Third-Party Risk Management • Develop and maintain a comprehensive Third-Party Risk Management (TPRM) framework. • Ensure third-party compliance with legal, regulatory, and internal policy ...
Third-Party Risk Management • Develop and maintain a comprehensive Third-Party Risk Management (TPRM) framework. • Ensure third-party compliance with legal, regulatory, and internal policy ...
This includes responsibilities for key operational risk functions such as Business Continuity, Third-Party Risk Management, and Corporate Insurance. This position, through specialized knowledge and ...
This includes responsibilities for key operational risk functions such as Business Continuity, Third-Party Risk Management, and Corporate Insurance. This position, through specialized knowledge and ...
US-MD-Bethesda
Bethesda, MD · Hybrid
$80K - $129K/yr
As a Third-Party Risk Management Analyst, you will play a critical role in ensuring that our partnership with vendors and service providers are secure, compliant and align with the Interagency ...
US-MD-Bethesda
Bethesda, MD · Hybrid
$80K - $129K/yr
As a Third-Party Risk Management Analyst, you will play a critical role in ensuring that our partnership with vendors and service providers are secure, compliant and align with the Interagency ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Design and manage a comprehensive supplier risk program , including ... Third-party risk assessments (financial, operational, geopolitical, cyber) * Continuous monitoring ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
Lead design and maturation of enterprise initiatives and risk programs including RCSA, Issue Management, 3rd Party Risk Management, Business Continuity, Data Risk Governance, Model Risk, Financial ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
The role involves performing detailed supply chain security reviews, analyzing third-party vendor ... risk management approaches against DoD and federal requirements. • Reviews independent audit ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
The role involves performing detailed supply chain security reviews, analyzing third-party vendor ... risk management approaches against DoD and federal requirements. • Reviews independent audit ...
Project Manager Professional - Onsite
Mclean, VA · On-site
$42.80 - $52.80/hr
This role is focused on third-party risk management within the financial services sector. The selected candidate will work alongside the Governance Advisor to drive the execution of the Enterprise ...
Project Manager Professional - Onsite
Mclean, VA · On-site
$42.80 - $52.80/hr
This role is focused on third-party risk management within the financial services sector. The selected candidate will work alongside the Governance Advisor to drive the execution of the Enterprise ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
Risk management certification such as: Certified Third-Party Risk Professional (CTPRP) At this time, Capital One will not sponsor a new applicant for employment authorization for this position. The ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
The Supply Chain Risk Management Audit Analyst supports WDP's enterprise SCRM program by conducting structured, evidence-based security assessments of third-party vendor documentation and audit ...
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
... in third-party Risk Management * One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager ...
... in third-party Risk Management * One or more current information security certifications such as Certified in Risk and Information Systems Controls (CRISC), Certified Information Security Manager ...
Third Party Risk Management information
See Silver Spring, MD salary details
$53.2K - $64.4K
4% of jobs
$64.4K - $75.5K
6% of jobs
$75.5K - $86.6K
11% of jobs
$90.8K is the 25th percentile. Wages below this are outliers.
$86.6K - $97.8K
11% of jobs
The median wage is $106.6K / yr.
$97.8K - $108.9K
23% of jobs
$108.9K - $120.1K
13% of jobs
$127.4K is the 75th percentile. Wages above this are outliers.
$120.1K - $131.2K
12% of jobs
$131.2K - $142.3K
8% of jobs
$142.3K - $153.5K
6% of jobs
$153.5K - $164.6K
4% of jobs
$164.6K - $175.7K
2% of jobs
$53.2K
$115.3K
$175.7K
How much do third party risk management jobs pay per year?
What is a Third Party Risk Management job?
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
What is the highest paying risk management job?
What is the role of a third party Risk Manager?
What is 3rd party risk management?
What are some common challenges faced in a Third Party Risk Management role, and how are they addressed?
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
What are the key skills and qualifications needed to thrive in the Third Party Risk Management position, and why are they important?
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.
Is TPRM a good career?
Full-time
Medical, Dental, Vision, Retirement, PTO
Posted 18 days ago
Job description
Who we are:
At SECU, we put our employees first, recognizing that their well-being and professional development are vital to our success. By fostering a supportive and empowering work environment, our employees are committed to helping members achieve long-term financial security. They are also inspired to give back to the communities we serve by volunteering and spreading kindness, which reflects our core values and who we are as an organization.
Every employee at SECU contributes to our member's financial well-being, and we'll always do what's right for our members, employees, and communities.
Feel good about what you do. Belong to a place where you matter and can make a difference.
What you will do:
The Assistant Vice President (AVP), Enterprise and Operational Risk Management (EORM) will support the VP, EORM with the daily operation and administration of the SECU enterprise risk management program. This includes responsibilities for key operational risk functions such as Business Continuity, Third-Party Risk Management, and Corporate Insurance. This position, through specialized knowledge and skill, provides support to the organization on all matters relating to EORM policies, procedures, processes, and reporting.
The AVP adheres to regulations and organizational policies, maintaining awareness and knowledge required to perform the duties of the position, including all aspects of the Bank Secrecy Act and related regulations, such as OFAC, and the USA Patriot Act, Fair Lending, and Information Security.
A day in your life might include:
Enterprise Risk Management Program
• Identifies key emerging risks, assesses their potential impact on SECU, and discusses risk mitigation with appropriate business units.
• Ensures that SECU's various planning processes consider the risks of key products, processes, and strategies.
• Develops and maintains organizational EORM playbooks, policies, procedures, process-flows and reference material to ensure all processes are documented, organized, and scaled to current and future state.
• Develops comprehensive risk analytics, reporting, and presentations for all EORM program areas, including risk appetite metrics development.
• Coordinates and facilitates training to all levels of the organization on the EORM program, ensures program documentation is accurate and up to date.
• Supports remediation efforts of audit, exam, compliance, and issues management findings.
Business Continuity Program
• Evaluates and recommends various business continuity strategies, plans, and programs.
• Identifies key emerging risks, assesses their potential impact on SECU, and discusses risk mitigation with appropriate business units.
• Ensures that SECU's various business continuity planning processes consider the risks of key products, processes, and strategies.
• Coordinates and facilitates business continuity meetings and tabletop exercises.
• Presents tabletop exercise and risk assessment results to senior leadership.
• Leads updates to business continuity risk assessments.
• Coordinates and facilitates annual training, program reviews and ensures program documentation is accurate and up to date.
Third-Party Risk Management
• Develop and maintain a comprehensive Third-Party Risk Management (TPRM) framework.
• Ensure third-party compliance with legal, regulatory, and internal policy requirements.
• Establish governance models, policies, and procedures for vendor oversight.
• Provides support to initial and ongoing vendor due diligence reviews, documents collection/retention and risk rating of vendors.
• Implement and monitor controls and testing programs to validate vendor compliance and performance, drive continuous improvement.
• Identify and mitigate third-party risks, establish enhanced oversight for critical and high-risk vendors.
• Lead Third-Party Risk Management Reporting.
Corporate Insurance
• Establish and maintain a framework to manage and evaluate corporate insurance programs.
• Oversee end-to-end insurance claims management, serving a central liaison between insurers, brokers and SECU.
• Lead all aspects of annual corporate insurance renewal cycles.
• Assess emerging risks and coverage needs, monitor and evaluate performance and recommendations to risk transfer strategies.
Additional Responsibilities may include:
• Interact and support CUSO partners and credit union partners
• Serves on various projects and performs other duties as assigned
Education Requirements
• Bachelor's degree required.
• Advanced Degree in Business Administration, Banking, Finance, and/or Law preferred.
Experience and Business Acumen Requirements
• 6-9 years' experience in governance, risk, or compliance roles in a financial institution or regulatory oversight, bank examiner roles within a regulatory agency.
• Experience with risk analytics and reporting platforms preferred, developing and running reports, incorporating them into dashboards and executive-level reporting.
• Must have seasoned experience with Microsoft programs including Word, Excel, Powerpoint, and Outlook.
• Must be experienced in financial institution risk management practices, preferably in a credit union.
• Prioritizes tasks effectively to support team goals and organizational timelines.
• Applies critical thinking to troubleshoot issues and escalate concerns when appropriate.
• Understands the importance of confidentiality, compliance, and ethical behavior in daily responsibilities.
• Takes personal responsibility for decisions, actions, failures and overall deliverable.
• Utilizes oral and written communication to enhance relationships across the organization.
• Clearly communicates information, thoughts and ideas in a clear, concise and organized manner.
• Relates comfortably with people across levels, functions, culture, and geography.
• Possesses a clear understanding of strengths, limitations, emotions, beliefs, and motivations of self and others.
• Maintains composure and effectiveness when experiencing major changes in work tasks or the work environment.
• Adjusts effectively to work within new work structures, processes, requirements, or cultures.
• Maintains professionalism in communication, behavior, and representation of SECU.
• Demonstrates an understanding of SECU's culture, core values, mission and strategic priorities as it relates to one's work and overall performance.
Physical Requirements
• Must be able to remain in a stationary position, often standing or sitting for prolonged periods
• Must be able to lift up to 25 pounds
Compensation Information: Offers will be commensurate with experience and education.
• Salary: Min. $142,000- Max. $200,000
Other Compensation Includes:
• Annual corporate-wide incentive
We provide comprehensive benefits, with a focus on total well-being:
• Medical, vision, dental benefits
• 401k plan with company matching
• Generous sick, vacation and personal leave
• And more...2026 SECU Benefits Guide
SECU is committed to fostering a diverse, equitable, and inclusive workforce where all individuals are valued and respected. We take pride in providing equal opportunities for all qualified applicants regardless of race, ethnicity, national origin, gender, sexual orientation, gender identity or expression, religion, military or veteran status, or any other characteristics protected by law.
About SECU Credit Union
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
501 - 1,000 Employees
Headquarters location
Linthicum, MD, US
Year founded
1951