You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and ...
You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and ...
Architect and lead the transformation of the Cyber Third-Party Risk Management (CTPRM) operating model, embedding agentic AI, automation, and intelligent workflows to significantly improve ...
Architect and lead the transformation of the Cyber Third-Party Risk Management (CTPRM) operating model, embedding agentic AI, automation, and intelligent workflows to significantly improve ...
The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies. This role will ...
The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies. This role will ...
KPMG is currently seeking a Lead Specialist, Third Party Risk Management to join our Managed Services practice. Responsibilities: * Interact with onshore engagements and clients directly performing ...
KPMG is currently seeking a Lead Specialist, Third Party Risk Management to join our Managed Services practice. Responsibilities: * Interact with onshore engagements and clients directly performing ...
Risk Analyst I
Atlanta, GA · On-site
Our goal is to establish a centrally managed framework and process that empowers the business to achieve regulatory compliance, maintain visibility over third-party risk posture, and effectively ...
Risk Analyst I
Atlanta, GA · On-site
Our goal is to establish a centrally managed framework and process that empowers the business to achieve regulatory compliance, maintain visibility over third-party risk posture, and effectively ...
Monitor compliance with third-party management policies by reviewing reports and confirming ... Respond promptly to vendor risk management inquiries via email, phone, and Microsoft Teams.
Monitor compliance with third-party management policies by reviewing reports and confirming ... Respond promptly to vendor risk management inquiries via email, phone, and Microsoft Teams.
Perform non-performing Third Party metric root cause analysis and prepare and manage Go to Green plans * Review and challenge data transmission registrations (DTRs) and Third Party risk assessments ...
Perform non-performing Third Party metric root cause analysis and prepare and manage Go to Green plans * Review and challenge data transmission registrations (DTRs) and Third Party risk assessments ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
Performing secondary reviews of business relationship submissions in the Third Party Risk Management (TPRM) Gateway and reinforcing data quality standards * Advising Lead Client Service Partners ...
This position will also be responsible for oversight and program management of third-party risk management and Business Continuity Planning activities for the organization. They will report on these ...
This position will also be responsible for oversight and program management of third-party risk management and Business Continuity Planning activities for the organization. They will report on these ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... expansion opportunities and design integrated risk advisory solutions. * Establish and maintain ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... expansion opportunities and design integrated risk advisory solutions. * Establish and maintain ...
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Cyber Security
Atlanta, GA · On-site
Exposure of vendor-managed assets • Correlate vendor risk intelligence with internal security telemetry • Enable and enhance SOC workflows for third-party risk detections • Design and implement ...
Cyber Security
Atlanta, GA · On-site
Exposure of vendor-managed assets • Correlate vendor risk intelligence with internal security telemetry • Enable and enhance SOC workflows for third-party risk detections • Design and implement ...
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Identify the most important customer problems related to SaaS supply chain risk, third-party access ... Required qualifications * 7+ years of Product Management experience, ideally in B2B SaaS ...
Quick apply
Identify the most important customer problems related to SaaS supply chain risk, third-party access ... Required qualifications * 7+ years of Product Management experience, ideally in B2B SaaS ...
Manager, Third Party Vendor Management
Alpharetta, GA · On-site +1
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking For (Minimum Qualifications) * Minimum of 5 years of experience in procurement, vendor management, or ...
Manager, Third Party Vendor Management
Alpharetta, GA · On-site +1
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking For (Minimum Qualifications) * Minimum of 5 years of experience in procurement, vendor management, or ...
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking For (Minimum Qualifications) * Minimum of 5 years of experience in procurement, vendor management, or ...
Facilitate legal review and Third Party Risk Management Assessment processes. What We are Looking For (Minimum Qualifications) * Minimum of 5 years of experience in procurement, vendor management, or ...
Technical Account Manager
Atlanta, GA · On-site +1
About VISO TRUST VISO TRUST is a venture-backed, high-growth B2B SaaS company transforming how enterprises manage third-party risk. Our AI-native platform replaces legacy, questionnaire-based TPRM ...
Technical Account Manager
Atlanta, GA · On-site +1
About VISO TRUST VISO TRUST is a venture-backed, high-growth B2B SaaS company transforming how enterprises manage third-party risk. Our AI-native platform replaces legacy, questionnaire-based TPRM ...
... risk management, incident response, and infrastructure teams to validate threats, contain incidents and recommend remediation steps. 6. Perform threat modeling for SaaS applications, third-party ...
... risk management, incident response, and infrastructure teams to validate threats, contain incidents and recommend remediation steps. 6. Perform threat modeling for SaaS applications, third-party ...
... risk management, incident response, and infrastructure teams to validate threats, contain incidents and recommend remediation steps. 6. Perform threat modeling for SaaS applications, third-party ...
... risk management, incident response, and infrastructure teams to validate threats, contain incidents and recommend remediation steps. 6. Perform threat modeling for SaaS applications, third-party ...
Third Party Risk Manager information
See Georgia salary details
$43.5K - $52.6K
4% of jobs
$52.6K - $61.7K
6% of jobs
$61.7K - $70.8K
11% of jobs
$74.2K is the 25th percentile. Wages below this are outliers.
$70.8K - $79.9K
11% of jobs
The median wage is $87.1K / yr.
$79.9K - $89K
23% of jobs
$89K - $98.1K
13% of jobs
$104.1K is the 75th percentile. Wages above this are outliers.
$98.1K - $107.2K
12% of jobs
$107.2K - $116.3K
8% of jobs
$116.3K - $125.4K
6% of jobs
$125.4K - $134.4K
4% of jobs
$134.4K - $143.5K
2% of jobs
$43.5K
$94.2K
$143.5K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
What is a Third Party Risk Manager?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

Full-time
Posted 15 days ago
McKinsey & Company rating
8.5
Based on 22 frontline employees who took The Breakroom Quiz
15th of 57 rated business consultants
Job description
YOUR IMPACT
You will lead strategy and program oversight across multiple third-party risk verticals, including suppliers and client-facing collaborators.
You will be responsible for shaping and advancing a unified, end-to-end TPRM framework that supports a diverse and global third-party ecosystem. You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and offboarding governance.
You will ensure that the framework is consistently applied across third-party segments, while incorporating tailored approaches for different risk profiles and engagement models. You will ensure that onboarding processes are efficient, auditable, and aligned with firm risk appetite and user experience expectations.
You will be part of Optimize, McKinsey's global procurement capability, enhancing and protecting the firm's resources and reputation by making responsible buying easy and creating leading solutions and experiences across our third-party ecosystem.You will be joining the Third-Party Risk Strategy pillar of Optimize's Third Party Risk & Social Responsibility team. Thisteam defines and governs the firm's global third-party risk management (TPRM) program, spanning various third-party types and risk domains.
While day-to-day execution is led by the Operations team, you will be accountable for program performance and alignment to strategy. You will assess whether service levels, controls, and processes are operating effectively across verticals, and drive improvements where gaps are identified.
You will define and monitor key program metrics, including service levels, onboarding cycle times, risk coverage, and remediation effectiveness. You will use these insights to optimize performance, reduce risk exposure, and improve the overall third-party experience.
You will partner closely with the governance pillar to inform the development of policies, standards, and control requirements, providing input based on program insights, operational performance, and emerging risks. You will ensure that policies and standards are effectively translated into scalable processes, tools, and workflows across the third-party risk lifecycle. You will stay ahead of evolving regulatory expectations and industry frameworks (e.g., NIST, ISO, SOC, and relevant regulatory guidance), assessing implications for the program and driving necessary enhancements to maintain alignment.
You will own the evolution of third-party risk tooling and digital capabilities, including governance of TPRM platforms, onboarding workflows, data sources, and reporting infrastructure. You will drive the use of data, automation, and analytics to enhance scalability, transparency, and decision-making.
In addition to strategy development, you will lead execution of complex, global initiatives to enhance program capabilities, improve processes, and implement changes across the firm. You will play a key role in strengthening risk management capabilities, including supporting documentation, training, and fostering a strong risk-aware culture.
You will report to the Director of Third Party Risk Strategy and work closely with global stakeholders including Ethics & Compliance, Finance, Legal, Client Service Risk focused specifically on suppliers and client-facing collaborators (CFCs) external entities the firm engages with to deliver products and services, including suppliers, and ecosystem partners. You will be based out of London, Philadelphia, New York, New Jersey, Atlanta, Boston, Miramar, Tampa, or Washington DC office.
YOUR GROWTH
You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.
In return for your drive, determination, and curiosity, we'll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
- Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
- A voice that matters: From day one, we value your ideas and contributions. You'll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
- Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm's diversity fuels creativity and helps us come up with the best solutions. Plus, you'll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
- Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
YOUR QUALIFICATIONS AND SKILLS
- 10+ years of professional experience with a demonstrable record of impact, including 10+ years in third-party risk management, compliance, or a related field, ideally within a global organization
- Deep expertise in third-party risk management frameworks, including lifecycle design, onboarding processes, and internal control environments across multiple third-party segments
- Experience designing, governing, or advancing enterprise risk programs, with accountability for program performance and outcomes
- Experience in a professional services or consulting environment strongly preferred
- Strong understanding of global regulatory expectations and industry frameworks related to third-party risk (e.g., NIST, ISO, SOC, and relevant regulatory guidance)
- Experience with TPRM/GRC platforms and driving digital enablement, including workflow design, data, reporting, and automation
- Exceptional analytical and problem-solving skills, with the ability to translate complex data into actionable insights
- Excellent judgment and exceptional integrity, as well as distinctive interpersonal and collaborative skills
- Proven ability to lead large, cross-functional initiatives and drive execution in complex, global environments
- Curious mindset and demonstrated ability to learn new concepts and ideas, and to apply those concepts across multiple content areas
- Strong professional computing skills, including Microsoft Office products (i.e. Excel, PowerPoint, Visio)
- Comfortable with ambiguity in a work-setting, knowing how to address and manage unpredictable outcomes
- Superior communication & interpersonal skills, including the ability to present to a global audience on a regular basis, build and maintain highly effective and collaborative relationships
Please review the additional requirements regarding essential job functions of McKinsey colleagues.
Our unwavering commitment to integrity drives everything we do, guiding us to always act in the best interests of our clients, our people, and the communities we serve.
What McKinsey & Company employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom