... third-party risk management and disaster recovery. Key Responsibilities: IT Risk Assessments: • Conduct comprehensive IT risk assessments, including identifying and analyzing potential threats and ...
... third-party risk management and disaster recovery. Key Responsibilities: IT Risk Assessments: • Conduct comprehensive IT risk assessments, including identifying and analyzing potential threats and ...
Vice President - Third Party Resilience 2nd LOD Lead Analyst - Risk Management (Hybrid)
Tampa, FL · On-site
Operating within the Operational Risk Management (ORM) Framework, this role provides independent ... Collaborate with horizontal Risk SMEs (incl. but not limited to Technology Risk, Third-Party Risk ...
Vice President - Third Party Resilience 2nd LOD Lead Analyst - Risk Management (Hybrid)
Tampa, FL · On-site
Operating within the Operational Risk Management (ORM) Framework, this role provides independent ... Collaborate with horizontal Risk SMEs (incl. but not limited to Technology Risk, Third-Party Risk ...
The Principal, Third-Party Management (TPM) Risk Lead is a senior individual contributor who will lead day-to-day execution of the enterprise Third-Party Management governance framework-driving ...
The Principal, Third-Party Management (TPM) Risk Lead is a senior individual contributor who will lead day-to-day execution of the enterprise Third-Party Management governance framework-driving ...
Gather and document business requirements to support technology product planning and development within third party risk management (TPRM).Conduct business process mapping to identify and analyze ...
Gather and document business requirements to support technology product planning and development within third party risk management (TPRM).Conduct business process mapping to identify and analyze ...
The Principal, Third-Party Management (TPM) Risk Lead is a senior individual contributor who will lead day-to-day execution of the enterprise Third-Party Management governance framework-driving ...
The Principal, Third-Party Management (TPM) Risk Lead is a senior individual contributor who will lead day-to-day execution of the enterprise Third-Party Management governance framework-driving ...
Identify, evaluate, and analyze operational, contractual, and third-party risk exposures arising from client business activities, vendors, service providers, and customers. * Strategically manage ...
Identify, evaluate, and analyze operational, contractual, and third-party risk exposures arising from client business activities, vendors, service providers, and customers. * Strategically manage ...
Risk Management About Everest: Everest is a global leader in risk management, rooted in a rich, 50 ... Logan, Everest's growing proprietary 3rd party capital platform, covering the respective risk ...
Risk Management About Everest: Everest is a global leader in risk management, rooted in a rich, 50 ... Logan, Everest's growing proprietary 3rd party capital platform, covering the respective risk ...
Senior Risk Manager
Miami, FL · On-site
Initially, the individual will be heavily involved in risk management programs designed to identify and report risks associated with third party relationships. Over time, the role is expected to ...
Senior Risk Manager
Miami, FL · On-site
Initially, the individual will be heavily involved in risk management programs designed to identify and report risks associated with third party relationships. Over time, the role is expected to ...
Senior Risk Manager
Miami, FL · On-site
Initially, the individual will be heavily involved in risk management programs designed to identify and report risks associated with third party relationships. Over time, the role is expected to ...
Senior Risk Manager
Miami, FL · On-site
Initially, the individual will be heavily involved in risk management programs designed to identify and report risks associated with third party relationships. Over time, the role is expected to ...
Senior Risk Manager
Miami, FL · On-site
Initially, the individual will be heavily involved in risk management programs designed to identify and report risks associated with third party relationships. Over time, the role is expected to ...
Quick apply
Senior Risk Manager
Miami, FL · On-site
Initially, the individual will be heavily involved in risk management programs designed to identify and report risks associated with third party relationships. Over time, the role is expected to ...
Risk Manager
$91K - $146K/yr
The Risk Manager is assigned primary responsibility for management the County's insurance programs ... third-party adjusters as appropriate. Manages settlement or recommends settlement of claims in ...
Risk Manager
$91K - $146K/yr
The Risk Manager is assigned primary responsibility for management the County's insurance programs ... third-party adjusters as appropriate. Manages settlement or recommends settlement of claims in ...
Risk Manager
Key West, FL · On-site
$91K - $146K/yr
The Risk Manager is assigned primary responsibility for management the County's insurance programs ... third-party adjusters as appropriate. Manages settlement or recommends settlement of claims in ...
Risk Manager
Key West, FL · On-site
$91K - $146K/yr
The Risk Manager is assigned primary responsibility for management the County's insurance programs ... third-party adjusters as appropriate. Manages settlement or recommends settlement of claims in ...
Insurance Risk Manager
Miami, FL · On-site
... third-party administrator, insurance broker and/or insurance carrier (directly or through ... Bachelor's degree in Business, Finance, Risk Management or related field from an accredited college ...
Insurance Risk Manager
Miami, FL · On-site
... third-party administrator, insurance broker and/or insurance carrier (directly or through ... Bachelor's degree in Business, Finance, Risk Management or related field from an accredited college ...
Insurance Risk Manager
Miami, FL · On-site
... third-party administrator, insurance broker and/or insurance carrier (directly or through ... Bachelor's degree in Business, Finance, Risk Management or related field from an accredited college ...
Insurance Risk Manager
Miami, FL · On-site
... third-party administrator, insurance broker and/or insurance carrier (directly or through ... Bachelor's degree in Business, Finance, Risk Management or related field from an accredited college ...
Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares ...
Reporting to the IT Enterprise Risk Management Manager, the role maintains policies, assesses risks and controls, coordinates third-party reviews, drafts responses for client guidelines, prepares ...
Risk Management Analyst
Fort Lauderdale, FL · On-site
$59K - $94K/yr
Work requires contact with claimants and the City's third-party administrator (TPA). The employee works under the direction of the Risk Manager and must exercise considerable initiative and ...
Risk Management Analyst
Fort Lauderdale, FL · On-site
$59K - $94K/yr
Work requires contact with claimants and the City's third-party administrator (TPA). The employee works under the direction of the Risk Manager and must exercise considerable initiative and ...
Risk Management Analyst
$59K - $94K/yr
Work requires contact with claimants and the City's third-party administrator (TPA). The employee works under the direction of the Risk Manager and must exercise considerable initiative and ...
Risk Management Analyst
$59K - $94K/yr
Work requires contact with claimants and the City's third-party administrator (TPA). The employee works under the direction of the Risk Manager and must exercise considerable initiative and ...
Third Party & Vendor Cyber Risk * Own the Bank's third party and vendor cybersecurity risk management framework in coordination with Third Party Risk Management, Operations, and Procurement. * Ensure ...
Third Party & Vendor Cyber Risk * Own the Bank's third party and vendor cybersecurity risk management framework in coordination with Third Party Risk Management, Operations, and Procurement. * Ensure ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...
Oversee the Third-Party Risk Management Program (TPRM) and analyze SOC-2 and other reports, mapping to key security controls. * Manage IT security vulnerabilities in alignment with PCI and NIST ...
Oversee the Third-Party Risk Management Program (TPRM) and analyze SOC-2 and other reports, mapping to key security controls. * Manage IT security vulnerabilities in alignment with PCI and NIST ...
Third Party Risk Manager information
See Florida salary details
$38.5K - $46.5K
4% of jobs
$46.5K - $54.6K
6% of jobs
$54.6K - $62.6K
11% of jobs
$65.7K is the 25th percentile. Wages below this are outliers.
$62.6K - $70.7K
11% of jobs
The median wage is $77.1K / yr.
$70.7K - $78.7K
23% of jobs
$78.7K - $86.8K
13% of jobs
$92.1K is the 75th percentile. Wages above this are outliers.
$86.8K - $94.8K
12% of jobs
$94.8K - $102.9K
8% of jobs
$102.9K - $110.9K
6% of jobs
$110.9K - $119K
4% of jobs
$119K - $127K
2% of jobs
$38.5K
$83.4K
$127K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
What is a Third Party Risk Manager?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 24 days ago
Refresco rating
7.1
Based on 58 frontline employees who took The Breakroom Quiz
178th of 381 rated food and drinks producers
Job description
Our vision is both simple and ambitious: to put our drinks on every table.
We are the leading global independent beverage solutions provider. We serve a broad range of national and international retailers as well as Global, National and Emerging (GNE) brands. Our products are distributed worldwide from our production sites in Europe, North America, and Australia. Although our own branding may not appear on the labels of the beverages we produce, there is a good chance you are reading this while sipping one of our drinks.
Our ambition is to continually improve and it's what keeps us at the top of our game. We are solutions-based. We are innovative. We seek out new challenges and conquer them. This is our company ethos, but it's our people's too: Refresco is at the cutting edge of a fast-moving industry because we have passionate people pushing the boundaries of what's best.
Stop and think: how would YOU put our drinks on every table?
Summary Description:
We are seeking a highly motivated and experienced IT GRC Manager to join our team. In this role, you will be responsible for maintaining and improving our IT governance, risk, and compliance (GRC) program, with a focus on SOX compliance, application and data transfer controls, validating the completeness and accuracy of reports, third-party risk management and disaster recovery.
Key Responsibilities:
IT Risk Assessments:
• Conduct comprehensive IT risk assessments, including identifying and analyzing potential threats and vulnerabilities across applications, infrastructure, and data.
• Develop and maintain risk registers, documenting identified risks, their potential impact, and mitigation strategies.
• Collaborate with IT and business stakeholders to prioritize and remediate identified risks.
• Assess impact of IT changes to policies, risks, controls, and governance process (including but not limited to disaster recovery, RCM)
SOX Compliance:
• Maintain and update the Risk and Control Matrix.
• Evaluate the design and monitor the execution of management's SOX controls.
• Participate in business process walkthroughs to identify application controls, reports, and ITGC dependencies/risks.
• Review SOC reports and map control deficiencies to relevant IT risks.
• Ensure all control evidence of operating effectiveness is maintained timely, with appropriate detail for all IT controls; own the development, reporting, completion of control remediation plans
• Train and educate IT teams and control owners on the effective operation of controls
Application and Data Transfer Controls, Report (IPE) Validation:
• Identify the application controls, interfaces/batch jobs and reports key to supporting SOX business processes
• Evaluate the design and effectiveness of application controls.
• Evaluate the design and effectiveness of controls intended to mitigate data transfer errors/incompleteness
• Evaluate the design (completeness and accuracy) of reports used for key controls
Third-Party Risk Management:
• Develop and implement a third-party risk management program.
• Monitor and manage risks associated with third-party relationships.
Disaster Recovery:
• Develop, maintain, and test the IT disaster recovery plan, inclusive of supporting audits and requests for understanding and evidence by 3rd parties
Cyber Security:
• Perform cyber security posture evaluations
• Design and execute strategies to evaluate the ICFR impact of cyber security incidents
• Draft the appropriate disclosures regarding cyber security posture and cyber incidents and response as necessary
Ongoing Regulatory Compliance:
• Ensure compliance with relevant regulations and industry standards (e.g., SOX, NIST).
• Assist with internal and external audits.
• Develop and deliver GRC training to IT and business stakeholders.
Skills/Qualifications:
• Advanced knowledge of SOX controls and compliance; experience implementing or improving SOX
• Strong drive and organizational skills inclusive of project and program management
• Ability to proactively, productively manage diverse stakeholder groups
• Excellent knowledge of business process risks and controls in the manufacturing or consumer sectors preferred
• Technical expertise in ERP system design and operation
• In-depth knowledge of IT governance frameworks (e.g., COBIT, ITIL) and risk management methodologies
• Excellent interpersonal and communication skills, verbal and written
• Strong understanding of SOX requirements and IT general controls (ITGCs).
• Ability to analyze and solve problems, results oriented
• Able to prioritize work, and determine when necessary to switch priorities
• Experience evaluating / governing SAP ITGCs
• Experience building and maintaining processes and controls around IAM tools (SailPoint ISC) would be an asset
Education and Experience:
• Undergraduate degree in Accounting, Information Technology, Computer Science or related technical degree required
• Certified Public Accountant (CPA), Certified Internal Auditor (CIA), Certified Information Systems Auditor (CISA), or Certified in Risk and Information Systems Control (CRISC) designation required (two or more preferred)
• 5+ years relevant work experience in public accounting or 6+ years industry required
• 3+ years working with SOX in the IT domain with or for a company listed on a US market required
• 1.5+ years of IT Audit / IT GRC managerial role preferred
Travel Requirements:
- N/A
A Career with Refresco
Refresco is passionate about empowering leaders who reflect our core values and live by our leadership behaviors. These behaviors encourage effective leadership within the business, and focus on leading courageously, empowering individuals, and driving company growth as one team. Joining our team as a people manager means you'll be encouraged to evolve as a leader who prioritizes the success of both you and your team, to deliver results, whilst bringing your authentic self to work.
Refresco Beverages US, Inc. offers competitive pay and comprehensive benefits, which include:
- Medical/Dental/Vision Insurance
- Health Savings Accounts and Flexible Spending Accounts
- Life and AD&D Insurance
- Pet Insurance
- Legal Benefits
- 401(k) Savings Plan with Company Match
- 12 Paid Holidays, Vacation, and Paid Time Off
- Well-being Benefits
- Discount and Total Reward Programs
Join Refresco TODAY and enjoy a rewarding CAREER!
Any employment agency, person, or entity that submits a résumé to this career site or a hiring manager does so with the understanding that the applicant's résumé will become the property of Refresco Beverages, Inc. Refresco Beverages, Inc. will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person, or entity.
Employment agencies that have agreements with Refresco Beverages, Inc., and have been engaged in a search shall submit résumé to the designated Refresco recruiter or, upon authorization, submit résumé to this career site to be eligible for placement fees.
Refresco Beverages US, Inc. is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity, gender expression, Veteran status, or any other classification protected by federal, state, or local law.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
About Refresco
Sourced by ZipRecruiter
Industry
Food and drink manufacturing
Company size
10,000+ Employees
Headquarters location
Tampa, FL, US