1

Director Third Party Risk Management Jobs in Colorado

Job Family Risk Management - General About Us At Transamerica, hard work, innovative thinking, and ... Escalate to appropriate third party risk management as appropriate. * Ensure required risk ...

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Highly organized, self-directed, and comfortable managing multiple workstreams simultaneously in a ...

The Director of Risk Management provides strategic leadership and operational oversight for risk ... Collaborate with project teams, legal counsel, and third-party administrators (TPAs) to manage ...

Director, Risk Management

Denver, CO · On-site

$169.48 - $203.38/hr

The Director of Risk Management provides strategic leadership and operational oversight for risk ... Collaborate with project teams, legal counsel, and third-party administrators (TPAs) to manage ...

Oversee vendor/third-party risk within the cyber risk portfolio to ensure supply-chain risk is ... Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$100K - $129K/yr

This includes cyber risk management, policy and standards governance, third-party risk management ... No direct supervisory responsibility. Coordinates vendor, business-owner, and control-owner actions ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$99K - $128K/yr

This includes cyber risk management, policy and standards governance, third-party risk management ... No direct supervisory responsibility. Coordinates vendor, business-owner, and control-owner actions ...

next page

Showing results 1-20

Director Third Party Risk Management information

See Colorado salary details

$56.8K

$150.6K

$273.4K

How much do director third party risk management jobs pay per year?

As of Aug 10, 2026, the average yearly pay for director third party risk management in Colorado is $150,561.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,900.00 and $176,100.00 per year, depending on experience, location, and employer.

What are some of the key challenges a director of third party risk management faces when implementing risk assessment frameworks across a large organization?

One of the main challenges is ensuring consistency and thoroughness in risk assessments across diverse business units and geographies, each with varying levels of vendor complexity and regulatory requirements. Directors often need to balance rigorous risk controls with the need for operational efficiency, which requires strong communication and influence skills to gain stakeholder buy-in. Additionally, keeping up with evolving third-party risks, such as cybersecurity threats and supply chain disruptions, demands continuous process improvement and cross-functional collaboration with IT, legal, and procurement teams.

What does a director of third party risk management do?

A Director of Third Party Risk Management is responsible for overseeing an organization's approach to identifying, assessing, and mitigating risks associated with its external partners, vendors, and suppliers. This role involves developing risk assessment frameworks, ensuring compliance with relevant regulations, and collaborating with internal teams to address any third-party issues that may affect the business. The director also leads the creation and execution of policies and procedures to manage third-party risks effectively, balancing operational needs with regulatory requirements.

What is the difference between Director Third Party Risk Management vs Vendor Risk Manager?

AspectDirector Third Party Risk ManagementVendor Risk Manager
CredentialsTypically requires advanced degrees and certifications like CTPRP or CRISCOften requires certifications such as CTPRP, CRISC, or vendor-specific training
Work EnvironmentStrategic leadership, overseeing multiple teams and enterprise-wide risk policiesOperational focus, managing vendor assessments and risk mitigation activities
Industry UsageUsed in large organizations across finance, healthcare, and technology sectorsCommon in organizations with extensive vendor networks, especially in finance and IT

The main difference is that the Director Third Party Risk Management holds a strategic, leadership role overseeing enterprise-wide third-party risks, while the Vendor Risk Manager focuses on operational vendor assessments and risk mitigation. Both roles require similar certifications but differ in scope and level of responsibility.

What are the key skills and qualifications needed to thrive as a director of third party risk management, and why are they important?

To thrive as a Director of Third Party Risk Management, you typically need expertise in risk assessment, compliance, vendor management, and a relevant degree in business, finance, or a related field. Familiarity with risk management frameworks, regulatory requirements, and tools like GRC (Governance, Risk, and Compliance) platforms or vendor risk assessment software is essential. Exceptional leadership, strategic thinking, and negotiation skills help manage cross-functional teams and build strong relationships with vendors. These competencies are crucial to effectively mitigate third-party risks, ensure regulatory compliance, and protect the organization’s reputation and operations.
What are the most commonly searched types of Third Party Risk Management jobs in Colorado? The most popular types of Third Party Risk Management jobs in Colorado are:
What are popular job titles related to Director Third Party Risk Management jobs in Colorado? For Director Third Party Risk Management jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Director Third Party Risk Management jobs in Colorado look for? The top searched job categories for Director Third Party Risk Management jobs in Colorado are:
What cities in Colorado are hiring for Director Third Party Risk Management jobs? Cities in Colorado with the most Director Third Party Risk Management job openings:
Infographic showing various Director Third Party Risk Management job openings in Colorado as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $150,561 per year, or $72.4 per hour.

Sr. Manager, Third Party Risk Management

Asurion

Sterling, CO • On-site

Full-time

Re-posted 11 days ago


Asurion rating

7.2

Company rating: 7.2 out of 10

Based on 84 frontline employees who took The Breakroom Quiz

135th of 223 rated it services


Job description

Position Overview

The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third-party risk lifecycle-intake, inherent-risk tiering, due diligence, contract controls, continuous monitoring, reassessment, and secure offboarding-protecting Asurion and its carrier and partner ecosystem from risks introduced by vendors, service providers, and technology suppliers. The leader partners closely with Procurement, Legal, Privacy, business portfolio owners, and security control owners to translate fragmented vendor information into clear, defensible risk decisions. This is both a program-building and people-leadership role, maturing the vendor risk function in alignment with NIST CSF 2.0 and strengthening supply chain risk outcomes while embedding modern practices for emerging risks such as third-party AI tooling, SaaS sprawl, and vendor concentration.

Key Responsibilities
  • Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program aligned to NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and regulatory obligations.
  • Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology; secure governance approval and drive consistent adoption across the enterprise.
  • Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership and apply them to vendor risk decisions.
  • Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding in partnership with Procurement and Legal.
  • Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination, treatment/acceptance, contracting, continuous monitoring, reassessment, and offboarding.
  • Operationalize inherent-risk tiering to scope assessment depth and cadence based on data sensitivity, access, criticality, and business impact.
  • Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments and evidence including SOC 2 Type II, ISO 27001, PCI AOC, and penetration test results.
  • Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk across the supplier portfolio.
  • Establish and lead risk reviews for third-party AI/GenAI tooling with security and privacy teams; address model and data-handling risks and shadow AI.
  • Translate findings into concise, business-relevant risk narratives and actionable remediation plans with owners and timelines.
  • Operate continuous monitoring leveraging external risk ratings, periodic attestations, threat/breach intelligence, and event-driven triggers.
  • Coordinate third-party incident response with SOC/IR; assess impact, drive containment, and track remediation to closure.
  • Manage the third-party risk register and findings inventory; escalate aging or accepted risks through governance.
  • Maintain visibility into critical vendor resilience and BC/DR posture for high-impact suppliers.
  • Partner with Legal and Procurement to define and negotiate security, privacy, and resilience terms (control requirements, right-to-audit, breach notification SLAs, data protection, subprocessor controls).
  • Develop a standardized library of contractual security requirements scaled to vendor risk tier.
  • Define and report outcome-driven metrics and KRIs (e.g., residual risk trends, assessment cycle time/coverage, time-to-remediate, monitoring coverage, exception aging); deliver executive-ready reporting to governance forums.
  • Serve as the primary point of contact for internal/external audits, regulatory exams, and carrier-partner due diligence.
  • Build, lead, and develop a high-performing team of vendor risk analysts; set objectives, coach performance, and scale capability through playbooks, training, and quality reviews.
  • Drive operational efficiency via process automation and analyst-assistive tooling to focus effort on judgment-intensive decisions.
Education and Experience
  • 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party/vendor risk management.
  • 2+ years of direct people leadership managing analysts or a risk team.
  • Demonstrated experience designing or maturing a TPRM program lifecycle end to end.
  • Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and assessment standards such as SIG/Shared Assessments.
  • Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports) and translating them into risk decisions.
  • Hands-on experience with TPRM/GRC platforms and continuous monitoring/security-rating tools (e.g., ProcessUnity, OneTrust, Prevalent/Mitratech, Whistic, BitSight, SecurityScorecard, or comparable).
  • Experience partnering with Procurement and Legal on vendor contracting and security/privacy terms.
  • Excellent written and verbal communication, including executive briefing and defensible risk narratives.
  • Bachelor's degree in a related field or equivalent professional experience.
  • Preferred: certifications such as CTPRP, CISSP, CISA, CRISC, or CISM; experience in regulated consumer or financial environments (e.g., GLBA, PCI DSS, state privacy laws); experience with AI/GenAI risk assessment; familiarity with three lines of defense; experience with automation or AI-assisted workflows in GRC.
Knowledge, Skills, and Abilities
  • Sound risk judgment balancing rigor with business enablement and speed-to-value.
  • Ability to influence without authority across Procurement, Legal, Privacy, Security, and business stakeholders.
  • Program design, policy/standard development, and governance execution for TPRM.
  • Expertise in vendor risk tiering, due diligence, continuous monitoring, issue management, and secure offboarding.
  • Strong analytical skills to assess concentration, systemic risk, and fourth-party dependencies.
  • Advanced communication skills; distills complex third-party risk into actionable executive decisions.
  • Team leadership, talent development, and operational scaling through playbooks, training, and QA.
  • Proficiency with metrics/KRIs, dashboards, and executive reporting.
  • Negotiation of contractual security/privacy/resilience terms and control requirements.
Travel Requirements

N/A

Physical Demands
  • Stationary Position: Frequently
  • Vision: 20/20 corrected vision
  • Hearing: Receive detailed information if spoken to

What Asurion employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom