1

Senior Vendor Risk Management Jobs in California

Manager, IT Risk Operations

Palo Alto, CA · On-site

$147K - $198K/yr

Managing a small team, you willwork closely with senior leaders across IT, Security Engineering ... Drive workflow optimization and automation within ServiceNow Vendor Risk Management * Review and ...

Conduct and oversee risk reviews for contracts, vendor agreements, and new business initiatives ... Serve as the primary advisor to senior leadership on all risk and insurance matters. * Lead, mentor ...

Director, Risk Management

San Diego, CA · On-site

$169.48 - $203.38/hr

Establish and track key risk indicators (KRIs) and present regular risk dashboards to senior ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Director, Risk Management

San Diego, CA · On-site

$169.48 - $203.38/hr

Establish and track key risk indicators (KRIs) and present regular risk dashboards to senior ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

New

Establish and track key risk indicators (KRIs) and present regular risk dashboards to senior ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Establish and track key risk indicators (KRIs) and present regular risk dashboards to senior ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Director, Risk Management

San Diego, CA · On-site

$169.48 - $203.38/hr

Establish and track key risk indicators (KRIs) and present regular risk dashboards to senior ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Showing results 21-40

Senior Vendor Risk Management information

What does a senior vendor risk management professional do?

A Senior Vendor Risk Management professional is responsible for overseeing an organization’s third-party vendors to identify, assess, and mitigate risks that could impact business operations, data security, or regulatory compliance. They develop and implement vendor risk assessment frameworks, conduct thorough due diligence, and collaborate with other departments to ensure vendors meet company standards and legal requirements. Additionally, they monitor ongoing vendor relationships, manage risk remediation efforts, and often report findings to senior leadership or regulatory bodies.

What are the key skills and qualifications needed to thrive as a senior vendor risk management professional, and why are they important?

To thrive as a Senior Vendor Risk Management professional, you need expertise in risk assessment, third-party due diligence, and a solid understanding of regulatory compliance, often supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk management platforms, vendor management systems, and certifications like CISA or CRVPM is commonly expected. Strong analytical thinking, communication, and negotiation skills are crucial for building effective relationships and addressing vendor issues. These skills and qualifications are essential for mitigating risks, ensuring compliance, and safeguarding organizational interests in vendor relationships.

What are some common challenges faced by senior vendor risk management professionals, and how can they be addressed?

Senior Vendor Risk Management professionals often encounter challenges such as navigating complex regulatory requirements, managing relationships with a diverse range of vendors, and ensuring consistent due diligence across all third parties. Addressing these challenges typically involves staying updated on relevant regulations, implementing robust risk assessment frameworks, and fostering strong communication with both internal stakeholders and vendors. Building cross-functional collaboration with legal, compliance, and procurement teams is also crucial for effectively mitigating vendor-related risks.

What is the difference between Senior Vendor Risk Management vs Vendor Risk Analyst?

AspectSenior Vendor Risk ManagementVendor Risk Analyst
CertificationsCRISC, CISA, or similarCRISC, CISA, or similar
Work EnvironmentStrategic, leadership-focused, cross-departmentalOperational, data analysis, risk assessment
Employer & Industry UsageFinancial, healthcare, technology firmsFinancial, retail, technology sectors

Senior Vendor Risk Management roles typically involve strategic oversight and leadership in managing vendor risks, requiring advanced certifications and experience. Vendor Risk Analysts focus on data collection, risk assessment, and supporting vendor evaluations. While both roles require similar credentials, the senior role emphasizes strategy and management, whereas the analyst role is more operational and detail-oriented.

What are the most commonly searched types of Vendor Risk Management jobs in California? The most popular types of Vendor Risk Management jobs in California are:
What are popular job titles related to Senior Vendor Risk Management jobs in California? For Senior Vendor Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Senior Vendor Risk Management jobs in California look for? The top searched job categories for Senior Vendor Risk Management jobs in California are:
What cities in California are hiring for Senior Vendor Risk Management jobs? Cities in California with the most Senior Vendor Risk Management job openings:
Infographic showing various Senior Vendor Risk Management job openings in California as of August 2026, with employment types broken down into 73% Full Time, 22% Part Time, 3% Temporary, and 2% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution.

Governance, Risk Management and Compliance, Senior Director

Astera Labs

San Jose, CA • On-site

$225K - $250K/yr

Full-time

Posted 9 days ago


Job description

Astera Labs (NASDAQ: ALAB) provides rack-scale AI infrastructure through purpose-built connectivity solutions. By collaborating with hyperscalers and ecosystem partners, Astera Labs enables organizations to unlock the full potential of modern AI. Astera Labs' Intelligent Connectivity Platform integrates CXL®, Ethernet, NVLink, PCIe®, and UALink™ semiconductor-based technologies with the company's COSMOS software suite to unify diverse components into cohesive, flexible systems that deliver end-to-end scale-up, and scale-out connectivity. The company's custom connectivity solutions business complements its standards-based portfolio, enabling customers to deploy tailored architectures to meet their unique infrastructure requirements. Discover more at www.asteralabs.com.
Senior Director, Governance, Risk Management and Compliance
Location: San Jose, CA
Role Overview
Astera Labs is redefining connectivity for the AI era, and as we scale, we need a strategic leader to safeguard how we operate. The Senior Director, Governance, Risk Management and Compliance (GRC) will build and lead the enterprise GRC function - establishing the frameworks, controls, and culture that protect Astera Labs' people, products, data, and reputation as we grow.
This is a highly visible, cross-functional role that partners with Finance, Legal, IT, Security, Engineering, and Operations to embed risk-aware decision-making across the company. You'll shape how Astera Labs manages enterprise risk, regulatory compliance, internal controls, and third-party risk during one of the most exciting growth chapters in semiconductors - enabling rack-scale AI infrastructure for the world's leading hyperscalers.
Key Responsibilities
  • Governance & Program Leadership
    • Build, lead, and continuously mature Astera Labs' enterprise GRC program, aligned to company strategy and growth stage
    • Define governance structures, policies, and standards; drive executive and Board-level reporting on risk and compliance posture
    • Partner with Legal, Finance, IT, and Security leadership to align GRC priorities with business objectives
  • Risk Management
    • Design and operate the enterprise risk management (ERM) framework, including risk identification, assessment, treatment, and monitoring
    • Lead third-party and vendor risk management, ensuring appropriate due diligence and ongoing oversight
    • Establish clear risk appetite, metrics, and escalation paths across business functions
  • Compliance & Controls
    • Own the internal controls program (including SOX readiness and ongoing 404 compliance) in partnership with Finance and Internal Audit
    • Drive compliance with applicable regulatory, industry, and customer requirements (e.g., SOC 2, ISO 27001, NIST, data privacy regulations)
    • Serve as primary liaison for internal and external auditors, coordinating audits, findings, and remediation
  • Team & Culture
    • Recruit, develop, and lead a high-performing GRC team as the function scales
    • Champion a culture of accountability, integrity, and continuous improvement across the organization
    • Deliver training, awareness, and enablement programs that make risk and compliance part of how Astera Labs operates day-to-day

Basic Qualifications
  • Bachelor's degree in business, Finance, Accounting, Information Systems, or a related field
  • 10+ years of progressive experience in governance, risk management, compliance, internal audit, or a related discipline, with 5+ years in a leadership role
  • Demonstrated experience building or scaling a GRC program at a public or pre-/post-IPO technology company
  • Strong working knowledge of SOX, ERM frameworks (e.g., COSO), and industry standards such as SOC 2, ISO 27001, or NIST
  • Proven ability to influence and partner with executive stakeholders across Finance, Legal, IT, Security, and business functions
  • Excellent written and verbal communication skills, with experience presenting to executives, auditors, and/or the Board

Preferred Qualifications
  • Advanced degree (MBA, MS) and/or professional certifications such as CPA, CIA, CISA, CRISC, or CISSP
  • Experience in the semiconductor, hardware, or hyper-growth technology sector
  • Familiarity with data privacy regulations (GDPR, CCPA) and export/trade compliance considerations
  • Experience implementing GRC tooling and automating controls, assessments, and reporting
  • Strategic thinker who thrives in fast-paced, ambiguous environments and can balance pragmatism with rigor

Salary range is $225,000 to $250,000 depending on experience, level, and business need. This role may be eligible for discretionary bonus, incentives and benefits.
We know that creativity and innovation happen more often when teams include diverse ideas, backgrounds, and experiences, and we actively encourage everyone with relevant experience to apply, including people of color, LGBTQ+ and non-binary people, veterans, parents, and individuals with disabilities.