Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
Project Manager Professional - Onsite
Mclean, VA · On-site
$42.80 - $52.80/hr
This role is focused on third-party risk management within the financial services sector. The selected candidate will work alongside the Governance Advisor to drive the execution of the Enterprise ...
Project Manager Professional - Onsite
Mclean, VA · On-site
$42.80 - $52.80/hr
This role is focused on third-party risk management within the financial services sector. The selected candidate will work alongside the Governance Advisor to drive the execution of the Enterprise ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
The role involves performing detailed supply chain security reviews, analyzing third-party vendor ... risk management approaches against DoD and federal requirements. • Reviews independent audit ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
The role involves performing detailed supply chain security reviews, analyzing third-party vendor ... risk management approaches against DoD and federal requirements. • Reviews independent audit ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
... in third-party Risk Management * One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager ...
... in third-party Risk Management * One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Collaborate with technical teams to ensure control effectiveness Third-Party Risk Management * Evaluate vendor and third-party cybersecurity risks * Conduct security assessments and due diligence ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Collaborate with technical teams to ensure control effectiveness Third-Party Risk Management * Evaluate vendor and third-party cybersecurity risks * Conduct security assessments and due diligence ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
... Third-Party Risk Management Evaluate vendor and third-party cybersecurity risks Conduct security assessments and due diligence reviews Ensure contractual security and compliance requirements are met ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
... Third-Party Risk Management Evaluate vendor and third-party cybersecurity risks Conduct security assessments and due diligence reviews Ensure contractual security and compliance requirements are met ...
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
... third-party risk management, cloud security, incident readiness, and managed risk services. * Identify and qualify high-value expansion opportunities by analyzing client risk maturity, cyber program ...
New
... third-party risk management, cloud security, incident readiness, and managed risk services. * Identify and qualify high-value expansion opportunities by analyzing client risk maturity, cyber program ...
New
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
... in third-party Risk Management * One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager ...
... in third-party Risk Management * One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager ...
Third Party Risk Management information
See Reston, VA salary details
$53.6K - $64.8K
4% of jobs
$64.8K - $76K
6% of jobs
$76K - $87.2K
11% of jobs
$91.4K is the 25th percentile. Wages below this are outliers.
$87.2K - $98.4K
11% of jobs
The median wage is $107.3K / yr.
$98.4K - $109.6K
23% of jobs
$109.6K - $120.8K
13% of jobs
$128.2K is the 75th percentile. Wages above this are outliers.
$120.8K - $132K
12% of jobs
$132K - $143.2K
8% of jobs
$143.2K - $154.4K
6% of jobs
$154.4K - $165.7K
4% of jobs
$165.7K - $176.9K
2% of jobs
$53.6K
$116.1K
$176.9K
How much do third party risk management jobs pay per year?
What is a Third Party Risk Management job?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What is the highest paying risk management job?
What is the role of a third party Risk Manager?
What is 3rd party risk management?
What are some common challenges faced in a Third Party Risk Management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in the Third Party Risk Management position, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.
Is TPRM a good career?
S&P Global rating
8.1
Based on 6 frontline employees who took The Breakroom Quiz
Job description
The Role:
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management.
Reporting to the Global Head of Procurement, the Procurement Risk & Compliance Lead, will lead a small team responsible for the operational implementation of the Company's vendor risk management process within Procurement. While Legal Risk & Compliance will design and maintain the enterprise risk framework, this role will be responsible for developing and building the third-party risk management function inside of procurement, aligning with enterprise risk domain owners (information security, HR, ethics and compliance, and finance), monitoring and mitigating supplier risk, and ensure proper governance across the procurement function.
This role serves as the operational bridge between Procurement, Legal, Risk & Compliance, and Information Security.
Responsibility and Impact:
Vendor Risk Process Operationalization
- Translate the enterprise vendor risk framework into scalable procurement processes and policies.
- Work with risk domain owners to define intake requirements and risk-tiering triggers for vendor engagements.
- Monitor the TPRM process and ensure timely completeness of the risk reviews by the applicable risk domain owners.
- Drive continuous improvement in vendor risk governance processes.
- Maintain vendor risk attributes, classifications, and documentation repositories.
- Partner with Finance Systems and IT to enhance automation and reporting.
- Develop dashboards and reporting to monitor review completion, SLAs, and compliance trends.
Policy & Documentation Development
- Draft and maintain procurement-facing vendor risk policies and SOPs.
- Conduct training sessions for business stakeholders.
Risk Review Coordination & Enforcement
- Monitor review timelines and escalate exceptions.
- Maintain documentation of approvals, conditions, and remediation requirements.
- Track and report compliance metrics to Procurement and Finance leadership.
Audit & Compliance Support
- Maintain audit-ready documentation of vendor risk approvals and workflows.
- Support SOX-related vendor governance controls where applicable.
- Partner with Internal Audit on third-party risk assessments.
- Support remediation efforts tied to vendor governance findings.
- Promote a culture of governance and risk awareness.
What We're Looking For:
Basic Required Qualifications:
- Bachelor's degree in Business, Supply Chain, Risk Management, Finance, or related field or equivalent relevant experience.
- 7 to 10+ years of experience in Procurement, Third-Party Risk, Compliance, or Governance.
- Experience in a publicly traded organization required.
- Strong understanding of third-party risk domains, including:
- Information security
- Data privacy
- Regulatory and compliance risk
- Operational and financial risk
- Experience developing policy documentation and process controls.
- Strong systems and workflow configuration experience.
- Must be a results-focused team player and adapt well to a multitasking, fast paced environment with changing priorities and challenges
- Strong organizational, presentation and communication skills.
- Experience working cross-functionally with Technology, Legal, Finance, and Risk teams.
Additional Preferred Qualifications:
- Experience with LogicGate or similar TPRM tool
- Governance-oriented with strong attention to detail.
- Systems-minded and process-driven.
- Confident cross-functional influencer.
- Able to enforce controls in a collaborative but firm manner.
- Comfortable operating in a transformation-oriented, post-spin environment.
If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.