Position Overview The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third ...
Position Overview The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third ...
Enterprise Risk Analyst
Denver, CO · On-site
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...
Enterprise Risk Analyst
Denver, CO · On-site
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...
Senior Cybersecurity Risk Analyst - USA Remote
Denver, CO · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
Senior Cybersecurity Risk Analyst - USA Remote
Denver, CO · Remote
$130K - $160K/yr
The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk ... Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake ...
The Sr. Supply Chain Partnerships team at Checkr is dedicated to advancing strategic partnerships ... and risk management.. * R&D Strategic Alignment: Lead collaboration with Product and Engineering ...
The Sr. Supply Chain Partnerships team at Checkr is dedicated to advancing strategic partnerships ... and risk management.. * R&D Strategic Alignment: Lead collaboration with Product and Engineering ...
Senior Vendor Relationship Manager
Denver, CO · On-site
$96K - $113K/yr
The Sr. Supply Chain Partnerships team at Checkr is dedicated to advancing strategic partnerships ... and risk management.. * R&D Strategic Alignment: Lead collaboration with Product and Engineering ...
Senior Vendor Relationship Manager
Denver, CO · On-site
$96K - $113K/yr
The Sr. Supply Chain Partnerships team at Checkr is dedicated to advancing strategic partnerships ... and risk management.. * R&D Strategic Alignment: Lead collaboration with Product and Engineering ...
Risk Management Specialist
Denver, CO · On-site
Effectively communicate status and provide risk reporting to senior management and other key stakeholders. * Develop and implement the Project Risk Management Plan as well as Risk Governance ...
Risk Management Specialist
Denver, CO · On-site
Effectively communicate status and provide risk reporting to senior management and other key stakeholders. * Develop and implement the Project Risk Management Plan as well as Risk Governance ...
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Director, Risk Management
Denver, CO · On-site
$192K - $216K/yr
STACK is looking for a Director of Risk Management togrow and mature its insurance programs. As a ... Field and manage COI requests from vendors and financing parties * Advise on insurable and ...
Director, Risk Management
Denver, CO · On-site
$192K - $216K/yr
STACK is looking for a Director of Risk Management togrow and mature its insurance programs. As a ... Field and manage COI requests from vendors and financing parties * Advise on insurable and ...
Direct the third-party risk management strategy, conducting vendor due diligence and evaluating ecosystem security controls * Deploy artificial intelligence solutions to automate governance risk ...
New
Quick apply
Direct the third-party risk management strategy, conducting vendor due diligence and evaluating ecosystem security controls * Deploy artificial intelligence solutions to automate governance risk ...
New
Risk Management Professional - Insurance Risk
Westminster, CO · On-site
$99K - $137K/yr
Manage external broker partnerships and insurance vendors, holding partners accountable for top-tier service delivery and cutting-edge market intelligence. * Optimize the company's Total Cost of Risk ...
Risk Management Professional - Insurance Risk
Westminster, CO · On-site
$99K - $137K/yr
Manage external broker partnerships and insurance vendors, holding partners accountable for top-tier service delivery and cutting-edge market intelligence. * Optimize the company's Total Cost of Risk ...
Within our Corporate Enterprise Risk Management team in Denver , Leprino is seeking a Senior Risk ... Partner with manufacturing facilities and corporate teams to evaluate vendor insurance requirements ...
Within our Corporate Enterprise Risk Management team in Denver , Leprino is seeking a Senior Risk ... Partner with manufacturing facilities and corporate teams to evaluate vendor insurance requirements ...
Within our Corporate Enterprise Risk Management team in Denver , Leprino is seeking a Senior Risk ... Partner with manufacturing facilities and corporate teams to evaluate vendor insurance requirements ...
Within our Corporate Enterprise Risk Management team in Denver , Leprino is seeking a Senior Risk ... Partner with manufacturing facilities and corporate teams to evaluate vendor insurance requirements ...
Serve as a trusted advisor to senior leaders on enterprise and emerging risk matters. * Collaborate with Legal, Compliance, Finance, External Affairs, Emergency Management, and other functions to ...
Serve as a trusted advisor to senior leaders on enterprise and emerging risk matters. * Collaborate with Legal, Compliance, Finance, External Affairs, Emergency Management, and other functions to ...
Serve as a trusted advisor to senior leaders on enterprise and emerging risk matters. * Collaborate with Legal, Compliance, Finance, External Affairs, Emergency Management, and other functions to ...
Serve as a trusted advisor to senior leaders on enterprise and emerging risk matters. * Collaborate with Legal, Compliance, Finance, External Affairs, Emergency Management, and other functions to ...
Serve as a trusted advisor to senior leaders on enterprise and emerging risk matters. * Collaborate with Legal, Compliance, Finance, External Affairs, Emergency Management, and other functions to ...
Serve as a trusted advisor to senior leaders on enterprise and emerging risk matters. * Collaborate with Legal, Compliance, Finance, External Affairs, Emergency Management, and other functions to ...
Risk Management Coordinator Denver, CO Rocky Mountain Public Media, Inc. (RMPM) is the parent ... Collects, reviews, and tracks Certificates of Insurance (COIs) from vendors, contractors ...
Risk Management Coordinator Denver, CO Rocky Mountain Public Media, Inc. (RMPM) is the parent ... Collects, reviews, and tracks Certificates of Insurance (COIs) from vendors, contractors ...
Risk Management Coordinator
Denver, CO · On-site
$27.27 - $36.78/hr
Risk Management Coordinator Denver, CO Rocky Mountain Public Media, Inc. (RMPM) is the parent ... Collects, reviews, and tracks Certificates of Insurance (COIs) from vendors, contractors ...
Quick apply
Risk Management Coordinator
Denver, CO · On-site
$27.27 - $36.78/hr
Risk Management Coordinator Denver, CO Rocky Mountain Public Media, Inc. (RMPM) is the parent ... Collects, reviews, and tracks Certificates of Insurance (COIs) from vendors, contractors ...
Risk Management Coordinator
Denver, CO · On-site
$27.27 - $36.78/hr
Risk Management Coordinator Denver, CO Rocky Mountain Public Media, Inc. (RMPM) is the parent ... Collects, reviews, and tracks Certificates of Insurance (COIs) from vendors, contractors ...
Risk Management Coordinator
Denver, CO · On-site
$27.27 - $36.78/hr
Risk Management Coordinator Denver, CO Rocky Mountain Public Media, Inc. (RMPM) is the parent ... Collects, reviews, and tracks Certificates of Insurance (COIs) from vendors, contractors ...
Senior Vendor Risk Management information
What does a Senior Vendor Risk Management professional do?
What are the key skills and qualifications needed to thrive as a Senior Vendor Risk Management professional, and why are they important?
What are some common challenges faced by Senior Vendor Risk Management professionals, and how can they be addressed?
What is the difference between Senior Vendor Risk Management vs Vendor Risk Analyst?
| Aspect | Senior Vendor Risk Management | Vendor Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, or similar | CRISC, CISA, or similar |
| Work Environment | Strategic, leadership-focused, cross-departmental | Operational, data analysis, risk assessment |
| Employer & Industry Usage | Financial, healthcare, technology firms | Financial, retail, technology sectors |
Senior Vendor Risk Management roles typically involve strategic oversight and leadership in managing vendor risks, requiring advanced certifications and experience. Vendor Risk Analysts focus on data collection, risk assessment, and supporting vendor evaluations. While both roles require similar credentials, the senior role emphasizes strategy and management, whereas the analyst role is more operational and detail-oriented.

Asurion rating
7.2
Based on 84 frontline employees who took The Breakroom Quiz
125th of 213 rated it services
Job description
The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third-party risk lifecycle-intake, inherent-risk tiering, due diligence, contract controls, continuous monitoring, reassessment, and secure offboarding-protecting Asurion and its carrier and partner ecosystem from risks introduced by vendors, service providers, and technology suppliers. The leader partners closely with Procurement, Legal, Privacy, business portfolio owners, and security control owners to translate fragmented vendor information into clear, defensible risk decisions. This is both a program-building and people-leadership role, maturing the vendor risk function in alignment with NIST CSF 2.0 and strengthening supply chain risk outcomes while embedding modern practices for emerging risks such as third-party AI tooling, SaaS sprawl, and vendor concentration.
Key Responsibilities- Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program aligned to NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and regulatory obligations.
- Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology; secure governance approval and drive consistent adoption across the enterprise.
- Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership and apply them to vendor risk decisions.
- Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding in partnership with Procurement and Legal.
- Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination, treatment/acceptance, contracting, continuous monitoring, reassessment, and offboarding.
- Operationalize inherent-risk tiering to scope assessment depth and cadence based on data sensitivity, access, criticality, and business impact.
- Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments and evidence including SOC 2 Type II, ISO 27001, PCI AOC, and penetration test results.
- Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk across the supplier portfolio.
- Establish and lead risk reviews for third-party AI/GenAI tooling with security and privacy teams; address model and data-handling risks and shadow AI.
- Translate findings into concise, business-relevant risk narratives and actionable remediation plans with owners and timelines.
- Operate continuous monitoring leveraging external risk ratings, periodic attestations, threat/breach intelligence, and event-driven triggers.
- Coordinate third-party incident response with SOC/IR; assess impact, drive containment, and track remediation to closure.
- Manage the third-party risk register and findings inventory; escalate aging or accepted risks through governance.
- Maintain visibility into critical vendor resilience and BC/DR posture for high-impact suppliers.
- Partner with Legal and Procurement to define and negotiate security, privacy, and resilience terms (control requirements, right-to-audit, breach notification SLAs, data protection, subprocessor controls).
- Develop a standardized library of contractual security requirements scaled to vendor risk tier.
- Define and report outcome-driven metrics and KRIs (e.g., residual risk trends, assessment cycle time/coverage, time-to-remediate, monitoring coverage, exception aging); deliver executive-ready reporting to governance forums.
- Serve as the primary point of contact for internal/external audits, regulatory exams, and carrier-partner due diligence.
- Build, lead, and develop a high-performing team of vendor risk analysts; set objectives, coach performance, and scale capability through playbooks, training, and quality reviews.
- Drive operational efficiency via process automation and analyst-assistive tooling to focus effort on judgment-intensive decisions.
- 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party/vendor risk management.
- 2+ years of direct people leadership managing analysts or a risk team.
- Demonstrated experience designing or maturing a TPRM program lifecycle end to end.
- Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and assessment standards such as SIG/Shared Assessments.
- Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports) and translating them into risk decisions.
- Hands-on experience with TPRM/GRC platforms and continuous monitoring/security-rating tools (e.g., ProcessUnity, OneTrust, Prevalent/Mitratech, Whistic, BitSight, SecurityScorecard, or comparable).
- Experience partnering with Procurement and Legal on vendor contracting and security/privacy terms.
- Excellent written and verbal communication, including executive briefing and defensible risk narratives.
- Bachelor's degree in a related field or equivalent professional experience.
- Preferred: certifications such as CTPRP, CISSP, CISA, CRISC, or CISM; experience in regulated consumer or financial environments (e.g., GLBA, PCI DSS, state privacy laws); experience with AI/GenAI risk assessment; familiarity with three lines of defense; experience with automation or AI-assisted workflows in GRC.
- Sound risk judgment balancing rigor with business enablement and speed-to-value.
- Ability to influence without authority across Procurement, Legal, Privacy, Security, and business stakeholders.
- Program design, policy/standard development, and governance execution for TPRM.
- Expertise in vendor risk tiering, due diligence, continuous monitoring, issue management, and secure offboarding.
- Strong analytical skills to assess concentration, systemic risk, and fourth-party dependencies.
- Advanced communication skills; distills complex third-party risk into actionable executive decisions.
- Team leadership, talent development, and operational scaling through playbooks, training, and QA.
- Proficiency with metrics/KRIs, dashboards, and executive reporting.
- Negotiation of contractual security/privacy/resilience terms and control requirements.
N/A
Physical Demands- Stationary Position: Frequently
- Vision: 20/20 corrected vision
- Hearing: Receive detailed information if spoken to