1

Director Third Party Risk Management Jobs in Orem, UT

Own and manage various actions and task queues that will result from risk management and mitigation activities * Perform quality control & audit checks over TPRM program and third party or business ...

The Director Bank Partnerships is a key member of Merrick Bank's Bank Origination team, serving as ... Familiarity with banking regulations third-party risk management guidelines.Demonstrated expertise ...

New

The DIRECTOR OF RISK MANAGEMENT will be part of an extraordinary team and be committed to making a difference in the lives of those in need. Position Details: * Full-Time, salaried exempt, Monday ...

The DIRECTOR OF RISK MANAGEMENT will be part of an extraordinary team and be committed to making a difference in the lives of those in need. Position Details: * Full-Time, salaried exempt, Monday ...

next page

Showing results 1-20

Director Third Party Risk Management information

See Orem, UT salary details

$46.9K

$124.5K

$226K

How much do director third party risk management jobs pay per year?

As of Aug 27, 2026, the average yearly pay for director third party risk management in Orem, UT is $124,480.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,700.00 and $145,600.00 per year, depending on experience, location, and employer.

What does a director of third party risk management do?

A Director of Third Party Risk Management is responsible for overseeing an organization's approach to identifying, assessing, and mitigating risks associated with its external partners, vendors, and suppliers. This role involves developing risk assessment frameworks, ensuring compliance with relevant regulations, and collaborating with internal teams to address any third-party issues that may affect the business. The director also leads the creation and execution of policies and procedures to manage third-party risks effectively, balancing operational needs with regulatory requirements.

What are some of the key challenges a director of third party risk management faces when implementing risk assessment frameworks across a large organization?

One of the main challenges is ensuring consistency and thoroughness in risk assessments across diverse business units and geographies, each with varying levels of vendor complexity and regulatory requirements. Directors often need to balance rigorous risk controls with the need for operational efficiency, which requires strong communication and influence skills to gain stakeholder buy-in. Additionally, keeping up with evolving third-party risks, such as cybersecurity threats and supply chain disruptions, demands continuous process improvement and cross-functional collaboration with IT, legal, and procurement teams.

What are the key skills and qualifications needed to thrive as a director of third party risk management, and why are they important?

To thrive as a Director of Third Party Risk Management, you typically need expertise in risk assessment, compliance, vendor management, and a relevant degree in business, finance, or a related field. Familiarity with risk management frameworks, regulatory requirements, and tools like GRC (Governance, Risk, and Compliance) platforms or vendor risk assessment software is essential. Exceptional leadership, strategic thinking, and negotiation skills help manage cross-functional teams and build strong relationships with vendors. These competencies are crucial to effectively mitigate third-party risks, ensure regulatory compliance, and protect the organization’s reputation and operations.

What is the difference between Director Third Party Risk Management vs Vendor Risk Manager?

AspectDirector Third Party Risk ManagementVendor Risk Manager
CredentialsTypically requires advanced degrees and certifications like CTPRP or CRISCOften requires certifications such as CTPRP, CRISC, or vendor-specific training
Work EnvironmentStrategic leadership, overseeing multiple teams and enterprise-wide risk policiesOperational focus, managing vendor assessments and risk mitigation activities
Industry UsageUsed in large organizations across finance, healthcare, and technology sectorsCommon in organizations with extensive vendor networks, especially in finance and IT

The main difference is that the Director Third Party Risk Management holds a strategic, leadership role overseeing enterprise-wide third-party risks, while the Vendor Risk Manager focuses on operational vendor assessments and risk mitigation. Both roles require similar certifications but differ in scope and level of responsibility.

What are the most commonly searched types of Third Party Risk Management jobs in Orem, UT?

The most popular types of Third Party Risk Management jobs in Orem, UT are:

What are popular job titles related to Director Third Party Risk Management jobs in Orem, UT?

For Director Third Party Risk Management jobs in Orem, UT, the most frequently searched job titles are:

What job categories do people searching Director Third Party Risk Management jobs in Orem, UT look for?

The top searched job categories for Director Third Party Risk Management jobs in Orem, UT are:

Infographic showing various Director Third Party Risk Management job openings in Orem, UT as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 17% Part Time, and 3% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $124,480 per year, or $59.8 per hour.

Director- Third Party Risk and Business Continuity

Mountain America Federal Credit Union

Sandy, UT • Hybrid

Full-time

Posted 28 days ago


Job description

Please reference the schedule and minimum qualifications listed below before applying.

If you need assistance with filling out our application form or during any phase of the application, interview, or employment process, please notify our Human Resources Team at 801-366-6947 option 1 or email macurecruiting@macu.com and every reasonable effort will be made to accommodate your needs in a timely manner.

Job SummaryThe Director of Third-Party Risk and Business Continuity is a key leader within Mountain America Credit Union's Enterprise and Operational Risk function, reporting to the Vice President of Enterprise and Operational Risk. The role is responsible for overseeing the day-to-day execution and continued maturity of the third-party risk management and operational resilience programs, including business continuity, crisis management, operational scenario analysis, and alignment with technology recovery capabilities and disaster recovery dependencies. As part of the second line of defense, the Director partners with business units, Legal, Procurement, Compliance, IT, Information Security, and other stakeholders to align program execution with strategic objectives, regulatory expectations, and enterprise risk standards.Job Description

LOCATION

Mountain America Center - Hybrid

9800 S Monroe St
Sandy, UT 84070

SCHEDULE

Full Time; this is a hybrid schedule with some weekly in office expectation, based on business need.

To be effective, an individual must be able to perform each job duty successfully.

Business Continuity and Operational Resilience
  • Lead the design, implementation, testing, and continued maturity of the enterprise business continuity and operational resilience program, including business impact analyses, risk assessments, operational scenario analysis, tabletop exercises, and crisis management simulations.
  • Partner with IT and Information Security to align business continuity planning with technology recovery capabilities, disaster recovery dependencies, and business response requirements.
  • Coordinate crisis response governance, escalation protocols, decision rights, leadership communications, situational risk reporting, lessons learned, and prioritized remediation for significant operational events.
  • Monitor emerging threats and trends, including cyber, technology, supply chain, regulatory, physical security, climate, and geopolitical events; maintain related program documentation, reporting, and remediation visibility for operational continuity risks.
Third-Party Risk and Contract Oversight
  • Direct the continued maturity of a scalable third-party risk management program aligned to the credit union's vendor ecosystem, operational complexity, internal governance standards, and regulatory expectations.
  • Oversee the third-party risk lifecycle, including due diligence, risk assessments, contract risk reviews, ongoing monitoring, issue escalation, remediation tracking, exit planning, and senior-level credible challenge of evidence-based risk conclusions.
  • Partner with business units, Vendor Relationship Owners, Subject Matter Experts, Legal, Procurement, Information Security, Compliance, and other stakeholders to identify, assess, mitigate, monitor, and document third-party risks, contract provisions, controls, and risk mitigation strategies.
  • Monitor third-party performance, control effectiveness, key risk indicators, critical vendor exposure, concentration risk, fourth-party risk, and emerging risk themes, escalating issues when risk exposure exceeds defined thresholds.
  • Lead TPRM responses for regulatory exams, internal audits, and independent reviews, including documentation, analysis, issue remediation, and management responses.
  • Drive the TPRM program maturity roadmap, including process improvements, automation, data quality, GRC optimization, regulatory alignment, and adoption of sound industry practices.
  • Provide executive, committee, and Board-level reporting and recommendations on third-party risk exposure, trends, issues, concentrations, emerging risks, program maturity, remediation priorities, and related governance documentation.

Education and Experience

  • Bachelor's degree in finance, risk management, business administration, economics, or related field required; advanced degree preferred.
  • Minimum of 8 years of experience in enterprise risk, operational risk, business continuity, third-party risk management, contract management, or related risk disciplines.
  • Minimum of 3 years of experience leading teams, business processes, or cross-functional initiatives with notable risk and complexity.
  • Experience developing or maturing risk, resilience, third-party, or contract management programs in a regulated financial institution preferred.
  • Understanding of ERM frameworks, operational resilience expectations, third-party risk lifecycle practices, contract risk considerations, and regulatory expectations for financial institutions.
  • Understanding of SOC 2, SSAE-18, financial statements, business impact analysis, recovery planning, operational scenario analysis, and crisis response practices.

Certifications

  • Preferred certifications: CTPRP, ORCE, CRCMP, or similar risk-related credentials.

Skills

  • Strategic thinking with strong analytical, problem-solving, and risk data interpretation capabilities, including the ability to aggregate, interpret, and visualize complex risk information.
  • Demonstrated ability to apply credible challenge, respectfully question assumptions, escalate risks, and influence outcomes using facts, regulatory knowledge, and clear communication.
  • Excellent written and verbal communication skills, with the ability to synthesize risk information, prepare executive-ready materials, and collaborate effectively with cross-functional teams, including Compliance, Internal Audit, and senior leadership.
  • Familiarity with GRC platforms and risk analytics tools, such as Tableau, Power BI, or similar.

Leadership and Organization Development

  • Demonstrates ownership and accountability in delivering high-quality risk governance and reporting outcomes.
  • Fosters a culture of collaboration, transparency, and continuous improvement within the Risk function.
  • Provides mentorship and guidance to junior team members and peers, supporting professional development and knowledge sharing.
  • Aligns team activities and deliverables with operational risk strategy and organizational goals.
  • Effectively manages change and adapts to evolving regulatory, strategic, and operational priorities.
  • Builds strong cross-functional relationships to influence outcomes and promote a unified risk culture.
  • Contributes to succession planning by developing documentation, tools, and processes that support long-term team capability and resilience.

Managerial Responsibility

  • Has supervisory/managerial responsibilities that are direct or through work leaders or assistants, typically with a subordinate group of 2 to 15 employees. Estimates personnel needs and assigns work to meet these needs. Supervises, coordinates and reviews the work of assigned staff. Recommends candidates for employment, conducts performance evaluations and salary reviews for assigned staff, and applies company policy.

Mountain America Credit Union is an EEO/AA/ADA/Veterans employer.