1

Director Third Party Risk Management Jobs in Riverside, CA

VP, Information Security and Compliance

Irvine, CA Β· On-site

$135K - $181K/yr

Serve as the primary security advisor to the Board of Directors, Executive Leadership Team and ... Third-Party & Vendor Risk: Establish and enforce third-party risk management (TPRM) programs to ...

VP, Information Security and Compliance

Irvine, CA Β· On-site

$135K - $181K/yr

Serve as the primary security advisor to the Board of Directors, Executive Leadership Team and ... Third-Party & Vendor Risk: Establish and enforce third-party risk management (TPRM) programs to ...

Director of Safety

Brea, CA Β· On-site

$160K - $180K/yr

Reporting directly to the Risk Manager, this role is responsible for directing the Safety ... Lead OSHA, Cal/OSHA, DIR, client, General Contractor, and third-party safety inspections. * Develop ...

Reporting directly to the Risk Manager , this role is responsible for directing the Safety ... Lead OSHA, Cal/OSHA, DIR, client, General Contractor, and third-party safety inspections. * Develop ...

Reporting directly to the Risk Manager, this role is responsible for directing the Safety ... Lead OSHA, Cal/OSHA, DIR, client, General Contractor, and third-party safety inspections. * Develop ...

Showing results 21-40

Director Third Party Risk Management information

See Riverside, CA salary details

$56.3K

$149.4K

$271.2K

How much do director third party risk management jobs pay per year?

As of Sep 15, 2026, the average yearly pay for director third party risk management in Riverside, CA is $149,380.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,100.00 and $174,700.00 per year, depending on experience, location, and employer.

What does a director of third party risk management do?

A Director of Third Party Risk Management is responsible for overseeing an organization's approach to identifying, assessing, and mitigating risks associated with its external partners, vendors, and suppliers. This role involves developing risk assessment frameworks, ensuring compliance with relevant regulations, and collaborating with internal teams to address any third-party issues that may affect the business. The director also leads the creation and execution of policies and procedures to manage third-party risks effectively, balancing operational needs with regulatory requirements.

What are some of the key challenges a director of third party risk management faces when implementing risk assessment frameworks across a large organization?

One of the main challenges is ensuring consistency and thoroughness in risk assessments across diverse business units and geographies, each with varying levels of vendor complexity and regulatory requirements. Directors often need to balance rigorous risk controls with the need for operational efficiency, which requires strong communication and influence skills to gain stakeholder buy-in. Additionally, keeping up with evolving third-party risks, such as cybersecurity threats and supply chain disruptions, demands continuous process improvement and cross-functional collaboration with IT, legal, and procurement teams.

What are the key skills and qualifications needed to thrive as a director of third party risk management, and why are they important?

To thrive as a Director of Third Party Risk Management, you typically need expertise in risk assessment, compliance, vendor management, and a relevant degree in business, finance, or a related field. Familiarity with risk management frameworks, regulatory requirements, and tools like GRC (Governance, Risk, and Compliance) platforms or vendor risk assessment software is essential. Exceptional leadership, strategic thinking, and negotiation skills help manage cross-functional teams and build strong relationships with vendors. These competencies are crucial to effectively mitigate third-party risks, ensure regulatory compliance, and protect the organization’s reputation and operations.

What is the difference between Director Third Party Risk Management vs Vendor Risk Manager?

AspectDirector Third Party Risk ManagementVendor Risk Manager
CredentialsTypically requires advanced degrees and certifications like CTPRP or CRISCOften requires certifications such as CTPRP, CRISC, or vendor-specific training
Work EnvironmentStrategic leadership, overseeing multiple teams and enterprise-wide risk policiesOperational focus, managing vendor assessments and risk mitigation activities
Industry UsageUsed in large organizations across finance, healthcare, and technology sectorsCommon in organizations with extensive vendor networks, especially in finance and IT

The main difference is that the Director Third Party Risk Management holds a strategic, leadership role overseeing enterprise-wide third-party risks, while the Vendor Risk Manager focuses on operational vendor assessments and risk mitigation. Both roles require similar certifications but differ in scope and level of responsibility.

What job categories do people searching Director Third Party Risk Management jobs in Riverside, CA look for?

The top searched job categories for Director Third Party Risk Management jobs in Riverside, CA are:

What cities near Riverside, CA are hiring for Director Third Party Risk Management jobs?

Cities near Riverside, CA with the most Director Third Party Risk Management job openings:

Infographic showing various Director Third Party Risk Management job openings in Riverside, CA as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 15% Part Time, and 3% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $149,380 per year, or $71.8 per hour.

VP, Information Security and Compliance

Irvine, CA β€’ On-site

Veritone
Software DevelopmentΒ β€’Β 501 - 1,000 employees

$135K - $181K/yr

Full-time

Medical, Life, Retirement, PTO

Re-posted 14 days ago


Job description

POSITION SUMMARYThe VP, Information Security & Compliance, will serve as the Company's Chief Information Security Officer and executive champion for our global enterprise security and compliance programs. Reporting directly to the Chief Legal Officer, this role will design, execute and mature an overarching security strategy that protects customer data, intellectual property and infrastructure across all of Veritone's business units, including, but not limited to commercial SaaS and high stringency public sector (federal, state and defense) environments.
The role requires a rare blend of strategic vision, commercial SaaS agility, public sector governance (e.g., FedRAMP, NIST, DoD), and public company risk management capabilities (e.g., SOX, SEC disclosure requirements).WHAT YOU'LL DO

Strategic Leadership & Governance

  • Security Vision & Roadmap: Architect and execute a multi-year, enterprise wide information security and compliance strategy aligned with commercial growth targets and public sector expansion goals.

  • Executive Presence: Serve as the primary security advisor to the Board of Directors, Executive Leadership Team and entire organization. Clearly translate complex security risks into actionable business terms.

  • Team Leadership: Build, mentor and lead a high performing global security team and compliance organization across security operations, engineering, risk management and regulatory compliance

  • Security Culture: Foster a company-wide security first culture through continuous training, awareness programs and cross-functional advocacy

Compliance

  • FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required to achieve and maintain FedRAMP (moderate/high), StateRAMP, DoD/CMMC, and CJIS authorizations in cloud environments (AWS GovCloud/Azure Government)

  • Commercial Frameworks: Oversee compliance and auditing for SOC 2 Type II, ISO 27001, PCI-DSS and global privacy standards (GDPR, CCPA/CPRA)

  • Public Company Compliance: Partner with legal, finance and internal audit teams to maintain robust IT general controls (ITGCs) for SOX compliance and support SEC cybersecurity disclosure requirements

Security Operations, Architecture & Incident Response

  • Cloud & Product Architecture: Partner with Enterprise Architecture, Infrastructure, and Engineering teams to embed security controls into multi-tenant SaaS platforms, CI/CD pipelines, and cloud environments.

  • Threat & Vulnerability Management: Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence operations to proactively address emerging vector threats.

  • Incident Management: Oversee breach investigations, threat response protocols, and tabletop exercises, ensuring rapid containment, notification, and mitigation when incidents arise.

Enterprise Risk Management & Operations

  • Third-Party & Vendor Risk: Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ecosystems, software supply chains, and external partners.

  • M&A Due Diligence: Lead security and compliance due diligence for mergers and acquisitions, driving post-acquisition security integration strategies.

  • Business Continuity & Resilience: Construct policies and operational frameworks for Business Continuity Planning (BCP), Disaster Recovery (DR), loss prevention, and fraud prevention.

WHAT YOU'LL NEED
  • Education: Bachelor of Science degree in Computer Science, Cybersecurity, Computer Engineering, Information Technology, or equivalent technical discipline.

  • Executive Experience: 10+ years of progressive leadership experience in information security, cloud architecture, and compliance within a global, publicly traded cloud/SaaS technology company.

  • Proven FedRAMP Track Record: Hands-on experience leading a cloud solution through the FedRAMP authorization lifecycle (PMO/JAB or Agency route) and continuous monitoring in AWS and/or Azure cloud environments.

  • Dual-Domain Capability: Equal fluency in scaling commercial enterprise SaaS security and navigating rigid public sector regulatory landscapes (NIST 800-53, NIST 800-171, CMMC, CJIS, FISMA).

  • Executive Presence & Communication: Exceptional ability to communicate security concepts to technical engineers, enterprise buyers, regulatory auditors, and Board members alike.

  • Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing agreements (DPAs), and risk terms with enterprise clients and vendors.

BONUS POINTS IF YOU HAVE...

  • Advanced Degree: Master's degree (M.S. in Cybersecurity/Computer Science or MBA).

  • Industry Certifications: Active professional certifications such as CISSP, CISM, CRISC, CISA, or CCSP.

  • Security Clearance: Active or clearable U.S. Government Security Clearance (DoD Secret or Top Secret preferred).

  • AI/ML Security: Knowledge of security, privacy, and governance frameworks surrounding Artificial Intelligence and Machine Learning workloads.

DISCLOSURE

Our company provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics.

(Colorado & California Only*): The Annual salary listed for the position is a range of $200,000-$250,000. This base pay is for illustrative purposes only and will be determined based on skills and experience comparable to the job requirements. This position may be eligible for additional compensation and benefits including but not limited to: incentive compensation; health benefits; retirement benefits; life insurance; paid time off; parental leave and benefits; and other employee perks and benefits.

*Note: Disclosure as required by sb19-085 (8-5-20) of the minimum salary compensation for this role when being hired in Colorado & California.