Serve as the firm'ssubject matter experton third-party risk management. * Contribute to the development and execution of the firm'sTPRM strategy, roadmap, and target-state operating model. * Lead the ...
Serve as the firm'ssubject matter experton third-party risk management. * Contribute to the development and execution of the firm'sTPRM strategy, roadmap, and target-state operating model. * Lead the ...
The overall TRPM team provides not only the governance structure for TPRM at Capital One, but also advice and effective challenge in all areas of Third Party Risk Management, from individual third ...
The overall TRPM team provides not only the governance structure for TPRM at Capital One, but also advice and effective challenge in all areas of Third Party Risk Management, from individual third ...
Third-Party Risk Analyst
Mclean, VA · On-site
$45 - $47/hr
Key Responsibilities Risk & Program Management * Partner with the Governance Advisor to execute EOCTP and VIM programs. * Ensure divisions comply with internal guidance for managing third-party risk.
Quick apply
Third-Party Risk Analyst
Mclean, VA · On-site
$45 - $47/hr
Key Responsibilities Risk & Program Management * Partner with the Governance Advisor to execute EOCTP and VIM programs. * Ensure divisions comply with internal guidance for managing third-party risk.
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Strengthen escalation, issue management, and risk acceptance processes, including practical guidance for consistent and defensible third-party risk decisions. * Develop training, education, and ...
Principal Associate, Operational Risk Management, Third Party Risk Manager (TPRM)
Mclean, VA · On-site
Principal Associate, Operational Risk Management, Third Party Risk Manager (TPRM) Capital One is seeking an energetic, self-motivated Principal Associate to join the Third Party Risk Management (TPRM ...
New
Principal Associate, Operational Risk Management, Third Party Risk Manager (TPRM)
Mclean, VA · On-site
Principal Associate, Operational Risk Management, Third Party Risk Manager (TPRM) Capital One is seeking an energetic, self-motivated Principal Associate to join the Third Party Risk Management (TPRM ...
New
This position is expected to independently manage complex risk assessments, lead oversight ... Third-Party Risk Management: * Perform quality assurance and effective challenge of third-party ...
This position is expected to independently manage complex risk assessments, lead oversight ... Third-Party Risk Management: * Perform quality assurance and effective challenge of third-party ...
The role will focus on Third Party Risk and resides within the Legal and Compliance's Operational ... The individual will play a critical strategic role in driving risk management oversight activities ...
The role will focus on Third Party Risk and resides within the Legal and Compliance's Operational ... The individual will play a critical strategic role in driving risk management oversight activities ...
The role will focus on Third Party Risk and resides within the Legal and Compliance's Operational ... The individual will play a critical strategic role in driving risk management oversight activities ...
The role will focus on Third Party Risk and resides within the Legal and Compliance's Operational ... The individual will play a critical strategic role in driving risk management oversight activities ...
At least 6 years of experience in Third-Party Risk Management, Vendor Management, or Operational Risk Management * At least 3 years of experience in IT Operations Management Preferred Qualifications:
At least 6 years of experience in Third-Party Risk Management, Vendor Management, or Operational Risk Management * At least 3 years of experience in IT Operations Management Preferred Qualifications:
At least 6 years of experience in Third-Party Risk Management, Vendor Management, or Operational Risk Management * At least 3 years of experience in IT Operations Management Preferred Qualifications:
At least 6 years of experience in Third-Party Risk Management, Vendor Management, or Operational Risk Management * At least 3 years of experience in IT Operations Management Preferred Qualifications:
This includes responsibilities for key operational risk functions such as Business Continuity, Third-Party Risk Management, and Corporate Insurance. This position, through specialized knowledge and ...
This includes responsibilities for key operational risk functions such as Business Continuity, Third-Party Risk Management, and Corporate Insurance. This position, through specialized knowledge and ...
Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting. * Broader Risk Support:
Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting. * Broader Risk Support:
Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting. * Broader Risk Support:
Maintain accurate third-party records, assessment results, and issues within the system of record, and support preparation of metrics, dashboards, and management reporting. * Broader Risk Support:
The Risk Management Analyst Intern will gain exposure and support operational risk programs ... Govern and support associates in the completion of third party risk assessments and control self ...
New
The Risk Management Analyst Intern will gain exposure and support operational risk programs ... Govern and support associates in the completion of third party risk assessments and control self ...
New
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Third Party Risk Management information
See Silver Spring, MD salary details
$53.2K - $64.4K
4% of jobs
$64.4K - $75.5K
6% of jobs
$75.5K - $86.6K
11% of jobs
$90.8K is the 25th percentile. Wages below this are outliers.
$86.6K - $97.8K
11% of jobs
The median wage is $106.6K / yr.
$97.8K - $108.9K
23% of jobs
$108.9K - $120.1K
13% of jobs
$127.4K is the 75th percentile. Wages above this are outliers.
$120.1K - $131.2K
12% of jobs
$131.2K - $142.3K
8% of jobs
$142.3K - $153.5K
6% of jobs
$153.5K - $164.6K
4% of jobs
$164.6K - $175.7K
2% of jobs
$53.2K
$115.3K
$175.7K
How much do third party risk management jobs pay per year?
What is a Third Party Risk Management job?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What are some common challenges faced in a Third Party Risk Management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in the Third Party Risk Management position, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.

T. Rowe Price rating
9.1
Based on 21 frontline employees who took The Breakroom Quiz
Job description
Role Summary
TheDirector- ThirdParty Risk Management is aSecond Line of Defense (2LoD)leadership role responsible for thestrategic development, oversight, and ongoing maturation of the firm'sThirdPartyRisk Management (TPRM) program. Reporting to the Head of Privacy & TPRM, this role is regarded as asubject matter expert in third-party riskand plays a key role in shaping the firm's risk strategy, governance framework, and operating model following the implementation of anoutsourced TPRMcapability.
TheDirectorprovides independent oversight, crediblechallenge, and assurance over first-line and outsourced TPRM activities, while building a sustainable, regulator-ready 2LoD function aligned with the firm's risk appetite and regulatory expectations.
Responsibilities
TPRM Strategy & Program Leadership:
Serve as the firm'ssubject matter experton third-party risk management.
Contribute to the development and execution of the firm'sTPRM strategy, roadmap, and target-state operating model.
Lead the build-out and continuous improvement of a 2LoD TPRM functionfollowing outsourcing of due diligence and periodic reviews.
Define and maintain TPRM policies, standards, risk methodologies, and oversight frameworks aligned with regulatory expectations and industry best practices.
Ensure alignment of the TPRM program with enterprise risk appetite and governance structures.
Lead assessment of emergingthird partyrisks and technologies, including AI, andintegratefindings into TPRM strategy, governance, and executive reporting.
Oversight of Outsourced & First-Line TPRM Activities:
Provide independent oversight and effectivechallengeofoutsourced TPRM service providers, including due diligence execution and ongoing monitoring.
Oversight of monitoring activities related toSLAs, KPIs, quality assurance standards, and performance metrics for outsourced partners.
Report onsystemic control gaps, concentration risk, and emerging third-party risk themes across the vendor population.
Escalatematerialthird-party risk issues and control deficiencies throughappropriate governanceand risk committees.
Risk Governance, Reporting & Regulatory Readiness:
Design and deliver executive and board-level reporting on third-party risk, including trends, emerging risks, and risk appetite breaches.
Lead TPRM-related regulatory exams, internal audits, and management assurance activities.
Ensure TPRM documentation, evidence, and reporting areaudit-and exam-ready.
Partner with Enterprise Risk, Compliance, Legal, Information Security, Procurement, and Technology while maintaining 2LoD independence.
Leadership & Capability Development:
Provide leadership, guidance, and technical mentorship to TPRM risk analysts and managers.
Establish clear roles, responsibilities, and RACI alignment across 1LoD, 2LoD, and outsourced providers.
Drive adoption of data-driven, AI-enabled reporting and analytics to enhance risk insight and oversight efficiency.
Promote a strong risk culture and consistent application of third-party risk standards across the firm.
Qualifications
Required:
Bachelor's degree in Risk Management, Information Systems, Finance, Business, Law, ora relatedfield.10+ years of experience inthird-party risk management, operational risk, or compliance, withsignificant experiencein a2LoD capacitywithin financial services or asset management(or other industry subject to equivalent regulatory scrutiny).
Demonstrated experiencedesigning, implementing, or maturing a TPRM program, including oversight of outsourced or co-sourced models.
Deep understanding of regulatory expectations for third-party risk (e.g., SEC, FINRA, global regulators).
Proven ability tooperateas a trusted expert and strategic advisor to senior leadership.
Required Certifications (at least one): Certified Third Party Risk Professional (CTPRP), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA)
Preferred:
Advanced degree (MBA, JD, or equivalent).
Experience supporting global or complex vendor ecosystems.
Additionalcertifications:
ISO 27001 Lead Implementer or Auditor
PMP or equivalent program management certification
ExperienceleveragingAI, automation, or advanced analytics in TPRM oversight(e.g., Microsoft Co-Pilot, ChatGPT Enterprise).
Tools & Technology (Preferred)
Extensive experience with TPRM and GRC platforms (e.g., ServiceNow, Coupa).
Strong executive-level reporting and data visualization skills (e.g., Power BI).
Experience implementing metrics, KRIs, and dashboards aligned to risk appetite.
Key Competencies
Recognizedexpertisein third-party risk management.
Strategic mindset with hands-on oversight capability.
Strong executive presence and ability to provide crediblechallenge.
Excellent written and verbal communication skills.
Ability to lead through influence in a matrixed, regulated environment.
FINRA Requirements
FINRA licenses are not required and will not be supported for this role.
Work Flexibility
This role is eligible for hybrid work, with up to one day per week from home.
What T. Rowe Price employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About T. Rowe Price
Sourced by ZipRecruiter
Industry
Funds, trusts and financial programs
Company size
5,001 - 10,000 Employees
Headquarters location
Baltimore, MD, US
Year founded
1937