1

Third Party Risk Management Jobs in Kentucky (NOW HIRING)

$160K/yr

Third Party Risk Management Lead Professional US 2 days ago Requisition ID: 1286 Salary: $160,000.00 Annually Third Party Risk Management Lead About Sungrow: Sungrow North America is a leading ...

$77K - $127K/yr

The Third-Party Risk Management Program Administrator will support the organization's Third-Party Risk Management (TPRM) program within a regulated banking environment. This mid-level role is ...

New

$110K - $167K/yr

As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle--from tiering and onboarding to ...

As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle--from tiering and onboarding to ...

Department Overview The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald's global third-party cyber risk management capability across a ...

$160K/yr

Working under the direction of the Third-Party Risk Management Lead and in partnership with the Governance, Risk & Compliance (GRC) Manager, this role is responsible for performing vendor security ...

$112K - $236K/yr

Oversee third-party cybersecurity risk management processes including supplier risk evaluations and contractual security requirements. * Coordinate enterprise-wide remediation strategies for ...

$70K - $92K/yr

Run third-party security risk management. Conduct vendor security due diligence and assessments, contract and control reviews, continuous monitoring, and risk reporting. * Lead data protection.

Third-Party Risk Management: Execute established processes to assess, monitor, and manage information security risks associated with third parties, vendors, and other external partners. * Client ...

New

Manage day-to-day relationships with brokers, carriers, third-party administrators, consultants, outside counsel, and other insurance and risk management advisors. * Work with the Company's captive ...

$140K - $190K/yr

Cyber & Technology Risk Management is an independent second-line risk function within Enterprise ... third-party risk, or a related control function. Demonstrated experience assessing cyber risk ...

... includes Third-Party Risk Management as well as senior risk professionals. Trust Risk at Autodesk is an established team and program. We are looking for a leader with the lived experience of ...

$175K - $200K/yr

... Risk Management program and provide executive leadership across operational, regulatory, compliance, cybersecurity, fraud, third-party, reputational, liquidity, and strategic risk. Rather than ...

Support third-party risk management and operational resilience. * Coordinate business continuity planning activities. * Prepare quarterly executive and Board risk reports. * Provide ERM education and ...

Support third-party risk management, including vendor assessments and ongoing monitoring. * Collaborate with cybersecurity and technology teams to align security tooling and monitoring with ...

$185K - $230K/yr

Operational Risk Management and enterprise/CUSO Non-Financial Risk teams, including Technology Risk, Cyber Risk, Data Risk, Fraud Risk, Third Party Risk, and other specialist risk functions.

The Risk Management Specialist supports the Company's insurance, claims, and risk management ... and third-party administrators. This role exercises independent judgment in reviewing claims ...

$163K - $236K/yr

Strong understanding of AI and third-party risk as they relate to AI systems, including ... Bachelor's degree in Risk Management, Information Systems, or a related field required * AI ...

New

$114K - $194K/yr

... third-party risk management; privacy; process change management * Independently manage and/or coordinate: - Business unit risk inventory assessment - advice/review/challenge - including the ...

Departments include Strategic Sourcing, Third Party Risk Management, Procure to Pay, Integrated Travel and Expense and Sustainable Operations. Product & Reporting Manages end-to-end product lifecycle ...

next page

Showing results 1-20

Third Party Risk Management information

See Kentucky salary details

$44.7K

$96.9K

$147.6K

How much do third party risk management jobs pay per year?

As of Sep 14, 2026, the average yearly pay for third party risk management in Kentucky is $96,889.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,200.00 and $112,000.00 per year, depending on experience, location, and employer.

What is a third party risk management?

A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.

What are some common challenges faced in a third party risk management role, and how are they addressed?

One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.

What are the key skills and qualifications needed to thrive in third party risk management, and why are they important?

To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.

Is third party risk management a good career?

Third Party Risk Management is a growing field focused on identifying and mitigating risks associated with external vendors and partners. It requires skills in compliance, cybersecurity, and contract management, often involving certifications like CTPRP or CRISC. The role offers opportunities in various industries with increasing demand due to regulatory requirements and supply chain complexities.

What does a third party risk management do?

A third party risk management professional assesses and monitors risks associated with external vendors, suppliers, and partners to ensure compliance, security, and operational integrity. They conduct risk assessments, develop mitigation strategies, and often use tools like risk management software to protect the organization from potential threats and vulnerabilities.

What are popular job titles related to Third Party Risk Management jobs in Kentucky?

For Third Party Risk Management jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Management jobs in Kentucky look for?

The top searched job categories for Third Party Risk Management jobs in Kentucky are:

Infographic showing various Third Party Risk Management job openings in Kentucky as of September 2026, with employment types broken down into 1% As Needed, 82% Full Time, 13% Part Time, 3% Contract, and 1% Nights. Highlights an 82% Physical, 2% Hybrid, and 16% Remote job distribution, with an average salary of $96,889 per year, or $46.6 per hour.

Third Party Risk Management Lead

On-site

$160K/yr

Other

Posted 24 days ago


Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Third Party Risk Management Lead

Professional US

2 days ago Requisition ID: 1286

Salary: $160,000.00 Annually

Third Party Risk Management Lead

About Sungrow:

Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America is known for its commitment to innovation, high-quality standards, and exceptional customer service, aiming to provide sustainable and reliable energy solutions to meet the growing demand for clean power.

The Position:

Sungrow Americas is seeking a Third Party Risk Management (TPRM) Lead to establish and operate a scalable program for managing vendor, supplier, and third-party risk across the organization.

This role is responsible for ensuring that third-party relationships are assessed, governed, and continuously monitored in alignment with regulatory expectations and customer requirements.

In parallel, this role will support the development of business continuity and resilience capabilities, including Business Impact Analysis (BIA) and foundational BCDR program elements.

This is a program leadership role requiring strong execution, cross-functional influence, and the ability to operate in a regulated, critical infrastructure environment

Key Responsibilities
  • Build and operate the TPRM program lifecycle, including:
    • Vendor intake and risk tiering
    • Security assessments and due diligence
    • Ongoing monitoring and reassessment
  • Define and enforce minimum security requirements for vendors and suppliers
  • Partner with legal and procurement to embed security and risk clauses into contracts
  • Establish processes for exception management and risk acceptance
  • Lead execution of third-party security reviews, including:
    • Questionnaires and evidence validation
    • Review of SOC 2, ISO certifications, and supporting artifacts
  • Identify and communicate material risks and required mitigations
  • Ensure alignment to frameworks (NIST, ISO 27001, SOC 2, NERC CIP where applicable)
  • Implement ongoing monitoring capabilities for vendor risk posture
  • Track and drive remediation of identified third-party risks
  • Maintain visibility into fourth-party and supply chain dependencies where relevant
Business Continuity & Resilience (BCDR/BIA Support)
  • Support development of Business Impact Analysis (BIA) across critical functions
  • Partner with business and IT stakeholders to define:
    • Critical processes
    • Recovery time objectives (RTO) / recovery point objectives (RPO)
  • Contribute to the development of BCDR plans and testing frameworks
  • Ensure third-party dependencies are integrated into continuity planning
Governance, Reporting & Audit Readiness
  • Develop and track TPRM KPIs and risk metrics
  • Provide executive-level reporting on third-party risk posture
  • Maintain documentation and evidence to support:
    • Audits
    • Customer security reviews
    • Regulatory inquiries
  • Ensure program is defensible and repeatable
Cross-Functional Collaboration
  • Partner with:
    • Procurement (vendor onboarding)
    • Legal (contractual protections)
    • IT and engineering (technical validation)
  • Act as the central point of coordination for third-party risk decisions
Requirements
  • 7–10+ years of experience in third-party risk management, GRC, or vendor risk programs
  • Proven experience building or leading a TPRM program in a regulated or enterprise environment
  • Strong understanding of:
    • Vendor risk assessment methodologies
    • Security frameworks (NIST, ISO 27001, SOC 2)
  • Experience reviewing:
    • Security documentation (policies, controls, audit reports)
    • Third-party attestations (SOC 2, ISO certifications)
  • Working knowledge of business continuity and resilience concepts (BIA, BCDR)
  • Ability to drive cross-functional alignment and accountability
Preferred
  • Experience in energy, industrial, or critical infrastructure sectors
  • Familiarity with NERC CIP requirements
  • Experience implementing or operating TPRM platforms/tools
  • Certifications such as CRISC, CISM, CISSP, or CTPRP
  • Program Builder: Can stand up and mature TPRM from structure to scale
  • Risk Translator: Converts vendor risk into business and contractual impact
  • Governance-Oriented: Ensures decisions are documented and defensible
  • Cross-Functional Operator: Effective with procurement, legal, IT, and engineering
  • Pragmatic Enforcer: Balances risk reduction with business enablement
Strategic Fit
  • Establishes control over external risk exposure
  • Strengthens customer trust and regulatory alignment
  • Enables defensible procurement and vendor onboarding decisions
  • Builds foundation for enterprise resilience and continuity planning
Travel

Up to 10%

Work Location and Status:
  • Remote

Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only contact candidates who best meet the requirements. Thank you for your interest in Sungrow.

#J-18808-Ljbffr