1

Third Party Risk Management Jobs in New York (NOW HIRING)

Senior Fintech Risk Analyst

Manhattan, NY · On-site

$122.72 - $137.50/hr

Risk Team at Lead The Risk team helps Lead innovate responsibly by identifying and managing risk across the business. They own oversight of our strategic third-party partners, risk governance across ...

New

Risk Manager

New York, NY · Hybrid

$140K - $155K/yr

... risk management (ERM) and effective challenge across operational risks such as third-party risk ... fraud and identity theft, operational errors, and business continuity. The team partners closely ...

Showing results 41-60

Third Party Risk Management information

See New York salary details

$56.3K

$122K

$186K

How much do third party risk management jobs pay per year?

As of Aug 20, 2026, the average yearly pay for third party risk management in New York is $122,046.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,500.00 and $141,100.00 per year, depending on experience, location, and employer.

What is a third party risk management?

A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.

What are some common challenges faced in a third party risk management role, and how are they addressed?

One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.

What are the key skills and qualifications needed to thrive in third party risk management, and why are they important?

To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.

Is third party risk management a good career?

Third Party Risk Management is a growing field focused on identifying and mitigating risks associated with external vendors and partners. It requires skills in compliance, cybersecurity, and contract management, often involving certifications like CTPRP or CRISC. The role offers opportunities in various industries with increasing demand due to regulatory requirements and supply chain complexities.

What does a third party risk management do?

A third party risk management professional assesses and monitors risks associated with external vendors, suppliers, and partners to ensure compliance, security, and operational integrity. They conduct risk assessments, develop mitigation strategies, and often use tools like risk management software to protect the organization from potential threats and vulnerabilities.

What are the most commonly searched types of Third Party Risk Management jobs in New York?

The most popular types of Third Party Risk Management jobs in New York are:

What are popular job titles related to Third Party Risk Management jobs in New York?

For Third Party Risk Management jobs in New York, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Management jobs in New York look for?

The top searched job categories for Third Party Risk Management jobs in New York are:

What cities in New York are hiring for Third Party Risk Management jobs?

Cities in New York with the most Third Party Risk Management job openings:

Infographic showing various Third Party Risk Management job openings in New York as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 85% Physical, 3% Hybrid, and 12% Remote job distribution, with an average salary of $122,046 per year, or $58.7 per hour.

Third Party Due Diligence - Monitoring

Mizuho Financial Group Inc.

Manhattan, NY • On-site

$103 - $135/hr

Other

Medical, Dental, Retirement

Re-posted 18 days ago


Job description

Overview

The Mizuho Americas Enterprise Controls Department (ECD) is a 1st Line of Defense risk and control function that delivers enterprise control services across Third Party Services, Business Continuity Planning, and Business Risk and Control Services. The ECD serves as the single point of accountability for enterprise control services within Mizuho Americas and falls under the Mizuho Americas Enterprise Services Division.

The Third Party Risk Management (TPRM) Unit is a 1LoD risk function that provides white‑glove service to business lines and corporate functions, shepherding them through the Third Party Risk Management lifecycle, conducting due diligence directly with third parties, and providing oversight of the TPRM function.

The Third Party Due Diligence (TPDD) Team performs risk‑based evaluations of third‑party service providers across Information Security, Information Technology, Business Continuity Planning, and adjacent domains, and is responsible for ongoing monitoring of third and fourth parties across Cybersecurity, Financial, Compliance, Operational, Geographic, and ESG events using tools including BitSight, Supply Wisdom, and NCFTA intelligence feeds.

Role Summary

The Assistant Vice President of TPDD – Ongoing Monitoring is accountable for the end‑to‑end execution and quality of TPDD's continuous monitoring program for Critical, High, Moderate, Low, and Nominal third and fourth parties. The AVP owns timely identification, triage, escalation, and resolution of monitoring alerts; partners with Third Party Managers (TPMs), Business Approvers, SMEs, Legal, and Compliance to drive remediation; and ensures all monitoring activity is documented in an audit‑ready, regulator‑defensible manner consistent with the MUSO TPRM Policy, Standard, and Procedure.

Responsibilities
  • Own end‑to‑end ongoing monitoring of third and fourth party risks across cybersecurity (BitSight) and enterprise risk domains (Supply Wisdom); review weekly alerts, conduct trend and impact analysis, ransomware and vulnerability assessments, fourth‑party incident reporting, and monthly third‑party and location license and data reconciliation with heat‑map analysis.
  • Perform composite risk‑rating evaluations across Macro‑Economic, Financial, Geo‑Political, Infrastructure, Business, Legal, Security & Compliance, Scalability, and ESG domains; coordinate with Cyber Defense to review NCFTA alerts and identify, assess, and respond to emerging high‑risk cyber threats affecting Mizuho third parties.
  • Serve as the primary point of contact for TPMs, Business Approvers, Legal, Compliance, CISO/Cyber Defense, Data Loss Prevention (DLP), and SME teams to assess the business impact of third and fourth party risk events; document material incidents in Archer; identify and analyze risk issues; drive and track remediation to closure; and Escalate Critical or High‑risk issues to TPDD leadership and TPRM Management.
  • Support monthly concentration and portfolio risk monitoring across third parties (e.g., engagement volume, service locations, contingent workers, and sole‑provider exposure); contribute to quarterly reporting; maintain accurate BitSight portfolios and Supply Wisdom license assignments to ensure all concentration‑risk third parties are continuously monitored as Critical under appropriate license types.
  • Lead and perform due diligence reviews, reassessments, and significant change evaluations in accordance with TPRM policies and procedures; assess inherent risk and control effectiveness across key domains; identify and document due diligence gaps; recommend remediation, risk acceptance, or escalation actions; coordinate Certificate of Insurance validation; and document any gaps.
  • Review Archer KRI reports to identify threshold breaches and overdue activities; assess risk impact; drive remediation with stakeholders; ensure risk acceptances are recorded and tracked; support internal and external audits, regulatory exams, and Federal Banking Agency Report of Examination (ROE) reviews through timely documentation; maintain audit‑ready records, including QA reviews of 10% of Moderate/Low and 100% of Critical/High assessments.
  • Contribute to the enhancement of IRQs, DDQs, monitoring playbooks, KRIs, and reporting processes to improve consistency, efficiency, and audit readiness; remediate data anomalies in Archer and support reconciliations across systems (Archer, SNOW, Supply Wisdom, BitSight); and ensure timely, high‑quality delivery of monitoring activities aligned with TPRM objectives and regulatory requirements.
Qualifications
  • Bachelor’s degree in a relevant field such as Information Security, Cybersecurity, Business Administration, Finance, or Risk Management.
  • 5+ years of experience in third‑party risk management, monitoring, risk assessment, IT audit, or related disciplines within regulated financial services or consulting.
  • Professional certifications strongly preferred (CTPRP, CTPRA, CISA, CRISC, CISSP).
  • Experience with continuous monitoring platforms (BitSight, Supply Wisdom, or equivalent) and GRC tools (Archer or equivalent).
  • Solid knowledge of data analysis, contract review, data privacy, information security, information technology, and Business Continuity Planning (BCP) principles.
  • Strong ability to identify, assess, and articulate risks and vulnerabilities; sound judgment in evaluating control evidence.
  • Advanced Excel, AI and analytical skills; strong attention to detail and accuracy.
  • Proven ability to manage priorities, drive issues to closure, and meet regulatory deadlines.
  • Strong interpersonal, stakeholder‑management, and critical‑thinking skills; ability to collaborate across the 1LoD, 2LoD, Legal, Compliance, and senior management.
  • Excellent written and verbal communication skills; ability to translate technical risks into clear business language for TPMs, Business Approvers, and executive stakeholders.
  • Experience with Shared Assessments (SIG framework) preferred.
  • Familiarity with U.S. regulatory expectations applicable to TPRM (FRB SR 13‑19, OCC Bulletin 2013‑29, NYDFS Part 500, FFIEC guidance) preferred.
Compensation & Benefits

Base salary range: $103,000.00 – $135,000.00. Salary offers are based on qualifications, training, experience, education, certifications, and other market and organizational factors.

Benefits include medical, dental, and 401(k) plans that begin on day one; discretionary bonus eligibility.

Employment Type

Hybrid working program with varying opportunities for remote work depending on role, departmental needs, and local laws. Some roles have greater in‑office requirements that will be communicated during recruitment.

EEO & Legal Information

We are an EEO/AA Employer – M/F/Disability/Veteran. We participate in the E‑Verify program. We maintain a drug‑free workplace and reserve the right to require pre‑ and post‑hire drug testing as permitted by applicable law.

#J-18808-Ljbffr