Third-Party Risk Management * Take full ownership of the firm's Third-Party Risk Management (TPRM) program, leading both strategy and hands-on execution. Oversee vendor supervision using a risk-based ...
Third-Party Risk Management * Take full ownership of the firm's Third-Party Risk Management (TPRM) program, leading both strategy and hands-on execution. Oversee vendor supervision using a risk-based ...
Third-Party Risk Management * Take full ownership of the firm's Third-Party Risk Management (TPRM) program, leading both strategy and hands-on execution. Oversee vendor supervision using a risk-based ...
Quick apply
Third-Party Risk Management * Take full ownership of the firm's Third-Party Risk Management (TPRM) program, leading both strategy and hands-on execution. Oversee vendor supervision using a risk-based ...
Senior Cybersecurity GRC Analyst
San Jose, CA · On-site
$117K - $151K/yr
This individual will be responsible for managing compliance programs, conducting risk assessments, leading audits, overseeing identity and access governance, and driving third-party risk management ...
Senior Cybersecurity GRC Analyst
San Jose, CA · On-site
$117K - $151K/yr
This individual will be responsible for managing compliance programs, conducting risk assessments, leading audits, overseeing identity and access governance, and driving third-party risk management ...
Be Seen First
Senior Cybersecurity GRC Analyst
San Jose, CA · On-site
$85 - $95/hr
This individual will be responsible for managing compliance programs, conducting risk assessments, leading audits, overseeing identity and access governance, and driving third-party risk management ...
Quick apply
Be Seen First
Senior Cybersecurity GRC Analyst
San Jose, CA · On-site
$85 - $95/hr
This individual will be responsible for managing compliance programs, conducting risk assessments, leading audits, overseeing identity and access governance, and driving third-party risk management ...
GRC Risk Manager
Los Angeles, CA · On-site
... into third-party engagements. * Prepare risk assessment reports to inform risk treatment decisions. * Track and monitor remediation and risk management activities. * Maintain a current and ...
GRC Risk Manager
Los Angeles, CA · On-site
... into third-party engagements. * Prepare risk assessment reports to inform risk treatment decisions. * Track and monitor remediation and risk management activities. * Maintain a current and ...
... into third-party engagements. * Prepare risk assessment reports to inform risk treatment decisions. * Track and monitor remediation and risk management activities. * Maintain a current and ...
... into third-party engagements. * Prepare risk assessment reports to inform risk treatment decisions. * Track and monitor remediation and risk management activities. * Maintain a current and ...
Assess and manages emerging third-party risks, including artificial intelligence risks such as data ... Cyber Governance, Risk & Compliance (Supporting Responsibility) * Support cyber GRC activities ...
Assess and manages emerging third-party risks, including artificial intelligence risks such as data ... Cyber Governance, Risk & Compliance (Supporting Responsibility) * Support cyber GRC activities ...
Assess and manages emerging third-party risks, including artificial intelligence risks such as data ... Cyber Governance, Risk & Compliance (Supporting Responsibility) * Support cyber GRC activities ...
Quick apply
Assess and manages emerging third-party risks, including artificial intelligence risks such as data ... Cyber Governance, Risk & Compliance (Supporting Responsibility) * Support cyber GRC activities ...
Information Security Analsyt
Santa Clara, CA · On-site
Santa Clara, CA Duration: Long Term Duties and Responsibilities Lead or make senior contributions to the selection, deployment, and management of a Third-Party Risk Management (TPRM) platform Lead or ...
Information Security Analsyt
Santa Clara, CA · On-site
Santa Clara, CA Duration: Long Term Duties and Responsibilities Lead or make senior contributions to the selection, deployment, and management of a Third-Party Risk Management (TPRM) platform Lead or ...
Information Security Analsyt
Santa Clara, CA · On-site
Santa Clara, CA Duration: Long Term Duties and Responsibilities Lead or make senior contributions to the selection, deployment, and management of a Third-Party Risk Management (TPRM) platform Lead or ...
Information Security Analsyt
Santa Clara, CA · On-site
Santa Clara, CA Duration: Long Term Duties and Responsibilities Lead or make senior contributions to the selection, deployment, and management of a Third-Party Risk Management (TPRM) platform Lead or ...
Third-Party Risk Management: o Own and maintain Third-Party Risk Management evaluation practices to ensure effective risk management * Policy Management: o Maintain and update information security ...
Third-Party Risk Management: o Own and maintain Third-Party Risk Management evaluation practices to ensure effective risk management * Policy Management: o Maintain and update information security ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Design and operate the firm's third-party risk management program, including vendor tiering, security assessments, and remediation tracking * Manage the firm's response program for client security ...
Design and operate the firm's third-party risk management program, including vendor tiering, security assessments, and remediation tracking * Manage the firm's response program for client security ...
AVP, Risk Management
Vacaville, CA · On-site
Provides strategic oversight of the organization's third-party risk management program, ensuring robust vendor governance and compliance. * Leads enterprise-wide vendor risk assessments, due ...
AVP, Risk Management
Vacaville, CA · On-site
Provides strategic oversight of the organization's third-party risk management program, ensuring robust vendor governance and compliance. * Leads enterprise-wide vendor risk assessments, due ...
Third-Party Risk Management: Perform and document SOC report reviews to ensure critical service providers meet the organization's operational resilience standards and regulatory compliance ...
Third-Party Risk Management: Perform and document SOC report reviews to ensure critical service providers meet the organization's operational resilience standards and regulatory compliance ...
The Director of Risk Management provides leadership and direction for workers' compensation, auto ... Oversee the third-party administrator program and overall department processes * Review significant ...
The Director of Risk Management provides leadership and direction for workers' compensation, auto ... Oversee the third-party administrator program and overall department processes * Review significant ...
Director of Risk Management
Santa Ana, CA · On-site
$140K - $160K/yr
The Director of Risk Management provides leadership and direction for workers' compensation, auto ... Oversee the third-party administrator program and overall department processes * Review significant ...
Director of Risk Management
Santa Ana, CA · On-site
$140K - $160K/yr
The Director of Risk Management provides leadership and direction for workers' compensation, auto ... Oversee the third-party administrator program and overall department processes * Review significant ...
Oversee the third-party administrator program and overall department processes * Review significant ... Bachelor's degree in Risk Management, Business Administration, Finance, Insurance, Occupational ...
Oversee the third-party administrator program and overall department processes * Review significant ... Bachelor's degree in Risk Management, Business Administration, Finance, Insurance, Occupational ...
Build and oversee enterprise programs for data governance, vulnerability management, third-party risk management, and security awareness, ensuring scalable processes and organizational adoption.
Build and oversee enterprise programs for data governance, vulnerability management, third-party risk management, and security awareness, ensuring scalable processes and organizational adoption.
Third Party Risk Management information
See California salary details
$50.8K - $61.5K
4% of jobs
$61.5K - $72.1K
6% of jobs
$72.1K - $82.7K
11% of jobs
$86.7K is the 25th percentile. Wages below this are outliers.
$82.7K - $93.4K
11% of jobs
The median wage is $101.8K / yr.
$93.4K - $104K
23% of jobs
$104K - $114.6K
13% of jobs
$121.6K is the 75th percentile. Wages above this are outliers.
$114.6K - $125.2K
12% of jobs
$125.2K - $135.9K
8% of jobs
$135.9K - $146.5K
6% of jobs
$146.5K - $157.1K
4% of jobs
$157.1K - $167.8K
2% of jobs
$50.8K
$110.1K
$167.8K
How much do third party risk management jobs pay per year?
What is a Third Party Risk Management job?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What is the highest paying risk management job?
What is the role of a third party Risk Manager?
What is 3rd party risk management?
What are some common challenges faced in a Third Party Risk Management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in the Third Party Risk Management position, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.
Is TPRM a good career?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 20 days ago
Job description
The Director of Business Operations holds primary responsibility for managing and executing the firm's operational resilience framework, with full accountability for third-party risk management, incident response planning, business continuity and business operational reporting. This role requires both strategic oversight and hands-on execution. The director will also support key firmwide initiatives and special projects.
The Director, Business Operations establishes firmwide standards, ensuring controls are robust, thoroughly documented, effective, and appropriately tailored to the organization's needs. The position involves ongoing program enhancement by identifying and mitigating emerging threats in advance. Additionally, this role directly implements these standards, including incident triage and crisis response, as necessary.
Note: Considering incidents may occur outside of core working hours, occasional work during weekends and/or holidays may be required.
Third-Party Risk Management
- Take full ownership of the firm's Third-Party Risk Management (TPRM) program, leading both strategy and hands-on execution. Oversee vendor supervision using a risk-based approach, ensuring seamless management throughout the vendor lifecycle-including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.
- Ensure all vendor risk activities comply with internal policies, regulatory requirements (SEC, FINRA), and investor standards.
- Regularly update and maintain TPRM policies, standards and procedures, delivering clear documentation and continuous improvements.
Incident Management
- Lead the execution and ongoing enhancement of the firm's Incident Response Plan. Collaborate closely with legal, compliance, technology and additional internal stakeholders to maintain and update protocols.
- Serve as the primary point of contact for all incident types, coordinating rapid triage, containment, and resolution across teams. Guide the Incident Response Team, including after-hours support, as needed.
- Track, report, and document incidents; conduct thorough reviews and remediation planning post-incident. Perform analytics and root cause analysis to proactively reduce future risk and continually evolve the program to meet emerging threats and business needs.
Business Continuity Planning (BCP)
- Own and drive the Business Continuity Planning program, from policy development and governance to hands-on execution of annual tests and disaster response. Lead BCP committees and engage stakeholders to ensure the program evolves with changing business and regulatory requirements.
- Conduct regular business impact assessments to define suitable recovery goals. Integrate high-risk service providers into BCP testing, maintain comprehensive documentation of outcomes, and deliver remediation where needed.
- Execute BCP plans during disasters, providing after-hours leadership to restore operations promptly and in accordance with established recovery strategies.
Operational Excellence & Reporting
- Continuously review and refine workflows to optimize efficiency. Identify and implement improvement opportunities across operational risk controls.
- Deliver high-quality, insightful reporting-including dashboards, KPI tracking, incident summaries, and vendor risk metrics-to senior leadership and committees.
- Maintain client-ready documentation of operational risk controls; collaborate with the RFP team to address due diligence questionnaires and inquiries. Support internal/external audits, regulatory exams, and investor due diligence processes.
- Partner with Compliance to ensure SEC and FINRA regulatory adherence, actively supporting employee training and awareness initiatives.
- Manage one direct report and oversee vendor resources. Responsible for hiring, coaching and performance management.
- Support divisional and departmental business operational reporting, including Quarterly Business Review (QBRs).
- Support the Head of Transformation on high-priority, firmwide initiatives and special projects.
- Bachelor's degree required (Business, Economics, Information Systems, Risk Management, or related field preferred). Â
- 12+ years of business operations, internal controls, risk management, or compliance experience.
- Experience in real estate, asset management, financial services, or similar industries required.
- Experience as a people manager required.
- Advanced proficiency in Excel (index/match, pivot tables, advanced formulas, analytics).
- Familiarity with risk frameworks (e.g., SOC 2, NIST, ITGC, SOX) is preferred.
- Experience with Prevalent or similar platforms.
- Familiarity with FINRA and SEC compliance frameworks; FINRA S99 is a plus.
- Bachelor's degree required (Business, Economics, Information Systems, Risk Management, or related field preferred). Â
- 12+ years of business operations, internal controls, risk management, or compliance experience.
- Experience in real estate, asset management, financial services, or similar industries required.
- Experience as a people manager required.
- Advanced proficiency in Excel (index/match, pivot tables, advanced formulas, analytics).
- Familiarity with risk frameworks (e.g., SOC 2, NIST, ITGC, SOX) is preferred.
- Experience with Prevalent or similar platforms.
- Familiarity with FINRA and SEC compliance frameworks; FINRA S99 is a plus.
- A variety of Medical, dental, and vision benefit plans
- Health Savings Account with a generous employer contribution
- Company paid life and disability insurance
- 401(k) savings plan, with company match
- Comprehensive paid time off, including: vacation days, 10 designated holidays, sick time, and bereavement leave
- Up to 16 hours of volunteer time off
- Up to 16 weeks of Paid Parental Leave
- Ongoing professional development programs
- Wellness program, including monthly and quarterly prizes
- And more!
About CIM GROUP
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
1,001 - 5,000 Employees
Headquarters location
Los Angeles, CA, US
Year founded
1994