Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
Third-Party Risk & Security Vendor Management * Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers. * Review vendor assessments, SOC reports, penetration ...
IT Risk Director, Technology Risk Management Resiliency & Business Continuity
Atlanta, GA ยท On-site +1
Foster strong collaboration with Enterprise Risk Management, Technology, Information Security, Facilities, Third-Party Risk, and other risk disciplines. Ensure compliance with applicable regulatory ...
IT Risk Director, Technology Risk Management Resiliency & Business Continuity
Atlanta, GA ยท On-site +1
Foster strong collaboration with Enterprise Risk Management, Technology, Information Security, Facilities, Third-Party Risk, and other risk disciplines. Ensure compliance with applicable regulatory ...
... management, compliance, and control programs. Reporting to the Sr. Director of IT Governance, Risk ... data protection, third-party risk, artificial intelligence, and regulatory compliance.
... management, compliance, and control programs. Reporting to the Sr. Director of IT Governance, Risk ... data protection, third-party risk, artificial intelligence, and regulatory compliance.
Director, Sales Engineering
Atlanta, GA ยท On-site
Stay current with evolving cyber threats, third-party risk management trends, and the competitive landscape in the threat intelligence space. Required Skills * 8+ years of experience in Sales ...
Director, Sales Engineering
Atlanta, GA ยท On-site
Stay current with evolving cyber threats, third-party risk management trends, and the competitive landscape in the threat intelligence space. Required Skills * 8+ years of experience in Sales ...
Aravo Solutions, Inc., provides leading third-party risk management (TPRM), ESG, and vendor lifecycle management solutions powered by intelligent automation software and designed to meet the needs of ...
Aravo Solutions, Inc., provides leading third-party risk management (TPRM), ESG, and vendor lifecycle management solutions powered by intelligent automation software and designed to meet the needs of ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
Cyber ServiceNow - Consultant
Atlanta, GA ยท Remote
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
Cyber ServiceNow - Consultant
Atlanta, GA ยท Remote
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
Cyber ServiceNow - Consultant
Atlanta, GA ยท On-site
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
Cyber ServiceNow - Consultant
Atlanta, GA ยท On-site
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...
They are seeking a Staff Product Manager, AI Governance & Supply Chain Integration Risk to lead product strategy and execution, focusing on reducing risk across SaaS and third-party ecosystems.
They are seeking a Staff Product Manager, AI Governance & Supply Chain Integration Risk to lead product strategy and execution, focusing on reducing risk across SaaS and third-party ecosystems.
Identify the most important customer problems related to SaaS supply chain risk, third-party access ... Required qualifications * 7+ years of Product Management experience, ideally in B2B SaaS ...
Quick apply
Identify the most important customer problems related to SaaS supply chain risk, third-party access ... Required qualifications * 7+ years of Product Management experience, ideally in B2B SaaS ...
Vendor Analyst, AI & Technology Risk
Atlanta, GA ยท Hybrid
$85K - $110K/yr
Support Vendor Management in aligning with third-party risk requirements AI Governance Operations * Support execution of AI intake and governance workflows: * Track AIA Forms and FactSheets * Ensure ...
Vendor Analyst, AI & Technology Risk
Atlanta, GA ยท Hybrid
$85K - $110K/yr
Support Vendor Management in aligning with third-party risk requirements AI Governance Operations * Support execution of AI intake and governance workflows: * Track AIA Forms and FactSheets * Ensure ...
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Manager - ServiceNow
Atlanta, GA ยท On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Manager - ServiceNow
Atlanta, GA ยท On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Cybersecurity Automation Engineer
Atlanta, GA ยท On-site
Third-Party Risk Alerting * - Build alerting logic for vendor-related threats including vendor breaches, risk score degradation, SaaS abuse, and exposure of vendor-managed assets. * - Correlate ...
Cybersecurity Automation Engineer
Atlanta, GA ยท On-site
Third-Party Risk Alerting * - Build alerting logic for vendor-related threats including vendor breaches, risk score degradation, SaaS abuse, and exposure of vendor-managed assets. * - Correlate ...
Manager - ServiceNow
Atlanta, GA ยท On-site
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Manager - ServiceNow
Atlanta, GA ยท On-site
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
... topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk ... management, with a focus on cyber risk quantification, or an equal amount of time as product ...
... topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk ... management, with a focus on cyber risk quantification, or an equal amount of time as product ...
Procurement Contract Services Negotiator / Senior Contract Analyst
Atlanta, GA ยท Hybrid
$66K - $80K/yr
Third-Party Risk Management (TPRM) experience * Knowledge of contract lifecycle management (CLM) tools and sourcing processes Preferred Skills & Experience * Strong analytical, problem-solving, and ...
Procurement Contract Services Negotiator / Senior Contract Analyst
Atlanta, GA ยท Hybrid
$66K - $80K/yr
Third-Party Risk Management (TPRM) experience * Knowledge of contract lifecycle management (CLM) tools and sourcing processes Preferred Skills & Experience * Strong analytical, problem-solving, and ...
Director of Product Management
Atlanta, GA ยท Hybrid
$224K - $234K/yr
Why this role Evident runs the largest verified business network in third-party risk management ... millions of entities, hundreds of enterprise customers, and a product that's already the category ...
Quick apply
Director of Product Management
Atlanta, GA ยท Hybrid
$224K - $234K/yr
Why this role Evident runs the largest verified business network in third-party risk management ... millions of entities, hundreds of enterprise customers, and a product that's already the category ...
Third Party Risk Management information
See Georgia salary details
$43.5K - $52.6K
4% of jobs
$52.6K - $61.7K
6% of jobs
$61.7K - $70.8K
11% of jobs
$74.2K is the 25th percentile. Wages below this are outliers.
$70.8K - $79.9K
11% of jobs
The median wage is $87.1K / yr.
$79.9K - $89K
23% of jobs
$89K - $98.1K
13% of jobs
$104.1K is the 75th percentile. Wages above this are outliers.
$98.1K - $107.2K
12% of jobs
$107.2K - $116.3K
8% of jobs
$116.3K - $125.4K
6% of jobs
$125.4K - $134.4K
4% of jobs
$134.4K - $143.5K
2% of jobs
$43.5K
$94.2K
$143.5K
How much do third party risk management jobs pay per year?
What is a third party risk management?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What are some common challenges faced in a third party risk management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in third party risk management, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.

Senior Manager - Cybersecurity & Governance, Risk & Compliance (GRC)
Atlanta, GA โข On-site
Other
Re-posted 28 days ago
Job description
At FORTNA, we believe in fostering a workplace that isn't just a job but a movement - a collective effort to redefine success and transform challenges into opportunities. "Join the Movement" encapsulates our commitment to a workplace culture that thrives on collaboration, celebrates diversity, and empowers every individual to contribute to something greater than themselves. Our Team. Our Passion. Our Approach.
Position Summary
We are seeking an experienced Senior Manager, Cybersecurity & Governance, Risk & Compliance (GRC) to lead and mature our enterprise cybersecurity governance, risk management, compliance, and security assurance programs. This role is responsible for ensuring cybersecurity risks are effectively identified, managed, and communicated while maintaining compliance with regulatory requirements and industry security frameworks.
The Senior Manager will partner closely with Security Operations, IT, Legal, Privacy, Internal Audit, business leaders, and third-party providers to strengthen the organization's security posture, drive risk-based decision-making, and support business objectives. This position combines strategic leadership with operational oversight across governance, compliance, risk management, incident management, and vendor security programs.
Key Responsibilities
Governance & Cybersecurity Strategy
- Lead the enterprise cybersecurity governance framework, including policies, standards, controls, and procedures.
- Drive cybersecurity strategy and roadmap initiatives aligned with business goals and risk tolerance.
- Provide leadership with visibility into cybersecurity posture, risks, compliance status, and program effectiveness.
- Lead governance committees and facilitate cross-functional cybersecurity initiatives.
- Conduct enterprise cybersecurity risk assessments and oversee risk treatment activities.
- Maintain the cybersecurity risk register and monitor remediation efforts.
- Evaluate emerging threats, vulnerabilities, and business impacts.
- Perform security reviews for new technologies, projects, and strategic initiatives.
- Lead third-party and vendor security risk assessments and due diligence activities.
- Manage cybersecurity compliance programs aligned with frameworks and regulations.
- Coordinate internal and external audits and oversee remediation of audit findings.
- Ensure security controls, documentation, and evidence repositories support ongoing compliance requirements.
- Monitor and report compliance performance and remediation progress.
- Partner with Security Operations teams and external providers to strengthen monitoring, threat detection, incident response, and vulnerability management programs.
- Review significant cybersecurity incidents, root cause analyses, and corrective action plans.
- Participate in incident response exercises, tabletop simulations, and post-incident reviews.
- Drive continuous improvement of security controls, detection capabilities, and response processes.
- Monitor security metrics, KPIs, KRIs, and operational reporting.
- Manage relationships with MDR, MSSP, SOC-as-a-Service, and other cybersecurity service providers.
- Review vendor assessments, SOC reports, penetration test results, and compliance documentation.
- Ensure third-party providers meet security, compliance, and contractual obligations.
- Lead vendor risk remediation and ongoing security performance reviews.
- Lead and mentor cybersecurity governance, risk, and compliance professionals.
- Partner with IT, Security, Legal, Privacy, HR, Audit, and business leaders to address cybersecurity risks and compliance requirements.
- Present cybersecurity risks, compliance status, audit results, and strategic recommendations to senior leadership and governance committees.
- Serve as a trusted advisor on cybersecurity governance, risk management, and regulatory compliance.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- 12+ years of experience in cybersecurity, information security, risk management, compliance, audit, or security operations.
- 3+ years of leadership or people management experience.
- Experience supporting or partnering with Security Operations (SOC) teams and incident response programs.
- Strong knowledge of cybersecurity frameworks, governance models, and risk management methodologies.
- Experience leading compliance initiatives, audits, and remediation programs.
- Experience managing third-party security assessments and vendor risk programs.
- Strong executive communication, stakeholder management, and presentation skills.
- Experience with Microsoft security and compliance technologies, including Microsoft Purview and Microsoft Sentinel.
- Experience working with SIEM, SOAR, EDR, MDR, vulnerability management, and GRC platforms.
- Experience within regulated or compliance-driven industries.
- Master's degree in a related discipline.
The base salary range for this role is $133,200 to $199,800. This base salary range represents the low and high end of the base salary range for this position. Actual base salary offered will vary based on various factors including but not limited to location, level, job-related knowledge, skills, experience, and performance.
This job description describes the general nature and level of work expected of a person assigned to this position. All job requirements listed indicate the minimum level of knowledge, skills and/or ability deemed necessary to perform the job proficiently. Employees may be required to perform any other job-related duties as requested by their supervisor.
It is the policy of FORTNA and its affiliated companies to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, pregnancy or pregnancy-related condition, status with regard to public assistance, veteran status, citizenship status (if authorized to work in the U.S.), or any other characteristic protected by federal, state or local law. In addition, FORTNA will provide reasonable accommodations for qualified individuals with disabilities.