1

Internship Third Party Risk Management Jobs in Boston, MA

Senior Security Engineer

Framingham, MA ยท Hybrid

$85K - $115K/yr

Working closely with IT leadership and HealthDrive's Managed Security Service Provider (MSSP), the engineer also manages the third-party risk process from end to end. This is primarily a technical ...

Security Engineer (Boston HQ)

Boston, MA ยท On-site

$80K - $110K/yr

This is a high impact role with broad exposure: where you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while ...

Security Engineer (Boston HQ)

Boston, MA ยท On-site

$80K - $110K/yr

This is a high impact role with broad exposure: where you will work across core domains including identity and access management (IAM), third-party risk, and incident detection and response while ...

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...

Showing results 21-40

Internship Third Party Risk Management information

What is the difference between Internship Third Party Risk Management vs Third Party Risk Analyst?

AspectInternship Third Party Risk ManagementThird Party Risk Analyst
CredentialsTypically pursuing or recent graduate, no formal certification requiredBachelor's degree often required; certifications like CTPRP beneficial
Work EnvironmentInternship setting, supervised, entry-level tasksFull-time professional role, analytical and risk assessment tasks
Employer & Industry UsageInternship programs in finance, banking, or corporate sectorsFinancial institutions, corporations, and consulting firms

Internship Third Party Risk Management is an entry-level, supervised role for students or recent graduates gaining exposure to third-party risk processes. In contrast, a Third Party Risk Analyst is a full-time professional responsible for analyzing and managing third-party risks, often requiring relevant education and certifications. Both roles are essential in risk management but differ in experience level and responsibilities.

What is an internship in third party risk management?

An internship in Third Party Risk Management involves assisting organizations in identifying, assessing, and mitigating risks associated with their external vendors or partners. Interns typically support tasks such as conducting due diligence, reviewing vendor contracts, monitoring compliance, and helping to develop risk assessment reports. This position provides hands-on experience in risk analysis, compliance procedures, and understanding regulatory requirements related to third-party relationships. It's an excellent opportunity for students interested in risk management, compliance, or supply chain management to gain practical skills and industry knowledge.

What does an internship in third party risk management involve?

As an intern in Third Party Risk Management, you can expect to support the team in assessing, monitoring, and mitigating risks related to external vendors and partners. Typical tasks may include conducting due diligence reviews, assisting with risk assessments, updating databases, and helping prepare reports for senior management. You may also collaborate closely with procurement, compliance, and information security teams to ensure that third-party relationships align with company policies and regulatory requirements. This hands-on experience is valuable for understanding risk management processes and building cross-functional communication skills.

What are the key skills and qualifications needed for an internship in third party risk management?

To thrive in an Internship Third Party Risk Management role, you need a background in finance, business, or risk management, with strong analytical and research skills. Familiarity with risk assessment tools, vendor management systems, and Microsoft Excel is often required. Attention to detail, effective communication, and problem-solving abilities are important soft skills that set candidates apart. These competencies are crucial for accurately identifying and mitigating risks associated with third-party vendors, ensuring organizational compliance and security.
What are popular job titles related to Internship Third Party Risk Management jobs in Boston, MA? For Internship Third Party Risk Management jobs in Boston, MA, the most frequently searched job titles are:
What job categories do people searching Internship Third Party Risk Management jobs in Boston, MA look for? The top searched job categories for Internship Third Party Risk Management jobs in Boston, MA are:
What cities near Boston, MA are hiring for Internship Third Party Risk Management jobs? Cities near Boston, MA with the most Internship Third Party Risk Management job openings:

Technology Risk and Governance

Arrowstreet Capital

Boston, MA โ€ข On-site

$110K - $315K/yr

Full-time

Re-posted 26 days ago


Job description

Job Overview

The position reports to the Chief Information Security Officer and leads the enterprise-wide technology risk and governance program. This role establishes the risk framework, policies, and governance needed to identify, assess, and mitigate risk across IT services, platforms, and third parties.

Partnering with senior leadership across Technology, Cyber Security, Compliance, Legal, and business, the role translates complex technical and control issues into clear business risk narratives (operational, regulatory, reputational, and financial) and drives risk-based prioritization of remediation.

The position owns the technology risk policy suite and associated standards and oversees the technological aspects of the third-party risk program, including vendor onboarding due diligence and ongoing monitoring in partnership with Compliance and procurement stakeholders.

This role is a key contributor to enterprise risk management, partnering with the Chief Compliance Officer and risk owners to ensure technology risks are identified, documented, reported, and addressed through effective controls, risk acceptance, and continuous improvement. It also evaluates and implements tools and reporting to increase risk visibility and strengthen governance.


Responsibilities

  • Own the enterprise technology risk framework and governance model, aligned to the organization's enterprise risk framework.

  • Provide advisory support for material technology decisions (new systems, products, vendors, and significant changes), translating technical and control issues into business impact.

  • Establish clear governance and reporting for senior management and committees on material IT, cyber, third-party, and emerging technology risks, including key risk indicators and metrics.

  • Design and continuously improve technology risk assessment and control evaluation processes, including remediation tracking and governance for risk acceptance, waivers, and exceptions.

  • Lead and mature AI risk governance in partnership with IT, Security, Compliance, and the business.

  • Support enterprise data governance initiatives (classification, retention, and handling) in collaboration with Technology and business stakeholders.

  • Own the technology risk policy suite and standards, ensuring they are implemented, reviewed regularly, and supported through training and awareness.

  • Oversee technology aspects of third-party risk, including onboarding due diligence, review of assurance (e.g., SOC reports), remediation tracking, and ongoing monitoring in partnership with Compliance and procurement stakeholders.

  • Partner with Cyber Security to ensure threat, vulnerability, patch, and incident risk governance aligns to the current threat landscape and control expectations.

  • Drive operational resilience for technology services, including business continuity planning, crisis/incident governance, root-cause analysis, and lessons learned.

  • Support client, regulator, and internal audit engagements related to technology risk, including responses to inquiries and evidence of control design and effectiveness.

Qualifications

  • Experience leading technology risk, IT risk, cyber/operational risk, or technology governance in a regulated environment.

  • Demonstrated ability to design and implement risk frameworks and governance processes, including assessment, prioritization, remediation tracking, and risk acceptance.

  • Broad technical knowledge across enterprise IT (infrastructure, applications, identity and access management, cloud/SaaS, and data governance) and how controls mitigate risk.

  • Strong stakeholder management skills with a track record of influencing senior leaders and driving outcomes across Technology, Compliance, Legal, and Internal Audit.

  • Excellent written, verbal, and presentation skills; able to communicate complex technical risk issues clearly to executives and governance committees.

  • Experience in developing and defining enterprise risk level appetite, tolerance thresholds, and escalation criteria.

  • Ability to challenge control owners constructively and drive accountability and remediation.

Preferred

  • Familiarity with industry regulations and standards (SOX, PCI, DORA) and technical frameworks (e.g., NIST, ISO 27001) and attack frameworks (e.g., MITRE ATT&CK or similar).

  • Experience interacting directly with regulators, auditors, and board risk committees.

  • Understanding of secure software development and application security risks

The base salary range for this position is $110,000 - $315,000 per year.

Arrowstreet Capital operates a robust talent acquisition program, and we also seek to compensate and reward our employees competitively within our industry and in line with our merit-based culture.Our approach to total compensation includes base salaries and annual discretionary bonuses, as well as a robust benefits package. The determination of a successful candidate's base salary placement within the listed range will vary based on the candidate's relevant experience and qualifications (which may also include relevant certifications, credentials and other education), the job responsibilities and scope, the commensurate resulting level of the position and other relevant factors. The listed range is also an estimate, and additional information regarding base salary and other elements of total compensation offered by Arrowstreet Capital to successful applicants will be communicated during the recruitment process.

Arrowstreet Capital is a Boston-based systematic investment firm that manages global equity portfolios for institutional investors around the world.

All qualified applicants will receive consideration for employment without regard to sex, race, color, religion, national origin, ancestry, genetic information, age, pregnancy, medical condition, disability, veteran or military status, marital status or any other characteristic protected by federal, state, or local law.

Arrowstreet Capital is committed to working with and providing reasonable accommodations for qualified individuals with disabilities and disabled veterans. If you need a reasonable accommodation for any part of the employment process due to a disability, contact us to discuss the nature of your request and contact information.