You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and ...
You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and ...
The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies. This role will ...
The GPI IT Compliance team is seeking an experienced professional to oversee and manage various tasks related to GPI's IT/OT Third Party Risk Management practices and technologies. This role will ...
Technical Program Manager, Third Party Risk Management, Data Centers
Atlanta, GA · On-site
$124K - $160K/yr
As a Technical Program Manager for Third Party Risk Management, you will work with our risk coordinators, procurement teams, and external partners to maintain an accurate third-party risk profile.
Technical Program Manager, Third Party Risk Management, Data Centers
Atlanta, GA · On-site
$124K - $160K/yr
As a Technical Program Manager for Third Party Risk Management, you will work with our risk coordinators, procurement teams, and external partners to maintain an accurate third-party risk profile.
Bank Operational Risk Manager
Alpharetta, GA · On-site
$120K/yr
Bank Operational Risk Manager - First Century Bank First Century Bank is seeking a full-time ... This individual will also support ongoing activities to oversee and monitor third party risk. This ...
Quick apply
Bank Operational Risk Manager
Alpharetta, GA · On-site
$120K/yr
Bank Operational Risk Manager - First Century Bank First Century Bank is seeking a full-time ... This individual will also support ongoing activities to oversee and monitor third party risk. This ...
Bank Operational Risk Manager
Alpharetta, GA · On-site
$120K/yr
Bank Operational Risk Manager - First Century Bank First Century Bank is seeking a full-time ... This individual will also support ongoing activities to oversee and monitor third party risk. This ...
Bank Operational Risk Manager
Alpharetta, GA · On-site
$120K/yr
Bank Operational Risk Manager - First Century Bank First Century Bank is seeking a full-time ... This individual will also support ongoing activities to oversee and monitor third party risk. This ...
Third Party Cybersecurity GRC Advisor
Atlanta, GA · Hybrid
$106K - $144K/yr
Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the ...
Third Party Cybersecurity GRC Advisor
Atlanta, GA · Hybrid
$106K - $144K/yr
Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the ...
Perform non-performing Third Party metric root cause analysis and prepare and manage Go to Green plans * Review and challenge data transmission registrations (DTRs) and Third Party risk assessments ...
Perform non-performing Third Party metric root cause analysis and prepare and manage Go to Green plans * Review and challenge data transmission registrations (DTRs) and Third Party risk assessments ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in ...
Third Party Cybersecurity GRC Advisor Information Security Advisor ( Third Party Cybersecurity GRC Advisor ) Information Security Risk Management Hybrid 1: This role requires associates to be in ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Anticipated End Date: 2026-06-12 Position Title: Sr. Third Party Cybersecurity GRC Analyst Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Anticipated End Date: 2026-06-12 Position Title: Sr. Third Party Cybersecurity GRC Analyst Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · On-site
$96K - $124K/yr
Anticipated End Date: 2026-06-12 Position Title: Sr. Third Party Cybersecurity GRC Analyst Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst ) Information Security Risk Management ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · On-site
$96K - $124K/yr
Anticipated End Date: 2026-06-12 Position Title: Sr. Third Party Cybersecurity GRC Analyst Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst ) Information Security Risk Management ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This position will also be responsible for oversight and program management of third-party risk management and Business Continuity Planning activities for the organization. They will report on these ...
This position will also be responsible for oversight and program management of third-party risk management and Business Continuity Planning activities for the organization. They will report on these ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Senior GRC Analyst
Atlanta, GA · On-site
This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis ...
Sr. Third Party Cybersecurity GRC Analyst
Atlanta, GA · Hybrid
$96K - $124K/yr
Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis ...
Third Party Risk Manager information
See Georgia salary details
$43.5K - $52.6K
4% of jobs
$52.6K - $61.7K
6% of jobs
$61.7K - $70.8K
11% of jobs
$74.2K is the 25th percentile. Wages below this are outliers.
$70.8K - $79.9K
11% of jobs
The median wage is $87.1K / yr.
$79.9K - $89K
23% of jobs
$89K - $98.1K
13% of jobs
$104.1K is the 75th percentile. Wages above this are outliers.
$98.1K - $107.2K
12% of jobs
$107.2K - $116.3K
8% of jobs
$116.3K - $125.4K
6% of jobs
$125.4K - $134.4K
4% of jobs
$134.4K - $143.5K
2% of jobs
$43.5K
$94.2K
$143.5K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
What is a Third Party Risk Manager?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

Full-time
Posted 25 days ago
McKinsey & Company rating
8.5
Based on 22 frontline employees who took The Breakroom Quiz
15th of 57 rated business consultants
Job description
YOUR IMPACT
You will lead strategy and program oversight across multiple third-party risk verticals, including suppliers and client-facing collaborators.
You will be responsible for shaping and advancing a unified, end-to-end TPRM framework that supports a diverse and global third-party ecosystem. You will own the design and evolution of the firm's third-party risk lifecycle, including risk identification, onboarding due diligence, risk tiering, ongoing monitoring, issue management, and offboarding governance.
You will ensure that the framework is consistently applied across third-party segments, while incorporating tailored approaches for different risk profiles and engagement models. You will ensure that onboarding processes are efficient, auditable, and aligned with firm risk appetite and user experience expectations.
You will be part of Optimize, McKinsey's global procurement capability, enhancing and protecting the firm's resources and reputation by making responsible buying easy and creating leading solutions and experiences across our third-party ecosystem.You will be joining the Third-Party Risk Strategy pillar of Optimize's Third Party Risk & Social Responsibility team. Thisteam defines and governs the firm's global third-party risk management (TPRM) program, spanning various third-party types and risk domains.
While day-to-day execution is led by the Operations team, you will be accountable for program performance and alignment to strategy. You will assess whether service levels, controls, and processes are operating effectively across verticals, and drive improvements where gaps are identified.
You will define and monitor key program metrics, including service levels, onboarding cycle times, risk coverage, and remediation effectiveness. You will use these insights to optimize performance, reduce risk exposure, and improve the overall third-party experience.
You will partner closely with the governance pillar to inform the development of policies, standards, and control requirements, providing input based on program insights, operational performance, and emerging risks. You will ensure that policies and standards are effectively translated into scalable processes, tools, and workflows across the third-party risk lifecycle. You will stay ahead of evolving regulatory expectations and industry frameworks (e.g., NIST, ISO, SOC, and relevant regulatory guidance), assessing implications for the program and driving necessary enhancements to maintain alignment.
You will own the evolution of third-party risk tooling and digital capabilities, including governance of TPRM platforms, onboarding workflows, data sources, and reporting infrastructure. You will drive the use of data, automation, and analytics to enhance scalability, transparency, and decision-making.
In addition to strategy development, you will lead execution of complex, global initiatives to enhance program capabilities, improve processes, and implement changes across the firm. You will play a key role in strengthening risk management capabilities, including supporting documentation, training, and fostering a strong risk-aware culture.
You will report to the Director of Third Party Risk Strategy and work closely with global stakeholders including Ethics & Compliance, Finance, Legal, Client Service Risk focused specifically on suppliers and client-facing collaborators (CFCs) external entities the firm engages with to deliver products and services, including suppliers, and ecosystem partners. You will be based out of London, Philadelphia, New York, New Jersey, Atlanta, Boston, Miramar, Tampa, or Washington DC office.
YOUR GROWTH
You are someone who thrives in a high-performance environment, bringing a growth mindset and entrepreneurial spirit to tackle meaningful challenges that have a real impact.
In return for your drive, determination, and curiosity, we'll provide the resources, mentorship, and opportunities to help you quickly broaden your expertise, grow into a well-rounded professional, and contribute to work that truly makes a difference.
When you join us, you will have:
- Continuous learning: Our learning and apprenticeship culture, backed by structured programs, is all about helping you grow while creating an environment where feedback is clear, actionable, and focused on your development. The real magic happens when you take the input from others to heart and embrace the fast-paced learning experience, owning your journey.
- A voice that matters: From day one, we value your ideas and contributions. You'll make a tangible impact by offering innovative ideas and practical solutions, all while upholding our unwavering commitment to ethics and integrity. We not only encourage diverse perspectives, but they are critical in driving us toward the best possible outcomes.
- Global community: With colleagues across 65+ countries and over 100 different nationalities, our firm's diversity fuels creativity and helps us come up with the best solutions. Plus, you'll have the opportunity to learn from exceptional colleagues with diverse backgrounds and experiences.
- Exceptional benefits: On top of a competitive salary (based on your location, experience, and skills), we provide a comprehensive benefits package to enable holistic well-being for you and your family.
YOUR QUALIFICATIONS AND SKILLS
- 10+ years of professional experience with a demonstrable record of impact, including 10+ years in third-party risk management, compliance, or a related field, ideally within a global organization
- Deep expertise in third-party risk management frameworks, including lifecycle design, onboarding processes, and internal control environments across multiple third-party segments
- Experience designing, governing, or advancing enterprise risk programs, with accountability for program performance and outcomes
- Experience in a professional services or consulting environment strongly preferred
- Strong understanding of global regulatory expectations and industry frameworks related to third-party risk (e.g., NIST, ISO, SOC, and relevant regulatory guidance)
- Experience with TPRM/GRC platforms and driving digital enablement, including workflow design, data, reporting, and automation
- Exceptional analytical and problem-solving skills, with the ability to translate complex data into actionable insights
- Excellent judgment and exceptional integrity, as well as distinctive interpersonal and collaborative skills
- Proven ability to lead large, cross-functional initiatives and drive execution in complex, global environments
- Curious mindset and demonstrated ability to learn new concepts and ideas, and to apply those concepts across multiple content areas
- Strong professional computing skills, including Microsoft Office products (i.e. Excel, PowerPoint, Visio)
- Comfortable with ambiguity in a work-setting, knowing how to address and manage unpredictable outcomes
- Superior communication & interpersonal skills, including the ability to present to a global audience on a regular basis, build and maintain highly effective and collaborative relationships
Please review the additional requirements regarding essential job functions of McKinsey colleagues.
Our unwavering commitment to integrity drives everything we do, guiding us to always act in the best interests of our clients, our people, and the communities we serve.
What McKinsey & Company employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom