... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
Supply Chain Risk Analyst
Huntsville, AL · On-site
Familiarity with supplier risk, third-party risk, or vendor assessment processes Why Exiger: Exiger is transforming how governments understand and manage supply chain risk. In this role, you will ...
Supply Chain Risk Analyst
Huntsville, AL · On-site
Familiarity with supplier risk, third-party risk, or vendor assessment processes Why Exiger: Exiger is transforming how governments understand and manage supply chain risk. In this role, you will ...
Risk Management About Everest: Everest is a global leader in risk management, rooted in a rich, 50 ... management. Large transactions, underwriting growth initiatives, retrocession and 3rd party capital:
Risk Management About Everest: Everest is a global leader in risk management, rooted in a rich, 50 ... management. Large transactions, underwriting growth initiatives, retrocession and 3rd party capital:
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Manager - ServiceNow
Birmingham, AL · On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Manager - ServiceNow
Birmingham, AL · On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Manager - ServiceNow
Huntsville, AL · On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Manager - ServiceNow
Huntsville, AL · On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
The CISO will guide governance, threat protection, incident response, third-party risk, data privacy, and collaboration with Technology, Legal, and Compliance to protect critical assets and support ...
New
The CISO will guide governance, threat protection, incident response, third-party risk, data privacy, and collaboration with Technology, Legal, and Compliance to protect critical assets and support ...
New
LOB Risk Lead
Birmingham, AL · On-site
Cybersecurity Infrastructure availability Cloud services Identity and Access Management Data protection Artificial Intelligence Third-Party Technology Risk Executive Risk Reporting Produces executive ...
LOB Risk Lead
Birmingham, AL · On-site
Cybersecurity Infrastructure availability Cloud services Identity and Access Management Data protection Artificial Intelligence Third-Party Technology Risk Executive Risk Reporting Produces executive ...
Provide independent challenge for change risk (new/changed products, processes, technology) including Third-Party Risk Management assessments. * Coach and advise first line associates on operational ...
Provide independent challenge for change risk (new/changed products, processes, technology) including Third-Party Risk Management assessments. * Coach and advise first line associates on operational ...
Supports the Bank's third-party cybersecurity risk management program across the vendor lifecycle: * Due diligence and onboarding * Ongoing monitoring * Issue Identification and remediation * Works ...
Supports the Bank's third-party cybersecurity risk management program across the vendor lifecycle: * Due diligence and onboarding * Ongoing monitoring * Issue Identification and remediation * Works ...
... Management · Data protection · Artificial Intelligence · Third-Party Technology Risk Executive Risk Reporting · Produces executive-level insights that translate technical risk into business ...
... Management · Data protection · Artificial Intelligence · Third-Party Technology Risk Executive Risk Reporting · Produces executive-level insights that translate technical risk into business ...
Supports the Bank's third-party cybersecurity risk management program across the vendor lifecycle: * Due diligence and onboarding * Ongoing monitoring * Issue Identification and remediation * Works ...
New
Supports the Bank's third-party cybersecurity risk management program across the vendor lifecycle: * Due diligence and onboarding * Ongoing monitoring * Issue Identification and remediation * Works ...
New
Familiarity with supplier risk, third-party risk, or vendor assessment processes Why Exiger: Exiger is transforming how governments understand and manage supply chain risk. In this role, you will ...
Familiarity with supplier risk, third-party risk, or vendor assessment processes Why Exiger: Exiger is transforming how governments understand and manage supply chain risk. In this role, you will ...
Internal Audit Manager
Huntsville, AL · On-site
$120K - $170K/yr
Experience with third-party risk management programs. * Working knowledge of IT General Controls (ITGCs). * Experience supporting or auditing ERP implementations. * SAP experience strongly preferred.
Quick apply
Internal Audit Manager
Huntsville, AL · On-site
$120K - $170K/yr
Experience with third-party risk management programs. * Working knowledge of IT General Controls (ITGCs). * Experience supporting or auditing ERP implementations. * SAP experience strongly preferred.
Job Summary The Risk Management Coordinator 1 position will provide support, training, and ... third party liability claims, and property loss within the Hackbarth Delivery Service's departments.
Job Summary The Risk Management Coordinator 1 position will provide support, training, and ... third party liability claims, and property loss within the Hackbarth Delivery Service's departments.
Job Summary The Risk Management Coordinator 1 position will provide support, training, and ... third party liability claims, and property loss within the Hackbarth Delivery Service's departments.
Quick apply
Job Summary The Risk Management Coordinator 1 position will provide support, training, and ... third party liability claims, and property loss within the Hackbarth Delivery Service's departments.
Third Party Risk Management information
See Alabama salary details
$46.7K - $56.4K
4% of jobs
$56.4K - $66.2K
6% of jobs
$66.2K - $76K
11% of jobs
$79.6K is the 25th percentile. Wages below this are outliers.
$76K - $85.7K
11% of jobs
The median wage is $93.5K / yr.
$85.7K - $95.5K
23% of jobs
$95.5K - $105.3K
13% of jobs
$111.7K is the 75th percentile. Wages above this are outliers.
$105.3K - $115K
12% of jobs
$115K - $124.8K
8% of jobs
$124.8K - $134.6K
6% of jobs
$134.6K - $144.3K
4% of jobs
$144.3K - $154.1K
2% of jobs
$46.7K
$101.1K
$154.1K
How much do third party risk management jobs pay per year?
What is a third party risk management?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What are some common challenges faced in a third party risk management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in third party risk management, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.

Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
Consultant, ServiceNow
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an evolving threat landscape. Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Consultant, Strategy & Transformation on the Cyber Strategy & Transformation team, you will be responsible for...
- Supporting requirements workshops and stakeholder interviews to capture, validate, and document business requirements, user stories, and current-state and future-state process flows
- Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and automation across IT Operations Management, IT Asset Management, Integrated Risk Management, Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases
- Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service level agreements, dashboards, reports, roles, and access controls
- Supporting documentation of data models, taxonomies, workflows, controls, and reporting requirements for cyber, risk, and artificial intelligence governance use cases
- Producing project artifacts, including requirements documentation, functional designs, test scenarios, training materials, release notes, and deployment support materials
- Collaborating with client stakeholders, functional teams, and technical teams to support demonstrations, user acceptance testing, defect triage, training, cutover activities, and solution adoption
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
Qualifications
Required:
- Bachelor's degree in Computer Science, Information Systems, Cyber Security, Engineering, Information Technology, Finance, or Business
- 2+ years of experience supporting ServiceNow implementation projects in a client-facing consulting role
- 2+ years of experience gathering business requirements, facilitating workshops, documenting process flows or user stories, and producing functional documentation
- 2+ years of experience designing, configuring, or implementing ServiceNow solutions in one or more of the following modules: IT Operations Management, IT Asset Management, Integrated Risk Management, Security Operations, or Third-Party Risk Management
- 2+ years of experience configuring ServiceNow forms, workflows, notifications, service level agreements, reports, dashboards, roles, or access controls
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- ServiceNow Certified System Administrator (CSA)
- ServiceNow Certified Application Developer (CAD)
- ArchX (Architecture Excellence)
- One or more ServiceNow Certified Implementation Specialist (CIS) certifications, including CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS-Vulnerability Response (CIS-VR), CIS-Third-Party Risk Management (CIS-TPRM), CIS-Hardware Asset Management (CIS-HAM), CIS-Software Asset Management (CIS-SAM), CIS-Service Mapping (CIS-SM), CIS-Discovery (CIS-DISCO), CIS-Event Management (CIS-EM), CIS-Data Foundations (CIS-DF), or CIS-Strategic Portfolio Management (CIS-SPM)
- Experience supporting implementation and configuration of ServiceNow AI Control Tower capabilities, including AI inventory management, intake and approval workflows, lifecycle oversight, issue management, dashboards, and reporting
- Experience supporting identity governance for human and non-human actors using Veza, or cyber asset discovery and configuration management database (CMDB) integration using Armis
For individuals assigned and/or hired to work in a Remote role, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to a Remote role and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Consultant, ServiceNow
Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions that help clients navigate an evolving threat landscape. Through solutions and managed services that simplify complexity, we help clients operate with resilience, grow with confidence, and proactively manage cyber, risk, and technology programs.
Recruiting for this role ends on 12/31/2026.
Work you'll do
As a Consultant, Strategy & Transformation on the Cyber Strategy & Transformation team, you will be responsible for...
- Supporting requirements workshops and stakeholder interviews to capture, validate, and document business requirements, user stories, and current-state and future-state process flows
- Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and automation across IT Operations Management, IT Asset Management, Integrated Risk Management, Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases
- Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service level agreements, dashboards, reports, roles, and access controls
- Supporting documentation of data models, taxonomies, workflows, controls, and reporting requirements for cyber, risk, and artificial intelligence governance use cases
- Producing project artifacts, including requirements documentation, functional designs, test scenarios, training materials, release notes, and deployment support materials
- Collaborating with client stakeholders, functional teams, and technical teams to support demonstrations, user acceptance testing, defect triage, training, cutover activities, and solution adoption
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Our Cyber Strategy & Transformation offering develops and transforms cyber programs in line with a client's strategic objectives, regulatory requirements, and risk appetite. It keeps the enterprise a step ahead of the evolving threat landscape and gives stakeholders confidence in the organization's cyber posture. Includes design of the cyber organization, governance, and risk assessments.
Qualifications
Required:
- Bachelor's degree in Computer Science, Information Systems, Cyber Security, Engineering, Information Technology, Finance, or Business
- 2+ years of experience supporting ServiceNow implementation projects in a client-facing consulting role
- 2+ years of experience gathering business requirements, facilitating workshops, documenting process flows or user stories, and producing functional documentation
- 2+ years of experience designing, configuring, or implementing ServiceNow solutions in one or more of the following modules: IT Operations Management, IT Asset Management, Integrated Risk Management, Security Operations, or Third-Party Risk Management
- 2+ years of experience configuring ServiceNow forms, workflows, notifications, service level agreements, reports, dashboards, roles, or access controls
- Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
- Limited immigration sponsorship may be available.
Preferred:
- ServiceNow Certified System Administrator (CSA)
- ServiceNow Certified Application Developer (CAD)
- ArchX (Architecture Excellence)
- One or more ServiceNow Certified Implementation Specialist (CIS) certifications, including CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS-Vulnerability Response (CIS-VR), CIS-Third-Party Risk Management (CIS-TPRM), CIS-Hardware Asset Management (CIS-HAM), CIS-Software Asset Management (CIS-SAM), CIS-Service Mapping (CIS-SM), CIS-Discovery (CIS-DISCO), CIS-Event Management (CIS-EM), CIS-Data Foundations (CIS-DF), or CIS-Strategic Portfolio Management (CIS-SPM)
- Experience supporting implementation and configuration of ServiceNow AI Control Tower capabilities, including AI inventory management, intake and approval workflows, lifecycle oversight, issue management, dashboards, and reporting
- Experience supporting identity governance for human and non-human actors using Veza, or cyber asset discovery and configuration management database (CMDB) integration using Armis
For individuals assigned and/or hired to work in a Remote role, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to a Remote role and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.