation and risk management activities. * Maintain a current and ...

... into third-party engagements. * Prepare risk assessment reports to inform risk treatment decisions. * Track and monitor remediation and risk management activities. * Maintain a current and ...

Partnerships Manager

San Francisco, CA · On-site

$97K - $97K/yr

This hybrid role combines strategic partnership/network expansion with rigorous vendor management and third-party risk governance. In this position, you will be responsible for sourcing, building ...

Partnerships Manager

San Francisco, CA · Hybrid

$97K - $97K/yr

This hybrid role combines strategic partnership/network expansion with rigorous vendor management and third-party risk governance. In this position, you will be responsible for sourcing, building ...

## Director, Risk ManagementApplyremote type: In-Officelocations: San Diego CA Renewable Group: Dallas ... Collaborate with project teams, legal counsel, and third-party administrators (TPAs) to manage ...

The Director of Risk Management provides strategic leadership and operational oversight for risk ... Collaborate with project teams, legal counsel, and third-party administrators (TPAs) to manage ...

Experience: 1-4 years in enterprise risk, third-party risk, GRC, information security, or a related ... Strong analytical, organizational, stakeholder-management, and written and verbal communication ...

The Director of Risk Management provides strategic leadership and operational oversight for risk ... Collaborate with project teams, legal counsel, and third-party administrators (TPAs) to manage ...

Showing results 21-40

Director Third Party Risk Management information

See California salary details

$53.3K

$141.3K

$256.6K

How much do director third party risk management jobs pay per year?

As of Sep 8, 2026, the average yearly pay for director third party risk management in California is $141,310.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,100.00 and $165,300.00 per year, depending on experience, location, and employer.

What does a director of third party risk management do?

A Director of Third Party Risk Management is responsible for overseeing an organization's approach to identifying, assessing, and mitigating risks associated with its external partners, vendors, and suppliers. This role involves developing risk assessment frameworks, ensuring compliance with relevant regulations, and collaborating with internal teams to address any third-party issues that may affect the business. The director also leads the creation and execution of policies and procedures to manage third-party risks effectively, balancing operational needs with regulatory requirements.

What are some of the key challenges a director of third party risk management faces when implementing risk assessment frameworks across a large organization?

One of the main challenges is ensuring consistency and thoroughness in risk assessments across diverse business units and geographies, each with varying levels of vendor complexity and regulatory requirements. Directors often need to balance rigorous risk controls with the need for operational efficiency, which requires strong communication and influence skills to gain stakeholder buy-in. Additionally, keeping up with evolving third-party risks, such as cybersecurity threats and supply chain disruptions, demands continuous process improvement and cross-functional collaboration with IT, legal, and procurement teams.

What are the key skills and qualifications needed to thrive as a director of third party risk management, and why are they important?

To thrive as a Director of Third Party Risk Management, you typically need expertise in risk assessment, compliance, vendor management, and a relevant degree in business, finance, or a related field. Familiarity with risk management frameworks, regulatory requirements, and tools like GRC (Governance, Risk, and Compliance) platforms or vendor risk assessment software is essential. Exceptional leadership, strategic thinking, and negotiation skills help manage cross-functional teams and build strong relationships with vendors. These competencies are crucial to effectively mitigate third-party risks, ensure regulatory compliance, and protect the organization’s reputation and operations.

What is the difference between Director Third Party Risk Management vs Vendor Risk Manager?

AspectDirector Third Party Risk ManagementVendor Risk Manager
CredentialsTypically requires advanced degrees and certifications like CTPRP or CRISCOften requires certifications such as CTPRP, CRISC, or vendor-specific training
Work EnvironmentStrategic leadership, overseeing multiple teams and enterprise-wide risk policiesOperational focus, managing vendor assessments and risk mitigation activities
Industry UsageUsed in large organizations across finance, healthcare, and technology sectorsCommon in organizations with extensive vendor networks, especially in finance and IT

The main difference is that the Director Third Party Risk Management holds a strategic, leadership role overseeing enterprise-wide third-party risks, while the Vendor Risk Manager focuses on operational vendor assessments and risk mitigation. Both roles require similar certifications but differ in scope and level of responsibility.

What are the most commonly searched types of Third Party Risk Management jobs in California?

The most popular types of Third Party Risk Management jobs in California are:

What are popular job titles related to Director Third Party Risk Management jobs in California?

For Director Third Party Risk Management jobs in California, the most frequently searched job titles are:

What job categories do people searching Director Third Party Risk Management jobs in California look for?

The top searched job categories for Director Third Party Risk Management jobs in California are:

What cities in California are hiring for Director Third Party Risk Management jobs?

Cities in California with the most Director Third Party Risk Management job openings:

Infographic showing various Director Third Party Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $141,310 per year, or $67.9 per hour.

Supply Chain Risk Manager

General Atomics

Poway, CA • On-site

Full-time

Re-posted 4 days ago


General Atomics rating

9.0

Company rating: 9.0 out of 10

Based on 39 frontline employees who took The Breakroom Quiz

10th of 72 rated aerospace companies


Job description

Job Summary
General Atomics Aeronautical Systems, Inc. (GA-ASI), an affiliate of General Atomics, is a world leader in proven, reliable remotely piloted aircraft and tactical reconnaissance radars, as well as advanced high-resolution surveillance systems.
This position is responsible for assessing and mitigating supplier cybersecurity and supply chain risks that may impact program execution, compliance, and mission assurance. This role serves as a liaison between the supply chain organization, program management, engineering, cybersecurity, and external suppliers to address third party cyber risk, supply chain risk, operational resilience, and regulatory compliance concerns.
The position continually reviews supplier and product line risk posture, assesses emerging issues, and develops mitigation strategies to support production, quality, schedule, and customer requirements. Decisions made in this role directly influence program outcomes, supplier performance, and the organization's overall compliance posture.
This position sits at the intersection of cybersecurity compliance and supply chain management. Applications are welcomed from candidates whose background is primarily in third party risk management, cybersecurity compliance, information assurance, or governance and risk, as well as from candidates with a supply chain background. Preference will be given to applicants who bring both.
DUTIES AND RESPONSIBILITIES:
Third Party and Supplier Cybersecurity Risk
  • Administer and support the third party risk management program by collecting, reviewing, and assessing supplier cybersecurity compliance information, including SOC 2 reports, Supplier Performance Risk System (SPRS) scores, and CMMC certification and compliance artifacts.
  • Evaluate supplier cybersecurity posture against applicable DFARS flow down requirements, identify compliance gaps, and track supplier remediation to closure.
  • Interface directly with suppliers to communicate cybersecurity risk findings, understand root causes, and coordinate remediation activities, including support to suppliers working to close cybersecurity gaps and strengthen compliance with contractual and regulatory requirements.
  • Work closely with cybersecurity, compliance, and legal teams to ensure supplier risk is accurately documented, monitored, escalated, and reflected in supplier onboarding, qualification, and ongoing performance review.
  • Develop and maintain processes that align supply chain risk management practices with NIST SP 800-161 and applicable Department of Defense (DoD) cybersecurity requirements, integrating cybersecurity supply chain risk management into existing supply chain and governance workflows.
  • Monitor changes to defense industrial base cybersecurity regulations, including CMMC implementation milestones, and update supplier assessment criteria, processes, and flow down practices accordingly.
  • Ensure sensitive and proprietary information, including Controlled Unclassified Information (CUI), is properly identified and handled in accordance with contractual, regulatory, and company requirements.
Supply Chain Risk and Program Support
  • Conduct structured supply chain risk assessments for assigned product lines, evaluating supplier criticality, single points of failure, operational resilience, and cybersecurity posture.
  • Develop and implement mitigation strategies that address identified risks, and support program and supply chain leadership in risk informed decision making.
  • Research, identify, and validate supply chain risk signals using internal data sources, supplier information, and external intelligence tools, and translate those signals into actionable recommendations.
  • Serve as the primary point of coordination between supply chain organizations and program offices, ensuring alignment on risk priorities, mitigation plans, and program requirements.
  • Interpret and administer policies, processes, and procedures that impact supply chain risk management activities.
  • Prepare and deliver progress reports, risk assessments, briefings, and presentations to internal stakeholders and customers, communicating risk status, trends, and mitigation strategies to both technical and non-technical audiences.
General
  • Maintain the strict confidentiality of sensitive information.
  • Responsible for observing all laws, regulations, and other applicable obligations wherever and whenever business is conducted on behalf of the Company.
  • Responsible for ensuring work is accomplished in a safe manner in accordance with established operating procedures and practices.
  • Other duties as assigned or required.

We recognize and appreciate the value and contributions of individuals with diverse backgrounds and experiences and welcome all qualified individuals to apply.
Job Qualifications
  • Typically requires a Bachelor's degree in business, supply chain, cybersecurity, engineering, or a related discipline and eleven or more years of progressively complex experience in supply chain, risk management, cybersecurity, or defense related program support, with at least five of those years in supply chain. Equivalent experience may be substituted in lieu of education.
  • Must demonstrate a working knowledge of cybersecurity requirements within the defense industrial base, including DFARS clauses 252.204-7012, 252.204-7020, and 252.204-7021, NIST SP 800-171, and the Cybersecurity Maturity Model Certification (CMMC) framework.
  • CISSP, CompTIA Security+, CISA, or CMMC certification, such as Certified Professional (CCP) or Certified Assessor (CCA), is highly desirable.
  • Preference will be given to applicants with demonstrated experience in third party or vendor risk management, and to applicants with direct supply chain, procurement, or subcontracts experience.
  • Preference will be given to applicants familiar with supply chain risk management principles and NIST SP 800-161.
  • Must possess the ability to identify and assess risk, analyze and interpret data, and develop practical mitigation strategies for complex and non-routine issues. Strong analytical, communication, documentation, presentation, and interpersonal skills are required.
  • Must demonstrate the ability to work independently, lead cross functional efforts, and influence stakeholders across organizational boundaries. Experience interfacing directly with suppliers and supporting remediation activities is preferred.
  • Familiarity with enterprise and risk management tools such as SAP, Optro (formerly AuditBoard), Altana, Bitsight, Resilinc, and Microsoft Office applications is desired.
  • Applicant must be a U.S. citizen and must either have, or be eligible to obtain, a Secret clearance.
  • Must be able to work extended hours and travel as required. Travel is expected to be less than 25 percent.

What General Atomics employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Atomics logo

About General Atomics

Sourced by ZipRecruiter

General Atomics (GA), and its affiliated companies, is one of the world's leading resources for high-technology systems development ranging from the nuclear fuel cycle to remotely piloted aircraft, airborne sensors, and advanced electric, electronic, wireless and laser technologies.

Industry

Space research administration

Company size

10,000+ Employees

Headquarters location

San Diego, CA, US

Year founded

1955