Responsible for the enterprise third-party risk management program, including vendor assessments, monitoring, and remediation follow-through. * Independently completes customer security ...
Responsible for the enterprise third-party risk management program, including vendor assessments, monitoring, and remediation follow-through. * Independently completes customer security ...
We deliver the market-leading enterprise SaaS solution for managing third-party risk and compliance, helping Global 2000 companies protect their brand, build customer trust, and drive principled ...
We deliver the market-leading enterprise SaaS solution for managing third-party risk and compliance, helping Global 2000 companies protect their brand, build customer trust, and drive principled ...
We deliver the market-leading enterprise SaaS solution for managing third-party risk and compliance, helping Global 2000 companies protect their brand, build customer trust, and drive principled ...
Quick apply
We deliver the market-leading enterprise SaaS solution for managing third-party risk and compliance, helping Global 2000 companies protect their brand, build customer trust, and drive principled ...
We deliver the market-leading enterprise SaaS solution for managing third-party risk and compliance, helping Global 2000 companies protect their brand, build customer trust, and drive principled ...
We deliver the market-leading enterprise SaaS solution for managing third-party risk and compliance, helping Global 2000 companies protect their brand, build customer trust, and drive principled ...
Director of Security
OR · Remote
$190K - $240K/yr
Oversee third party risk management, due diligence, contractual security requirements, and continuous monitoring. * Provide AI related security assessments and guidance. Establish acceptable use ...
Director of Security
OR · Remote
$190K - $240K/yr
Oversee third party risk management, due diligence, contractual security requirements, and continuous monitoring. * Provide AI related security assessments and guidance. Establish acceptable use ...
Principle, Enterprise Governance, Risk, and Compliance Specialist (Remote)
OR · On-site +1
$98.40K/yr
Knowledge and experience with third party and global supply chain risk management * Demonstrated ability to manage complex projects with competing priorities and tight deadlines * Extensive ...
Principle, Enterprise Governance, Risk, and Compliance Specialist (Remote)
OR · On-site +1
$98.40K/yr
Knowledge and experience with third party and global supply chain risk management * Demonstrated ability to manage complex projects with competing priorities and tight deadlines * Extensive ...
OR · On-site
$110K - $150K/yr
The Manager, Enterprise Risk Management is responsible for overseeing and coordinating the organization's Enterprise Risk Management (ERM) framework, ensuring effective risk identification ...
Oversee third-party risk management activities, including anti-bribery/anti-corruption due diligence, background checks, and trade sactions screening, to ensure compliance with compliance standards ...
Description The Senior Director, Shared Services (Third Party Business Support) provides strategic ... Own business processes supporting third‑party risk management, including due diligence ...
Description The Senior Director, Shared Services (Third Party Business Support) provides strategic ... Own business processes supporting third‑party risk management, including due diligence ...
Description The Senior Director, Shared Services (Third Party Business Support) provides strategic ... Own business processes supporting thirdparty risk management, including due diligence coordination ...
Description The Senior Director, Shared Services (Third Party Business Support) provides strategic ... Own business processes supporting thirdparty risk management, including due diligence coordination ...
The Senior Director, Shared Services (Third Party Business Support) provides strategic leadership ... Own business processes supporting thirdparty risk management, including due diligence coordination ...
The Senior Director, Shared Services (Third Party Business Support) provides strategic leadership ... Own business processes supporting thirdparty risk management, including due diligence coordination ...
Administrative Program Specialist - Third Party Billing
La Grande, OR · On-site
$3.96K/mo
Manage third-party billing cycles, including manual invoicing and monthly statements * Reconcile accounts and maintain accurate financial records * Support accounts receivable processes, including ...
Administrative Program Specialist - Third Party Billing
La Grande, OR · On-site
$3.96K/mo
Manage third-party billing cycles, including manual invoicing and monthly statements * Reconcile accounts and maintain accurate financial records * Support accounts receivable processes, including ...
Hybrid - 1 day per month Role Overview The Relationship Management team is responsible for managing and strengthening New York Life's home office relationships with key third-party partner firms.
Hybrid - 1 day per month Role Overview The Relationship Management team is responsible for managing and strengthening New York Life's home office relationships with key third-party partner firms.
SkillBridge - IT Engineer
OR · Remote
Collaborate with third-party vendors and internal stakeholders to support rollout, troubleshooting, and updates of SaaS tools * Assist with Third Party Risk Management (TPRM) reviews, including ...
SkillBridge - IT Engineer
OR · Remote
Collaborate with third-party vendors and internal stakeholders to support rollout, troubleshooting, and updates of SaaS tools * Assist with Third Party Risk Management (TPRM) reviews, including ...
Decisioning, including integration of alternative data sources and third-party risk intelligence ... Deep expertise in merchant risk, card-not-present exposure, chargeback management, fraud typologies ...
Decisioning, including integration of alternative data sources and third-party risk intelligence ... Deep expertise in merchant risk, card-not-present exposure, chargeback management, fraud typologies ...
... third-party risk management practices
... third-party risk management practices
Senior Account Executive - Third Party Originations
Hillsboro, OR · Remote
$185K - $230K/yr
Description We're seeking an experienced Sr Account Executive -Third Party Originations to help ... Maintain strong adherence to risk management, controls, and compliance expectations, reinforcing a ...
Senior Account Executive - Third Party Originations
Hillsboro, OR · Remote
$185K - $230K/yr
Description We're seeking an experienced Sr Account Executive -Third Party Originations to help ... Maintain strong adherence to risk management, controls, and compliance expectations, reinforcing a ...
VP, Financial Crimes
Hillsboro, OR · On-site
$220K - $260K/yr
Coordinate with Third-Party Risk Management on criticality assessments, concentration risk, and exit strategies. * Produce enterprise-level financial crimes risk reporting for the CRO, Enterprise ...
VP, Financial Crimes
Hillsboro, OR · On-site
$220K - $260K/yr
Coordinate with Third-Party Risk Management on criticality assessments, concentration risk, and exit strategies. * Produce enterprise-level financial crimes risk reporting for the CRO, Enterprise ...
VP, Financial Crimes
Hillsboro, OR · Hybrid
$220K - $260K/yr
Coordinate with Third-Party Risk Management on criticality assessments, concentration risk, and exit strategies. * Produce enterprise-level financial crimes risk reporting for the CRO, Enterprise ...
VP, Financial Crimes
Hillsboro, OR · Hybrid
$220K - $260K/yr
Coordinate with Third-Party Risk Management on criticality assessments, concentration risk, and exit strategies. * Produce enterprise-level financial crimes risk reporting for the CRO, Enterprise ...
VP, Financial Crimes
Hillsboro, OR · Hybrid
$220K - $260K/yr
Coordinate with Third-Party Risk Management on criticality assessments, concentration risk, and exit strategies. * Produce enterprise-level financial crimes risk reporting for the CRO, Enterprise ...
VP, Financial Crimes
Hillsboro, OR · Hybrid
$220K - $260K/yr
Coordinate with Third-Party Risk Management on criticality assessments, concentration risk, and exit strategies. * Produce enterprise-level financial crimes risk reporting for the CRO, Enterprise ...
Third Party Risk Management Manager information
What are the key skills and qualifications needed to thrive as a Third Party Risk Management Manager, and why are they important?
How does a Third Party Risk Management Manager typically collaborate with other departments to ensure effective risk mitigation?
What does a Third Party Risk Management Manager do?
What is the difference between Third Party Risk Management Manager vs Vendor Risk Manager?
| Aspect | Third Party Risk Management Manager | Vendor Risk Manager |
|---|---|---|
| Certifications | CRMP, CTPRP, or similar | CRMP, CTPRP, or similar |
| Work Environment | Financial institutions, corporations, regulated industries | Financial services, healthcare, technology companies |
| Industry Usage | Common in industries with complex third-party relationships | Focused on vendor-specific risk assessments |
The Third Party Risk Management Manager and Vendor Risk Manager roles share similar certifications and often operate in regulated industries. The main difference lies in scope: the Third Party Risk Management Manager oversees all third-party relationships, including vendors, partners, and contractors, while the Vendor Risk Manager primarily focuses on assessing and mitigating risks associated with vendors specifically. Both roles are essential for organizations aiming to ensure compliance and manage third-party risks effectively.
Full-time
Medical, Retirement, PTO
Posted 28 days ago
Job description
WHO WE ARE
Relation Insurance is a leading, innovative company with a strong commitment to excellence and a passion for delivering cutting-edge solutions to our clients. As a key player in the insurance market, we pride ourselves on our dynamic culture, collaborative environment, and continuous drive for success. With a rich history and a bright future ahead, we are looking for exceptional individuals to join our team and contribute to our ongoing growth and success.
WHAT WE'RE LOOKING FOR
The Deputy CISO, Governance, Risk & Compliance (GRC) is a senior security leader responsible for executing the organization's enterprise governance, risk, and compliance program end-to-end. The individual in this role operates with full responsibility and accountability for GRC outcomes, including successful audit completion, regulatory compliance, customer assurance, and third-party risk management.
The Deputy CISO, GRC serves as the primary security compliance authority for auditors, regulators, and customers and is expected to independently drive results, ensure completion of regulatory obligations, and maintain audit-ready security governance across the enterprise.
A GLIMPSE INTO YOUR DAY
- Leads and executes the enterprise governance, risk, and compliance program end-to-end.
- Operates across multiple regulatory frameworks simultaneously, ensuring successful delivery of compliance and risk outcomes.
- Serves as the primary point of contact for auditors, regulators, and customers on security and compliance matters.
- Represents the organization as the accountable security compliance leader in regulatory examinations, customer diligence reviews, and external assurance engagements.
- Leads enterprise audit and regulatory readiness through gap analysis, control design, policy development, evidence collection, and timely remediation closure, ensuring successful audit completion across SOC 1, SOC 2, NYDFS Part 500, HIPAA, and GDPR.
- Ensures timely closure of audit findings and remediation of control gaps through completion.
- Responsible for writing, maintaining, and enforcing all security and compliance policies, standards, and procedures.
- Retains ownership of control intent, rationale, and narrative consistency across audits, regulators, and customer engagements.
- Performs security and privacy risk assessments, control testing, and remediation tracking through completion.
- Responsible for maintaining enterprise data mapping, documenting data flows, systems, and third-party processors.
- Leads vendor privacy and security risk assessments involving regulated and personal data.
- Partners with legal and business stakeholders to ensure privacy governance requirements are met.
- Responsible for the enterprise third-party risk management program, including vendor assessments, monitoring, and remediation follow-through.
- Independently completes customer security questionnaires (SIG, CAIQ, and custom SAQs) and provides security narrative responses for RFPs and customer due diligence inquiries.
- Independently develops accurate, clear, and consistent security narratives grounded in sustained understanding of the organization's technical and risk environment, without repeated reliance on technical or engineering resources.
- Partners with IT, Engineering, Legal, Privacy, Risk, and business leadership to obtain evidence and implement controls, while retaining accountability for control interpretation and compliance outcomes.
- Provides executive-ready reporting on audit status, compliance posture, remediation progress, and enterprise risk.
- Leverages AI-assisted tools and automation to improve efficiency, consistency, and scale across GRC execution, while exercising sound judgment in regulated and confidential environments.
- Continuously identifies opportunities to streamline GRC processes through tooling, automation, and workflow optimization.
- Performs other projects, duties, and tasks, as assigned.
WHAT SUCCESS LOOKS LIKE IN THIS ROLE
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity or other related field. Master's degree in Cybersecurity or Information Systems preferred.
- Minimum 8 years of progressively responsible experience in information security, cybersecurity risk management, or related roles.
- Relevant certifications (CISSP, CISM, CISA, CRISC, HCISPP, CCSK, ISO 27001 LA/LI, or equivalent).
- Prior experience as a Deputy CISO, Head of GRC, Director of GRC, or Principal GRC Lead preferred.
- Experience supporting highly regulated industries such as financial services or healthcare preferred.
- Demonstrated ability to operate as the accountable GRC leader in enterprise, audit, and regulator-facing environments.
- Extensive hands-on experience leading SOC programs from readiness through audit completion.
- Demonstrated experience managing HIPAA Security Rule compliance.
- Practical working knowledge of GDPR, including data mapping and vendor privacy risk management.
- Deep knowledge of SOC 1, SOC 2, NYDFS Part 500, and third-party risk management.
- Proven ability to independently manage audits, write policies, collect evidence, and respond to auditors and customers.
- Strong understanding of enterprise IT environments, cloud platforms, SaaS architectures, identity, networking, logging, and security controls.
- Exceptional written and verbal communication skills; comfortable interfacing with executives, auditors, regulators, and customers.
- Highly organized with the ability to manage multiple concurrent audits and regulatory obligations.
- Ability to travel as required by business need.
WHY CHOOSE RELATION?
- Competitive pay.
- A safe and healthy work environment provided by our robust benefit program including family health and wellness programs, 401K, employee assistance programs, paid time off, paid holidays and more.
- Career advancement and development opportunities.
.
Note: The above is not all encompassing of the full position description.
Relation Insurance Inc. provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Relation, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is presented within this posting.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
.
$200,000.00 - $250,000.00