Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 ...
Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 ...
Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 ...
Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 ...
Vendor Management and Renewals Lead
Boston, MA ยท On-site
$170K - $190K/yr
Apply vendor governance and third party risk management principles to how we manage our own customer commercial relationships. * Improve renewal forecasting, reporting, and operational processes ...
Quick apply
Vendor Management and Renewals Lead
Boston, MA ยท On-site
$170K - $190K/yr
Apply vendor governance and third party risk management principles to how we manage our own customer commercial relationships. * Improve renewal forecasting, reporting, and operational processes ...
Vendor Management and Renewals Lead
Boston, MA ยท On-site
$170K - $190K/yr
Apply vendor governance and third party risk management principles to how we manage our own customer commercial relationships. * Improve renewal forecasting, reporting, and operational processes ...
Vendor Management and Renewals Lead
Boston, MA ยท On-site
$170K - $190K/yr
Apply vendor governance and third party risk management principles to how we manage our own customer commercial relationships. * Improve renewal forecasting, reporting, and operational processes ...
Identify the most important customer problems related to SaaS supply chain risk, third-party access ... Required qualifications * 7+ years of Product Management experience, ideally in B2B SaaS ...
Quick apply
Identify the most important customer problems related to SaaS supply chain risk, third-party access ... Required qualifications * 7+ years of Product Management experience, ideally in B2B SaaS ...
Vendor Management and Renewals Lead
Boston, MA ยท On-site
$170K - $190K/yr
Apply vendor governance and third party risk management principles to how we manage our own customer commercial relationships. * Improve renewal forecasting, reporting, and operational processes ...
Vendor Management and Renewals Lead
Boston, MA ยท On-site
$170K - $190K/yr
Apply vendor governance and third party risk management principles to how we manage our own customer commercial relationships. * Improve renewal forecasting, reporting, and operational processes ...
Manage strategic relationships with application vendors and third-party providers, including contract administration, service-level performance, due diligence, and third-party risk management. Lead ...
Manage strategic relationships with application vendors and third-party providers, including contract administration, service-level performance, due diligence, and third-party risk management. Lead ...
VP, Enterprise Applications & Banking Systems Director
Newburyport, MA ยท On-site
$118K - $172K/yr
Manage strategic relationships with application vendors and third-party providers, including contract administration, service-level performance, due diligence, and third-party risk management. Lead ...
Quick apply
VP, Enterprise Applications & Banking Systems Director
Newburyport, MA ยท On-site
$118K - $172K/yr
Manage strategic relationships with application vendors and third-party providers, including contract administration, service-level performance, due diligence, and third-party risk management. Lead ...
Senior Customer Marketing Manager
Concord, MA ยท On-site
$105K - $140K/yr
About ProcessUnity ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that ...
Senior Customer Marketing Manager
Concord, MA ยท On-site
$105K - $140K/yr
About ProcessUnity ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that ...
Senior Customer Marketing Manager
Concord, MA ยท On-site
$120 - $160/hr
ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their ...
Senior Customer Marketing Manager
Concord, MA ยท On-site
$120 - $160/hr
ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their ...
Senior Customer Marketing Manager
Concord, MA ยท On-site
$120 - $160/hr
ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their ...
Senior Customer Marketing Manager
Concord, MA ยท On-site
$120 - $160/hr
ProcessUnity is the Third-Party Risk Management (TPRM) company. Our software platforms and data services protect customers from cybersecurity threats, breaches, and outages that originate from their ...
Compliance & Risk Manager (On-site/Hybrid/Remote)
Chicopee, MA ยท On-site
$74K - $145K/yr
Coordinate enterprise risk management activities, including business continuity planning, disaster recovery, cybersecurity readiness, and third-party risk management. * Collaborate with IT on ...
Quick apply
Compliance & Risk Manager (On-site/Hybrid/Remote)
Chicopee, MA ยท On-site
$74K - $145K/yr
Coordinate enterprise risk management activities, including business continuity planning, disaster recovery, cybersecurity readiness, and third-party risk management. * Collaborate with IT on ...
Staff Vendor Relations Manager
Marlborough, MA ยท Hybrid
$116K - $140K/yr
You will work closely with business leaders, Risk Management, Legal, Compliance, Information Security, and Procurement teams to ensure effective third-party oversight and alignment with ...
Staff Vendor Relations Manager
Marlborough, MA ยท Hybrid
$116K - $140K/yr
You will work closely with business leaders, Risk Management, Legal, Compliance, Information Security, and Procurement teams to ensure effective third-party oversight and alignment with ...
This leader ensures that the processes, platforms, controls, data, and analytics supporting sourcing, contracting, third-party risk management, supplier onboarding, buying channels, and procure-to ...
This leader ensures that the processes, platforms, controls, data, and analytics supporting sourcing, contracting, third-party risk management, supplier onboarding, buying channels, and procure-to ...
Enterprise Risk Management provides independent risk oversight over State Street's business ... Third-Party, Fraud, Reporting, Human Capital, Legal and Strategic risks. In this role, you will ...
Enterprise Risk Management provides independent risk oversight over State Street's business ... Third-Party, Fraud, Reporting, Human Capital, Legal and Strategic risks. In this role, you will ...
Enterprise Risk Management provides independent risk oversight over State Street's business ... Third-Party, Fraud, Reporting, Human Capital, Legal and Strategic risks. In this role, you will ...
Enterprise Risk Management provides independent risk oversight over State Street's business ... Third-Party, Fraud, Reporting, Human Capital, Legal and Strategic risks. In this role, you will ...
Manager - ServiceNow
Boston, MA ยท On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Manager - ServiceNow
Boston, MA ยท On-site +1
... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...
Senior Security Compliance Analyst
$140K - $180K/yr
You will own risk management initiatives-including third-party risk, control testing, and audit readiness-while ensuring the organization is prepared for certifications and regulatory requirements.
Senior Security Compliance Analyst
$140K - $180K/yr
You will own risk management initiatives-including third-party risk, control testing, and audit readiness-while ensuring the organization is prepared for certifications and regulatory requirements.
Corporate Auditor
Boston, MA ยท Hybrid
This includes audit coverage across Global Accounting Operations, Controllership, Regulatory Reporting, Procurement, Third-Party Risk Management, Corporate Tax, Corporate Strategy, and Investor ...
Corporate Auditor
Boston, MA ยท Hybrid
This includes audit coverage across Global Accounting Operations, Controllership, Regulatory Reporting, Procurement, Third-Party Risk Management, Corporate Tax, Corporate Strategy, and Investor ...
Business / Operational Audit, Officer
Boston, MA ยท On-site
$65K - $113K/yr
This includes audit coverage across Global Accounting Operations, Controllership, Regulatory Reporting, Procurement, Third-Party Risk Management, Corporate Tax, Corporate Strategy, and Investor ...
Business / Operational Audit, Officer
Boston, MA ยท On-site
$65K - $113K/yr
This includes audit coverage across Global Accounting Operations, Controllership, Regulatory Reporting, Procurement, Third-Party Risk Management, Corporate Tax, Corporate Strategy, and Investor ...
Third Party Risk Management information
See Massachusetts salary details
$56.2K - $68K
4% of jobs
$68K - $79.8K
6% of jobs
$79.8K - $91.5K
11% of jobs
$96K is the 25th percentile. Wages below this are outliers.
$91.5K - $103.3K
11% of jobs
The median wage is $112.7K / yr.
$103.3K - $115.1K
23% of jobs
$115.1K - $126.8K
13% of jobs
$134.6K is the 75th percentile. Wages above this are outliers.
$126.8K - $138.6K
12% of jobs
$138.6K - $150.4K
8% of jobs
$150.4K - $162.1K
6% of jobs
$162.1K - $173.9K
4% of jobs
$173.9K - $185.7K
2% of jobs
$56.2K
$121.8K
$185.7K
How much do third party risk management jobs pay per year?
What is a third party risk management?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What are some common challenges faced in a third party risk management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in third party risk management, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.
Is third party risk management a good career?
What does a third party risk management do?
What are the most commonly searched types of Third Party Risk Management jobs in Massachusetts?
The most popular types of Third Party Risk Management jobs in Massachusetts are:
What are popular job titles related to Third Party Risk Management jobs in Massachusetts?
For Third Party Risk Management jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Management jobs in Massachusetts look for?
The top searched job categories for Third Party Risk Management jobs in Massachusetts are:
What cities in Massachusetts are hiring for Third Party Risk Management jobs?
Cities in Massachusetts with the most Third Party Risk Management job openings:

Job description
An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.
The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.
About the role:
The Lead Security Governance & Risk Engineer is a senior, hands-on role at the point where security governance meets risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives Klaviyo a continuously updated, quantified view of its risk posture.
You will work alongside the Trust and Compliance team who are the custodians of our security policies and standards, making sure each one connects to a specific risk it reduces and is enforced through operational controls rather than living as a document. You will partner closely with Engineering, Product, GTS, Legal, Internal Audit, the ARIA team, and Finance to make risk legible across the business, and you will challenge first-line teams credibly while keeping your independence. This is a role for an engineer who thinks like a risk professional: someone who automates repeatable assessment, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure rather than an afterthought.
How you'll have an impact:
- Operate and maintain the risk register and taxonomy. Run the technology and third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.
- Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.
- Drive third-party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
- Perform the hands-on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels.
- Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision-ready risk materials and translating high-severity findings into clear business impact.
- Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first-line teams, apply consistent risk taxonomies and reporting standards, and escalate risks that exceed established tolerance.
- Partner cross-functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
- 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
- Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
- Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.
- Experience building and running a technology and/or third-party risk register and taxonomy, with the tooling and process automation behind it.
- Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
- Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement.
- Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
- Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.
- Proficiency discussing complex, nuanced topics with technical and non-technical audiences alike, and translating technical risk into clear business impact.
- Excellent ability to plan, prioritise, and execute work cross-functionally and on time.
- Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability.
- AI governance, model risk, or responsible-AI programme experience, and ISO 42001 readiness or certification work.
- Experience building metrics and dashboards (KPIs, KRIs, KCIs) using business intelligence or dashboarding tools like Tableau and so on.
- Experience in a regulated or high-trust environment (SOC 2, ISO 27000 series, ISO 42001, HIPAA, GDPR).
- Threat modeling or secure design reviews, and experience designing or implementing technical security controls in AWS.
- Experience securing web applications, Kubernetes clusters, and/or containers.
- Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, an ISO 42001 / AI governance certification, or Open FAIR.
Massachusetts Applicants:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location.
In addition to base salary, our total compensation package may include participation in the company's annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.
Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.
Base Pay Range For US Locations:
$156,000-$234,000 USD
This role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events. Travel is coordinated in advance.
Get to Know Klaviyo
We're Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology we're developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creators-ambitious and collaborative teammates who stay focused on our north star: delighting our customers. If you're ready to do the best work of your career, where you'll be welcomed as your whole self from day one and supported with generous benefits, we hope you'll join us.
AI fluency at Klaviyo includes responsible use of AI (including privacy, security, bias awareness, and human-in-the-loop). We provide accommodations as needed.
By participating in Klaviyo's interview process, you acknowledge that you have read, understood, and will adhere to our Guidelines for using AI in the Klaviyo interview Process. For more information about how we process your personal data, see our Job Applicant Privacy Notice.
Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law.
IMPORTANT NOTICE: Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses (@klaviyo.com), instant messaging platforms, or unsolicited calls.
By clicking "Submit Application" you consent to Klaviyo processing your Personal Data in accordance with our Job Applicant Privacy Notice. If you do not wish for Klaviyo to process your Personal Data, please do not submit an application. You can find our Job Applicant Privacy Notice here and here (FR).
About Klaviyo
Sourced by ZipRecruiter
Industry
Marketing
Company size
1,001 - 5,000 Employees
Headquarters location
Boston, MA, US
Year founded
2012