Must-haves * 4+ years of experience in vendor risk management * Third-party and vendor security risk assessment: * Experience running security risk assessments of third parties--reviewing ...
Must-haves * 4+ years of experience in vendor risk management * Third-party and vendor security risk assessment: * Experience running security risk assessments of third parties--reviewing ...
Security Risk Manager
San Francisco, CA ยท On-site
Specifically, the company wants someone with adept experience in security risk management (not just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * ...
Security Risk Manager
San Francisco, CA ยท On-site
Specifically, the company wants someone with adept experience in security risk management (not just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * ...
Senior Manager, Financial Risk Management
San Francisco, CA ยท On-site
$216K - $240K/yr
About the Team The Internal Controls function sits within the broader Finance Risk Management (FRM ... third-party dependencies, systems, and other high-risk workflows. We work closely with ...
Senior Manager, Financial Risk Management
San Francisco, CA ยท On-site
$216K - $240K/yr
About the Team The Internal Controls function sits within the broader Finance Risk Management (FRM ... third-party dependencies, systems, and other high-risk workflows. We work closely with ...
Partnerships Manager
San Francisco, CA ยท Hybrid
$97K - $97K/yr
This hybrid role combines strategic partnership/network expansion with rigorous vendor management and third-party risk governance. In this position, you will be responsible for sourcing, building ...
Partnerships Manager
San Francisco, CA ยท Hybrid
$97K - $97K/yr
This hybrid role combines strategic partnership/network expansion with rigorous vendor management and third-party risk governance. In this position, you will be responsible for sourcing, building ...
Partnerships Manager
San Francisco, CA ยท On-site
$97K - $97K/yr
This hybrid role combines strategic partnership/network expansion with rigorous vendor management and third-party risk governance. In this position, you will be responsible for sourcing, building ...
Partnerships Manager
San Francisco, CA ยท On-site
$97K - $97K/yr
This hybrid role combines strategic partnership/network expansion with rigorous vendor management and third-party risk governance. In this position, you will be responsible for sourcing, building ...
About the Team The Internal Controls function sits within the broader Finance Risk Management (FRM ... third-party dependencies, systems, and other high-risk workflows. We work closely with ...
About the Team The Internal Controls function sits within the broader Finance Risk Management (FRM ... third-party dependencies, systems, and other high-risk workflows. We work closely with ...
Risk Advisory Intern - Summer 2027
San Francisco, CA ยท On-site
$17.75 - $23.50/hr
Executing enterprise, operational, information technology and third-party risk management and ... Benefits for internship positions: Grant Thornton interns are eligible toparticipatein the firm ...
Risk Advisory Intern - Summer 2027
San Francisco, CA ยท On-site
$17.75 - $23.50/hr
Executing enterprise, operational, information technology and third-party risk management and ... Benefits for internship positions: Grant Thornton interns are eligible toparticipatein the firm ...
Risk Advisory Intern - Summer 2027
San Francisco, CA ยท On-site
$17.75 - $23.50/hr
Executing enterprise, operational, information technology and third-party risk management and ... Grant Thornton interns are eligible to participate in the firm's medical, dental and vision ...
Risk Advisory Intern - Summer 2027
San Francisco, CA ยท On-site
$17.75 - $23.50/hr
Executing enterprise, operational, information technology and third-party risk management and ... Grant Thornton interns are eligible to participate in the firm's medical, dental and vision ...
Risk Advisory Intern - Summer 2027
San Francisco, CA ยท On-site
$17.75 - $23.50/hr
Executing enterprise, operational, information technology and third-party risk management and ... Benefits for internship positions: Grant Thornton interns are eligible toparticipatein the firm ...
Risk Advisory Intern - Summer 2027
San Francisco, CA ยท On-site
$17.75 - $23.50/hr
Executing enterprise, operational, information technology and third-party risk management and ... Benefits for internship positions: Grant Thornton interns are eligible toparticipatein the firm ...
Lead the development and implementation of strategic cyber programs including virtual CISO services, board advisory, third-party risk management, cloud and technology risk, incident readiness, cyber ...
New
Lead the development and implementation of strategic cyber programs including virtual CISO services, board advisory, third-party risk management, cloud and technology risk, incident readiness, cyber ...
New
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contribute to the functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contribute to the functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
Ability to learn use of the ProcessUnity/CyberGRX third party risk management platform
Quick apply
Ability to learn use of the ProcessUnity/CyberGRX third party risk management platform
Own the AI and third-party risk management process -- delivering risk insights that matter, not rubber-stamping compliance * Establish a security steering committee with relevant stakeholders to ...
Own the AI and third-party risk management process -- delivering risk insights that matter, not rubber-stamping compliance * Establish a security steering committee with relevant stakeholders to ...
Program Manager, Compliance
San Francisco, CA ยท On-site
Experience with GRC tooling or third-party risk management systems, and certification such as CCEP or CCEP-I. * Current or past U.S. Government Security Clearance. Compensation packages at Scale for ...
Program Manager, Compliance
San Francisco, CA ยท On-site
Experience with GRC tooling or third-party risk management systems, and certification such as CCEP or CCEP-I. * Current or past U.S. Government Security Clearance. Compensation packages at Scale for ...
Manage the third-party risk management program, ensuring that third-party relationships are adequately assessed for sufficient controls (especially information security), risks and aligned with the ...
Quick apply
Manage the third-party risk management program, ensuring that third-party relationships are adequately assessed for sufficient controls (especially information security), risks and aligned with the ...
Program Manager, Compliance Scale AI San Francisco, CA
San Francisco, CA ยท On-site
$164K - $206K/yr
Experience with GRC tooling or third-party risk management systems, and certification such as CCEP or CCEP-I. * Current or past U.S. Government Security Clearance. Compensation packages at Scale for ...
Program Manager, Compliance Scale AI San Francisco, CA
San Francisco, CA ยท On-site
$164K - $206K/yr
Experience with GRC tooling or third-party risk management systems, and certification such as CCEP or CCEP-I. * Current or past U.S. Government Security Clearance. Compensation packages at Scale for ...
Manage the third-party risk management program, ensuring that third-party relationships are adequately assessed for sufficient controls (especially information security), risks and aligned with the ...
Manage the third-party risk management program, ensuring that third-party relationships are adequately assessed for sufficient controls (especially information security), risks and aligned with the ...
Customer Success Manager
San Francisco, CA ยท On-site
About Magnitude Magnitude (formerly Archer Faris) is pioneering the world's first 100% multi-agent approach to enterprise security, starting with Third-Party Risk Management, a domain that is mission ...
Customer Success Manager
San Francisco, CA ยท On-site
About Magnitude Magnitude (formerly Archer Faris) is pioneering the world's first 100% multi-agent approach to enterprise security, starting with Third-Party Risk Management, a domain that is mission ...
Internship Third Party Risk Management information
What is an internship in third party risk management?
What does an internship in third party risk management involve?
What are the key skills and qualifications needed for an internship in third party risk management?
What is the difference between Internship Third Party Risk Management vs Third Party Risk Analyst?
| Aspect | Internship Third Party Risk Management | Third Party Risk Analyst |
|---|---|---|
| Credentials | Typically pursuing or recent graduate, no formal certification required | Bachelor's degree often required; certifications like CTPRP beneficial |
| Work Environment | Internship setting, supervised, entry-level tasks | Full-time professional role, analytical and risk assessment tasks |
| Employer & Industry Usage | Internship programs in finance, banking, or corporate sectors | Financial institutions, corporations, and consulting firms |
Internship Third Party Risk Management is an entry-level, supervised role for students or recent graduates gaining exposure to third-party risk processes. In contrast, a Third Party Risk Analyst is a full-time professional responsible for analyzing and managing third-party risks, often requiring relevant education and certifications. Both roles are essential in risk management but differ in experience level and responsibilities.
What job categories do people searching Internship Third Party Risk Management jobs in Novato, CA look for?
The top searched job categories for Internship Third Party Risk Management jobs in Novato, CA are:
What cities near Novato, CA are hiring for Internship Third Party Risk Management jobs?
Cities near Novato, CA with the most Internship Third Party Risk Management job openings:

Security Analyst, Third-Party Ecosystem Risk Management
San Francisco, CA โข On-site
Other
Medical, Dental, Vision, Retirement
Posted 24 days ago
Key responsibilities
Run security risk assessments for third parties, including vendors, customers, and partners, from intake to risk rating and documentation of findings and exceptions.
Maintain and update the third-party risk lifecycle by managing risk tiering, reassessment cadence, remediation follow-through, and keeping the risk register current.
Report on ecosystem risk metrics such as assessment cycle times, backlog, open exceptions, and reassessment coverage to stakeholders.
Job description
We believe that the way people interact with their finances will drastically improve in the next few years. Weโre dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaidโs network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam.
Team:
The Security Governance, Risk, and Compliance (GRC) team is part of Plaidโs security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We partner closely across the company to ensure Plaidโs platform remains secure, resilient, and aligned with industry and regulatory expectations.
Third-party ecosystem risk is a core part of how we keep Plaid safeโwe vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions.
Role:
-
You will run security risk assessments for Plaidโs third parties end-to-endโfrom intake and questionnaire through risk rating, findings, and tracked exceptions.
-
You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors.
-
You will keep the third-party risk lifecycle movingโrisk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register.
-
You will help mature the programโquestionnaires, tiering criteria, intake, and runbooksโso reviews get faster and more consistent as volume grows, drawing on how youโve improved third-party risk programs before.
-
You will report on ecosystem risk to Security and cross-functional stakeholders, and operate as an AI power user to raise your own throughput.
Responsibilities:
-
Run Vendor Security Risk Assessments: Triage inbound vendor requests, run security reviews scaled to risk tier, rate the risk, and document findings and exceptions. Your assessments keep Plaid from inheriting a vendorโs security gaps and give Procurement, Privacy, and Legal a clear risk signal before contracts are signed.
-
Vet Customer and Partner Security Posture: Review the security practices of customers and partners onboarding to the platform, applying the same standards you use for vendors. Your reviews make sure who connects to Plaid meets the bar before they touch dataโprotecting consumers and the ecosystem.
-
Keep the Third-Party Risk Lifecycle Current: Maintain risk tiering, drive reassessments on cadence, chase remediation to closure, and keep the risk register accurate. Your follow-through keeps third-party risk a live, trustworthy picture rather than a point-in-time checkbox.
-
Mature the Program: Improve questionnaires, tiering criteria, intake, and runbooks, and tooling as review volume growsโbringing patterns from third-party risk programs youโve matured before. Your work moves the function from ad hoc toward fast, consistent, and scalable.
-
Report on Ecosystem Risk: Track assessment cycle times, backlog, open exceptions, and reassessment coverage, and report program health to stakeholders. Your reporting gives leadership real visibility into where third-party risk concentrates.
-
Scale Through AI and Tooling: Build and scale AI-assisted workflows for assessment review, questionnaire analysis, and reportingโand share what works. Your approach sets how the team uses AI to handle more reviews without adding headcount.
Qualifications:
Must-haves
- 4+ years of experience in vendor risk management
- Third-party and vendor security risk assessment:
- Experience running security risk assessments of third partiesโreviewing questionnaires, SOC 2 and ISO reports, and security documentation, and translating them into a defensible risk rating.
- Familiarity with the third-party risk lifecycle: intake, tiering, exceptions and risk acceptance, remediation tracking, and periodic reassessment.
- Security and compliance knowledge:
- Working knowledge of SOC 2, ISO 27001, NIST CSF, and common control domains (access control, encryption, incident response, BC/DR).
- Ability to read a control environment and tell a real gap from an acceptable compensating control.
- Program maturation and operational execution:
- Experience maturing a third-party or vendor risk programโimproving how it works (tiering criteria, questionnaires, workflow, automation), not just executing an existing one.
- Track record running assessments at volume without dropping rigor.
- Strong analytical and documentation skills: clear findings, clean tracking, and defensible risk decisions others can follow.
- Communication and cross-functional effectiveness:
- Clear written and verbal communicationโable to explain a security risk to Procurement, Legal, or a customer without overstating or hand-waving.
- Comfortable working across Security, Legal, Procurement, and GTM as the third-party risk point of contact.
- AI fluency and tooling:
- Demonstrated ability to apply AI tooling to assessment review, questionnaire analysis, and reporting to materially increase throughputโand to share what works with the team.
Nice-to-have
- A third-party-risk or audit credential (CTPRP, CISA, or CISSP), or hands-on ownership of a TPRM platform (e.g. OneTrust, ProcessUnity, Whistic, SecurityScorecard) beyond using it as an end user.
Our mission at Plaid is to unlock financial freedom for everyone. To support that mission, we seek to build a diverse team of driven individuals who care deeply about making the financial ecosystem more equitable. We recognize that strong qualifications can come from both prior work experiences and lived experiences. We encourage you to apply to a role even if your experience doesn't fully match the job description. We are always looking for team members that will bring something unique to Plaid!
Plaid is proud to be an equal opportunity employer and values diversity at our company.
We do not discriminate based on race, color, national origin, ethnicity, religion or religious belief, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, military or veteran status, disability, or other applicable legally protected characteristics.
We also consider qualified applicants with criminal histories, consistent with applicable federal, state, and local laws.
Plaid is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process.
If you need any assistance with your application or interviews due to a disability, please let us know at accommodations@plaid.com.
Please review our Candidate Privacy Notice here.
Additional compensation in the form(s) of equity and/or commission are dependent on the position offered. Plaid provides a comprehensive benefit plan, including medical, dental, vision, and 401(k). Pay is based on factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience and skillset, and location. Pay and benefits are subject to change at any time, consistent with the terms of any applicable compensation or benefit plans.
About MoneyLion
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
201 - 500 Employees
Headquarters location
NY, US
Year founded
2012