Archer is seeking a Senior Third Party Risk Management (TPRM) Engineer to execute our vendor cyber risk function across all tiers of our supplier ecosystem. In this high-visibility role, you will use ...
Archer is seeking a Senior Third Party Risk Management (TPRM) Engineer to execute our vendor cyber risk function across all tiers of our supplier ecosystem. In this high-visibility role, you will use ...
You will be responsible for the full lifecycle of third-party risk management, including identifying, assessing, mitigating, and monitoring risks to ensure our programs and business operations remain ...
You will be responsible for the full lifecycle of third-party risk management, including identifying, assessing, mitigating, and monitoring risks to ensure our programs and business operations remain ...
Third Party Risk Analyst
San Francisco, CA · On-site
$97K - $132K/yr
Create and manage reporting that provides leadership with clear insights into third-party risk posture, trends, and key performance indicators (KPIs). Risk Assessment & Due Diligence * Conduct ...
Third Party Risk Analyst
San Francisco, CA · On-site
$97K - $132K/yr
Create and manage reporting that provides leadership with clear insights into third-party risk posture, trends, and key performance indicators (KPIs). Risk Assessment & Due Diligence * Conduct ...
Third Party Risk Analyst
San Francisco, CA · On-site
$97K - $132K/yr
Create and manage reporting that provides leadership with clear insights into third-party risk posture, trends, and key performance indicators (KPIs). Risk Assessment & Due Diligence * Conduct ...
Third Party Risk Analyst
San Francisco, CA · On-site
$97K - $132K/yr
Create and manage reporting that provides leadership with clear insights into third-party risk posture, trends, and key performance indicators (KPIs). Risk Assessment & Due Diligence * Conduct ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor responsible for governing and overseeing Pacific Life's enterprise TPRM program within the 2nd line of ...
Manager, Third-Party Risk Management (GTM)
San Francisco, CA · On-site
$162K - $180K/yr
We're hiring a Third Party Risk Manager (GTM) to help scale customer risk operations, KYC/KYB onboarding, and sanctions screening across a rapidly expanding global customer and supplier ecosystem.
Manager, Third-Party Risk Management (GTM)
San Francisco, CA · On-site
$162K - $180K/yr
We're hiring a Third Party Risk Manager (GTM) to help scale customer risk operations, KYC/KYB onboarding, and sanctions screening across a rapidly expanding global customer and supplier ecosystem.
Security Risk Manager
San Francisco, CA · Hybrid
Specifically, the company wants someone with adept experience in security risk management (not just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * ...
Security Risk Manager
San Francisco, CA · Hybrid
Specifically, the company wants someone with adept experience in security risk management (not just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * ...
Security Risk Manager
San Francisco, CA · On-site
Specifically, the company wants someone with adept experience in security risk management (not just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * ...
Security Risk Manager
San Francisco, CA · On-site
Specifically, the company wants someone with adept experience in security risk management (not just third-party risk management or compliance or vulnerability management). * Consulting with Big 4 * ...
Security Analyst/Third-Party Risk Management (TPRM) - remote PST
Long Beach, CA · Remote
$60 - $70/hr
Third-Party Risk Management (TPRM) Security Analyst Our client is seeking a sharp and driven TPRM Security Analyst to join their Information Security GRC team in a remote capacity. This is a high ...
Security Analyst/Third-Party Risk Management (TPRM) - remote PST
Long Beach, CA · Remote
$60 - $70/hr
Third-Party Risk Management (TPRM) Security Analyst Our client is seeking a sharp and driven TPRM Security Analyst to join their Information Security GRC team in a remote capacity. This is a high ...
Third-Party Risk Management (TPRM) * Lead and execute third-party cybersecurity risk assessments throughout the vendor lifecycle, including onboarding, periodic reassessment, contract renewal, and ...
Third-Party Risk Management (TPRM) * Lead and execute third-party cybersecurity risk assessments throughout the vendor lifecycle, including onboarding, periodic reassessment, contract renewal, and ...
GRC Risk Manager
Los Angeles, CA · On-site
Conduct third-party risk assessments and security reviews of third-party agreements. * Work closely ... Track and monitor remediation and risk management activities. * Maintain a current and ...
GRC Risk Manager
Los Angeles, CA · On-site
Conduct third-party risk assessments and security reviews of third-party agreements. * Work closely ... Track and monitor remediation and risk management activities. * Maintain a current and ...
GRC Risk Manager
Los Angeles, CA · On-site
Conduct third-party risk assessments and security reviews of third-party agreements. * Work closely ... Track and monitor remediation and risk management activities. * Maintain a current and ...
GRC Risk Manager
Los Angeles, CA · On-site
Conduct third-party risk assessments and security reviews of third-party agreements. * Work closely ... Track and monitor remediation and risk management activities. * Maintain a current and ...
We are hiring a OneTrust Subject Matter Expert (SME) with deep expertise in Third-Party Risk Management (TPRM) and Cookie Consent solutions to support privacy, compliance, and risk management ...
We are hiring a OneTrust Subject Matter Expert (SME) with deep expertise in Third-Party Risk Management (TPRM) and Cookie Consent solutions to support privacy, compliance, and risk management ...
Risk Management develops, administers, and coordinates citywide liability insurance and risk ... Serves as a liaison with third party administrators, legal counsel, Cal-OSHA, CalPERS and other ...
Risk Management develops, administers, and coordinates citywide liability insurance and risk ... Serves as a liaison with third party administrators, legal counsel, Cal-OSHA, CalPERS and other ...
RISK MANAGER
Huntington Beach, CA · On-site
$10K - $14K/mo
Risk Management develops, administers, and coordinates citywide liability insurance and risk ... Serves as a liaison with third party administrators, legal counsel, Cal-OSHA, CalPERS and other ...
RISK MANAGER
Huntington Beach, CA · On-site
$10K - $14K/mo
Risk Management develops, administers, and coordinates citywide liability insurance and risk ... Serves as a liaison with third party administrators, legal counsel, Cal-OSHA, CalPERS and other ...
Senior Manager, Financial Risk Management
San Francisco, CA · On-site
$216K - $240K/yr
... third-party dependencies, systems, and other high-risk workflows. We work closely with ... About the Role We're seeking a Senior Manager, Financial Risk Management to help shape and scale ...
Senior Manager, Financial Risk Management
San Francisco, CA · On-site
$216K - $240K/yr
... third-party dependencies, systems, and other high-risk workflows. We work closely with ... About the Role We're seeking a Senior Manager, Financial Risk Management to help shape and scale ...
OneTrust Third-Party Risk Management (TPRM) and OneTrust Cookie Consent & Preference Management * Privacy, Risk & Compliance Management and Third-Party Vendor Risk Assessments * GDPR, CCPA, CPRA ...
OneTrust Third-Party Risk Management (TPRM) and OneTrust Cookie Consent & Preference Management * Privacy, Risk & Compliance Management and Third-Party Vendor Risk Assessments * GDPR, CCPA, CPRA ...
OneTrust Third-Party Risk Management (TPRM) and OneTrust Cookie Consent & Preference Management * Privacy, Risk & Compliance Management and Third-Party Vendor Risk Assessments * GDPR, CCPA, CPRA ...
OneTrust Third-Party Risk Management (TPRM) and OneTrust Cookie Consent & Preference Management * Privacy, Risk & Compliance Management and Third-Party Vendor Risk Assessments * GDPR, CCPA, CPRA ...
Third Party Risk Manager information
See California salary details
$50.8K - $61.5K
4% of jobs
$61.5K - $72.1K
6% of jobs
$72.1K - $82.7K
11% of jobs
$86.7K is the 25th percentile. Wages below this are outliers.
$82.7K - $93.4K
11% of jobs
The median wage is $101.8K / yr.
$93.4K - $104K
23% of jobs
$104K - $114.6K
13% of jobs
$121.6K is the 75th percentile. Wages above this are outliers.
$114.6K - $125.2K
12% of jobs
$125.2K - $135.9K
8% of jobs
$135.9K - $146.5K
6% of jobs
$146.5K - $157.1K
4% of jobs
$157.1K - $167.8K
2% of jobs
$50.8K
$110.1K
$167.8K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
What is a Third Party Risk Manager?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?
Job description
Archer is an aerospace company based in San Jose, California building an all-electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all-electric aircraft that can carry four passengers while producing minimal noise. Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members.
Job Overview
Archer is building the future of urban air mobility. Our supply chain spans hundreds of vendors - from avionics hardware suppliers to cloud infrastructure providers - and a compromise anywhere in that ecosystem could impact aircraft certification, delay FAA approvals, or expose sensitive information. You are key to effective enforcement of our extended enterprise third-party risk posture. Archer is seeking a Senior Third Party Risk Management (TPRM) Engineer to execute our vendor cyber risk function across all tiers of our supplier ecosystem. In this high-visibility role, you will use platforms like BitSight to continuously monitor, investigate, triage, and action security risks introduced by third-party partners and their downstream (4th-party) suppliers. You will serve as the connective tissue between Security, Sourcing, Legal, and executive leadership - translating third party risk indicators into actionable threat intelligence and coordinated response actions while ensuring strict compliance with NIST SP 800-171, CMMC Level 2, and SOX ITGC requirements. This role requires both hands-on technical depth and program-building acumen. You will support and execute Archer's TPRM function from the ground up, develop risk-tiered due diligence processes, and ensure vendor security posture remains aligned with our CMMC Level 2, NIST SP 800-161, and DFARS obligations as we grow our defense programs.
Key Responsibilities
Operate BitSight and complementary EASM/continuous monitoring platforms as the primary lens into Archer's third-party attack surface. Maintain a tiered vendor inventory, configure portfolio monitoring, tune alert thresholds, and ensure new vendors are onboarded into the program at contract execution.
Conduct deep-dive investigations into vendor risk signals - including unpatched CVEs, exposed services, credential leaks, certificate anomalies, business deterioration, and dark web indicators. Correlate external ratings data with internal telemetry to assess true business exposure and eliminate false positives before escalation.
Extend visibility beyond direct vendors to identify and monitor critical 4th-party sub-processor dependencies. Map supply chain concentration risks, single points of failure, and foreign ownership or influence (FOCI) concerns for vendors supporting defense programs or handling CUI.
Drive risk closure by issuing formal findings, coordinating with internal vendor relationship owners, and tracking remediation commitments through resolution. Engage procurement and legal channels when vendors are non-responsive or remediation timelines are unacceptable.
Produce crisp, executive-quality risk briefings, board-level metrics, and ad-hoc deep-dives for the CISO, General Counsel, and program security leads. Escalate critical or rapidly-deteriorating vendor risk findings in near-real-time with clear business impact statements and recommended courses of action.
Design and administer risk-tiered security questionnaires for new and renewing vendors. Evaluate responses, validate claims against external signals, execute integrated due diligence checkpoints in Archer's procurement workflow.
Influence, develop and maintain TPRM policies, standards, and procedures aligned to NIST SP 800-161 (C-SCRM), CMMC Level 2 SR practices, and ISO 27036. Provide transparency to external audits and government assessments by maintaining organized evidence of vendor risk controls and remediation activity.
Serve as the TPRM lead during vendor-related security incidents - coordinating with Archer's internal IR team, managing vendor communications under legal hold protocols, and driving root cause analysis and contractual remedies following a third-party breach.
Required Qualifications
7+ years in cybersecurity with at least 3 years of dedicated third-party or supply chain risk management experience
Demonstrated hands-on proficiency with BitSight or an equivalent continuous monitoring platform - including alert tuning, portfolio management, vendor engagement workflows, and peer benchmarking
Deep working knowledge of NIST SP 800-161 (C-SCRM), NIST CSF, CMMC Level 2 SR and CAÂ practices, and ISO 27036 as they apply to vendor security governance
Experience conducting structured vendor security due diligence across SaaS, cloud infrastructure, hardware manufacturers, and professional services suppliers
Proven ability to investigate and triage cyber risk findings at scale - correlating external signals with business context to produce prioritized, actionable intelligence for both technical and non-technical stakeholders
Familiarity with 4th-party risk mapping, sub-processor disclosure reviews, and supply chain concentration risk analysis
Excellent written and verbal communication skills - able to translate complex vendor risk findings into executive-ready briefings, board-level dashboards, and actionable
Eligibility to obtain a DoD Secret security clearance
Preferred Qualifications
Certifications: CTPRP (Prevalent), CRISC, CISSP, CISM, or equivalent risk management credentials
Active DoD Secret or Top Secret/SCI clearance
Familiarity with ITAR/EAR data sharing constraints and their implications for vendor contracting and CUI handling
Exposure to FOCI (Foreign Ownership, Control, or Influence) assessments
Experience integrating TPRM tooling with GRC platforms or building risk workflow automation (e.g., auto-routing findings, SLA tracking, contract clause triggers)
Prior startup or high-growth company experience - comfort operating with limited bureaucracy and building programs that scale with business growth
Please note that this job description is intended to provide a general overview of the position and does not include an exhaustive list of responsibilities and qualifications
At Archer we aim to attract, retain, and motivate talent that possess the skills and leadership necessary to grow our business. We drive a pay-for-performance culture and reward performance that supports the Company's business strategy. For this position we are targeting a base pay between $207,400 - $259,200. Actual compensation offered will be determined by factors such as job-related knowledge, skills, and experience.
Archer is proud to be an Equal Opportunity employer committed to diversity and inclusivity in the workplace. All aspects of employment are decided on the basis of merit, qualifications, and business needs. We do not discriminate based upon race, color, religion, sex, sexual orientation, age, national origin, disability status, protected veteran status, gender identity or any other characteristic protected by federal, state or local laws.Archer is committed to working with and providing reasonable accommodations to job applicants with physical or mental disabilities, and those with sincerely held religious beliefs. Applicants who may require reasonable accommodation for any part of the application or hiring process should provide their name and contact information to Archer's People Team at people@archer.com. Reasonable accommodations will be determined on a case-by-case basis.About Archer Systems
Sourced by ZipRecruiter
Company size
201 - 500 Employees
Headquarters location
Houston, TX, US
Year founded
2017