2

Remote Third Party Risk Management Jobs in Washington

Security Oversight Product Owner

Washington, DC · Remote

$120K - $130K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... proactive risk assessment, incident response, and security documentation support across high ... third-party Application Development and Operations (ADO) contractors. * Manage a customized ...

Senior Product Manager, Services

Reston, VA · Remote

$155K - $175K/yr

  • Medical

  • Dental

  • Vision

  • PTO

You'll lead Decisiv's third-party marketplace strategy, building a point of view on who to partner ... This is a remote role based in the United States, with occasional travel for partner engagements ...

Loan Review Managing Consultant

Washington, DC · On-site +1

$113K - $188K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

S. Small Business Administration (SBA) Office of Credit Risk Management (OCRM) by performing ... g., as a third-party reviewer, examiner, auditor, underwriter, loan closer, or liquidation ...

Risk Management & Governance: Capture, track, and drive resolution for all risks and issues via the ... Experience coordinating with third-party technology implementation teams on project dependencies ...

Showing results 41-60

Remote Third Party Risk Management information

See Washington salary details

$43.7K

$129.6K

$192.9K

How much do remote third party risk management jobs pay per year?

As of Aug 17, 2026, the average yearly pay for remote third party risk management in Washington is $129,627.00, according to ZipRecruiter salary data. Most workers in this role earn between $54,700.00 and $177,500.00 per year, depending on experience, location, and employer.

What is the difference between Remote Third Party Risk Management vs Remote Vendor Risk Management?

AspectRemote Third Party Risk ManagementRemote Vendor Risk Management
CertificationsISO 27001, CRISC, CTPRPISO 27001, CRISC, CTPRP
Work EnvironmentRemote, corporate, consultingRemote, corporate, consulting
Industry UsageFinancial, healthcare, techFinancial, healthcare, tech
FocusManaging risks from third parties and vendorsManaging risks specifically from vendors

Remote Third Party Risk Management and Remote Vendor Risk Management roles share similar credentials and work environments. However, Third Party Risk Management covers a broader scope, including all external entities, while Vendor Risk Management focuses specifically on vendors. Both are vital in industries like finance and healthcare, ensuring compliance and security in remote settings.

What are the most commonly searched types of Third Party Risk Management jobs in Washington?

The most popular types of Third Party Risk Management jobs in Washington are:

What are popular job titles related to Remote Third Party Risk Management jobs in Washington?

For Remote Third Party Risk Management jobs in Washington, the most frequently searched job titles are:

What job categories do people searching Remote Third Party Risk Management jobs in Washington look for?

The top searched job categories for Remote Third Party Risk Management jobs in Washington are:

What cities in Washington are hiring for Remote Third Party Risk Management jobs?

Cities in Washington with the most Remote Third Party Risk Management job openings:

Infographic showing various Remote Third Party Risk Management job openings in Washington as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 10% Part Time, 2% Temporary, and 6% Contract. Highlights an 80% Physical, 2% Hybrid, and 18% Remote job distribution, with an average salary of $129,627 per year, or $62.3 per hour.

Security Oversight Product Owner

ResolveSoft Inc

Washington, DC • Remote

$120K - $130K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 22 days ago


Job description

Security Oversight Product Owner

 

Position Overview

The Security Oversight Product Owner serves as a Key Personnel leader responsible for coordinating and executing the Security Oversight management program operations, maintenance, and continuous improvements for the Client’s Web and Emerging Technologies Group (WETG) digital ecosystem. This role ensures comprehensive security operations, continuous compliance management, proactive risk assessment, incident response, and security documentation support across high-profile, public-facing federal web assets.

The ideal candidate possesses deep expertise in Federal system security policies, NIST SP 800-series frameworks, and DevSecOps environments, serving as a trusted quality partner to protect beneficiary data and ensure continuous system authorization (ATO).


Core Responsibilities:

1. Program Coordination & Leadership

  • Coordinate the execution of the Security Oversight management program, managing operations, maintenance, and continuous engineering improvements.
  • Foster a collaborative, "badge-less" environment using Client-approved communication tools (e.g., Slack, Confluence) to align activities with federal Product Managers, ISSOs, the eCloud Service Provider (AWS), and third-party Application Development and Operations (ADO) contractors.
  • Manage a customized security service from an accredited FISMA-Moderate facility, ensuring all contractor workstations adhere to strict security configurations.

2. Vulnerability Management & Testing Coordination

  • Coordinate and support regular system security scanning activities, including Static/Dynamic Application Security Testing (SAST/DAST), penetration testing, and database vulnerability scans.
  • Collaborate closely with the Task 2 Independent Testing teams to align security testing with overall quality assurance workflows, ensuring non-duplicative effort and consistent prioritization of security fixes.
  • Analyze scan findings to generate actionable Vulnerability Result Reports with definitive remediation timelines matching Client’s metrics (Critical: 15 days; High: 30 days).

3. Risk Assessment & Requirements Analysis

  • Establish, maintain, and continuously update a comprehensive Security Risk Register mapping system vulnerability to formal Plans of Action and Milestones (POA&Ms).
  • Synthesize technical risk telemetry into a high-level monthly Security Risk Report tailored for executive decision-making.
  • Identify, track, and maintain security requirements baseline for all in-scope applications using global and local threat intelligence.

4. Compliance & Security Documentation (A&A / ATO)

  • Lead the preparation, quarterly review, and annual updates of a wide variety of NIST SP 800-Series security artifacts within the Client’s security documentation repository.
  • Develop and maintain critical authorization packages, including System Security and Privacy Plans (SSPPs), Information System Risk Assessments (ISRA), Security Impact Analyses (SIAs), Privacy Impact Assessments (PIAs), and Information System Contingency Plans (ISCP).
  • Proactively prepare for and actively support the auditing community during Inspector General (IG), FISMA, third-party, and internal agency audits.

5. Incident Handling Oversight

  • Manage 24x7x365 on-call staffing to respond to security alerts and Indicators of Compromise (IOCs) from the Client’s Virtual Data Center NOC and SOC within 24 hours.
  • Facilitate and triage responses to suspected or confirmed privacy breaches/incidents in accordance with Client Incident Handling Guidelines, reporting critical issues within the mandatory 1-hour window.
  • Coordinate reverse malware engineering to support forensic analysis and incident response workflows when required.

Key Deliverables Managed

  • Vulnerability Result Reports (As required)
  • Security Risk Register (Updated within 4 days of risk identification)
  • Monthly Security Risk Reports (Sourced from live data dashboards)
  • A&A Package Updates (SSP, SAR, POA&Ms, ISCP)
  • Security Impact Analyses (SIAs) (Aligned to product release cycles)


Qualifications & Experience Requirements

Minimum Technical Qualifications

  • Experience: Demonstrated expertise in cybersecurity oversight, risk management frameworks, and security auditing within a large-scale, multi-team Agile/DevSecOps digital environment.
  • Framework Mastery: Deep, demonstrable familiarity with the CMS Risk Management Framework, Cybersecurity and Risk Assessment Program (CSRAP), FIPS 199/200, FedRAMP guidelines, and NIST SP 800-53 security controls.
  • Tooling Familiarity: Experience working with automated configuration/vulnerability tools, (or similar Trusted Agent FISMA applications), and common Agile toolchains (Jira, Confluence, GitHub).

Certifications (Highly Preferred / Contract Required)

  • Certified Information Systems Security Professional (CISSP), CISM, or equivalent federal security governance certification.
  • Demonstrated experience maintaining organization-level ISO 20000 (IT Management) and ISO 2700X (Security) certifications.

Core Competencies

  • Ability to interpret complex cryptographic validation standards (FIPS 140) and supply chain risk requirements (C-SCRM).
  • Strong communication skills to present highly technical security concepts into non-technical, consumable formats for senior stakeholders.
  • Suitability: Must be able to obtain a federal background investigation clearance commensurate with a high-level Position Sensitivity Designation.

Company Description

Our mission is to empower our clients to achieve sustainable success through efficient, cost-effective, and scalable solutions that drive significant performance improvements. We believe in delivering value-driven results and fostering a culture that attracts and retains top talent to provide scalable, adaptable services.