Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Third Party Risk management encompasses evaluating suppliers across all operational risk domains including: Information, Technology, Operational Resiliency, Processes/Transactions, Models, Reporting ...
Third Party Risk management encompasses evaluating suppliers across all operational risk domains including: Information, Technology, Operational Resiliency, Processes/Transactions, Models, Reporting ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
Project Manager Professional - Onsite
Mclean, VA · On-site
$42.80 - $52.80/hr
This role is focused on third-party risk management within the financial services sector. The selected candidate will work alongside the Governance Advisor to drive the execution of the Enterprise ...
Project Manager Professional - Onsite
Mclean, VA · On-site
$42.80 - $52.80/hr
This role is focused on third-party risk management within the financial services sector. The selected candidate will work alongside the Governance Advisor to drive the execution of the Enterprise ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
The role involves performing detailed supply chain security reviews, analyzing third-party vendor ... risk management approaches against DoD and federal requirements. • Reviews independent audit ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
The role involves performing detailed supply chain security reviews, analyzing third-party vendor ... risk management approaches against DoD and federal requirements. • Reviews independent audit ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
Third Party Risk Management information
See Virginia salary details
$51.1K - $61.7K
4% of jobs
$61.7K - $72.4K
6% of jobs
$72.4K - $83.1K
11% of jobs
$87.1K is the 25th percentile. Wages below this are outliers.
$83.1K - $93.8K
11% of jobs
The median wage is $102.3K / yr.
$93.8K - $104.5K
23% of jobs
$104.5K - $115.1K
13% of jobs
$122.2K is the 75th percentile. Wages above this are outliers.
$115.1K - $125.8K
12% of jobs
$125.8K - $136.5K
8% of jobs
$136.5K - $147.2K
6% of jobs
$147.2K - $157.9K
4% of jobs
$157.9K - $168.5K
2% of jobs
$51.1K
$110.6K
$168.5K
How much do third party risk management jobs pay per year?
What is a Third Party Risk Management job?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What is the highest paying risk management job?
What is the role of a third party Risk Manager?
What is 3rd party risk management?
What are some common challenges faced in a Third Party Risk Management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in the Third Party Risk Management position, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.
Is TPRM a good career?

Full-time
Medical, Life, Retirement, PTO
Posted 6 days ago
Booz Allen Hamilton rating
8.8
Based on 47 frontline employees who took The Breakroom Quiz
9th of 57 rated business consultants
Job description
The Opportunity
Third-party relationships are central to how Booz Allen delivers technology, services, and mission outcomes at scale. As those relationships grow in complexity, so do the risks they can introduce-from compliance and reputational risk to supplier conduct, cybersecurity, privacy, legal, and enterprise risk considerations.
As the Ethics & Compliance Third-Party Risk Lead, you'll play a strategic role in Booz Allen's established enterprise Third-Party Risk Management program, serving as an advisor to Global Supply Chain, business leaders, and cross-functional risk partners. You'll help strengthen an already mature foundation by advancing practical, risk-based processes that support effective third-party due diligence, escalation, monitoring, issue management, and decision-making.
This is a high-impact role for a proven program leader who can bring rigor, curiosity, creativity, strong project and process discipline, and sound analytical judgment to help identify potential risks in an open, collaborative environment where new ideas and solutions are welcomed.
You'll have the opportunity to shape how Booz Allen continues to mature third-party risk governance, build trusted partnerships, and support defensible risk decisions across the third-party lifecycle. Due to the nature of work performed within this facility, U.S. citizenship is required.
What You'll Do
- Lead risk and compliance advisory support for Booz Allen's enterprise Third-Party Risk Management program, enhancing established processes, governance, and controls.
- Oversee third-party risk review areas, including sanctions, restricted parties, anti-bribery and anti-corruption, conflicts of interest, adverse media, reputational risk, and supplier conduct.
- Define and refine ethics, compliance, and related risk requirements across the third-party lifecycle, including intake, risk tiering, due diligence, onboarding, monitoring, reassessment, escalation, and offboarding.
- Serve as a strategic advisor to Global Supply Chain, Procurement, and business stakeholders by identifying, surfacing, and contextualizing compliance, operational, and reputational risks across vendors, subcontractors, business partners, customers, and other third parties.
- Partner with Legal, Security, Compliance, Privacy, Trade, ABAC, Compliance, ESG, Cybersecurity, Enterprise Risk, Internal Audit, and business leaders to support coordinated, risk-informed decisions.
- Define business requirements for third-party risk technology, including workflows, data fields, screening triggers, dashboards, reporting, and issue tracking.
- Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions.
- Develop training, education, and guidance for business teams, and contribute to third-party-facing content that helps stakeholders understand, identify, and manage third-party risk in delivery and business engagements.
- Establish program metrics, SLAs, KPIs, KRIs, and board and senior leadership materials while leading, coaching, and developing a team of 1-3 direct reports.
Join us. The world can't wait.
You Have
- 10+ years of experience in ethics and compliance, third-party risk, supplier risk, enterprise risk, compliance operations, legal, audit, or procurement risk
- Experience leading or improving third-party risk and supplier due diligence programs, including sanctions, anti-corruption, conflicts, adverse media, reputational risk, and supplier conduct
- Experience working across multiple functions, such as Global Supply Chain, Procurement, Legal, Cybersecurity, Privacy, Security, Finance, Enterprise Risk, Internal Audit, or business operations
- Experience turning risk or compliance requirements into clear workflows, controls, procedures, reporting, and practical guidance
- Experience leading complex programs with senior stakeholders, competing priorities, and enterprise visibility
- Bachelor's degree in Business, Supply Chain, Risk Management, Public Policy, Technology, or Legal Studies
Nice If You Have
- Experience in a technology, product, software, SaaS, data, AI, or cyber company
- Experience in government contracting, professional services, defense, national security, regulated industries, or federal customer environments
- Experience with third-party risk platforms, GRC tools, procurement systems, ERP platforms, contract lifecycle systems, supplier master data tools, or compliance screening tools
- Experience improving policies, standards, procedures, playbooks, escalation frameworks, risk acceptance processes, or governance charters
- Experience developing executive dashboards, KPIs, KRIs, issue reporting, remediation tracking, or audit-ready documentation
- Experience developing third-party risk remediation and monitoring plans, including working with Legal or other stakeholders to align risk mitigation steps, contractual protections, follow-up actions, and ongoing oversight
- Experience defining requirements for compliance, risk, procurement, GRC, screening, or third-party risk technology
- Industry certifications in operational risk management, third-party risk management, compliance, audit, or related disciplines
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $125,300.00 to $233,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date.
Identity Statement
As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud.
Candidate AI Usage Policy
AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided.
Work Model
Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings.
- Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility.
- Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility.
- Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
What Booz Allen Hamilton employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Booz Allen Hamilton
Sourced by ZipRecruiter
Booz Allen Hamilton is a leading provider of management and technology consulting services to the US government in defense, intelligence, and civil markets. Headquartered in McLean, Virginia, the firm also serves major corporations, institutions, and not-for-profit organizations. Founded in 1914 by Edwin G. Booz, the company has a long-standing tradition of helping clients achieve success by delivering a wide range of consulting services that include strategic planning, human capital and learning, communication, systems development, and others. The company's mission is to empower people to change the world, and it has a reputation for maintaining the highest standards of integrity and-excellence.
Industry
It services
Company size
10,000+ Employees
Headquarters location
McLean, VA, US
Year founded
1914