This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery ...
This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery ...
This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery ...
This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery ...
This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery ...
This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery ...
Monitor and manage all supplier alerts provided by third party information services * Respond to and advise management of risk alerts, potential impacts of the risk alert and suggest corrective ...
Quick apply
Monitor and manage all supplier alerts provided by third party information services * Respond to and advise management of risk alerts, potential impacts of the risk alert and suggest corrective ...
Detect and manage accumulation risk ; identify geographic and peril "hot spots" and provide real ... Expertise with third-party catastrophe models (RMS, AIR, etc) * Expert level knowledge of natural ...
Quick apply
Detect and manage accumulation risk ; identify geographic and peril "hot spots" and provide real ... Expertise with third-party catastrophe models (RMS, AIR, etc) * Expert level knowledge of natural ...
Detect and manage accumulation risk ; identify geographic and peril "hot spots" and provide real ... Expertise with third-party catastrophe models (RMS, AIR, etc) * Expert level knowledge of natural ...
Detect and manage accumulation risk ; identify geographic and peril "hot spots" and provide real ... Expertise with third-party catastrophe models (RMS, AIR, etc) * Expert level knowledge of natural ...
Third Party Liability Analyst - US Remote
Anthony, KS · Remote
$30.50K - $43.50K/yr
Summary The Third-Party Liability (TPL) department's primary function is to pursue and investigate ... A candidate must be able to independently manage workload with minimal supervision. * A candidate ...
Third Party Liability Analyst - US Remote
Anthony, KS · Remote
$30.50K - $43.50K/yr
Summary The Third-Party Liability (TPL) department's primary function is to pursue and investigate ... A candidate must be able to independently manage workload with minimal supervision. * A candidate ...
Chief Information Officer
Salina, KS · On-site
... Ensures Third-Party & Vendor Risk Management: establishes expectations for vendor security and compliance; evaluates and monitors third-party risk; and ensures vendor relationships align with ...
Chief Information Officer
Salina, KS · On-site
... Ensures Third-Party & Vendor Risk Management: establishes expectations for vendor security and compliance; evaluates and monitors third-party risk; and ensures vendor relationships align with ...
... management, providing actionable insights to guide strategic decision-making and risk mitigation efforts. * Coordinate with brokers, insurers, and third-party advisors to ensure optimal insurance ...
... management, providing actionable insights to guide strategic decision-making and risk mitigation efforts. * Coordinate with brokers, insurers, and third-party advisors to ensure optimal insurance ...
Serve as the primary administrator and process owner for 3rd party contractor safety management software. Ensure the platform is configured to reflect site-specific risk profiles and compliance ...
Serve as the primary administrator and process owner for 3rd party contractor safety management software. Ensure the platform is configured to reflect site-specific risk profiles and compliance ...
... management, providing actionable insights to guide strategic decision-making and risk mitigation efforts. * Coordinate with brokers, insurers, and third-party advisors to ensure optimal insurance ...
... management, providing actionable insights to guide strategic decision-making and risk mitigation efforts. * Coordinate with brokers, insurers, and third-party advisors to ensure optimal insurance ...
Proven experience advising banks on operational resilience, including operational risk, business continuity, third-party risk management, and regulatory resilience frameworks. * Experience managing ...
Proven experience advising banks on operational resilience, including operational risk, business continuity, third-party risk management, and regulatory resilience frameworks. * Experience managing ...
Proven experience advising senior executives on operational resilience, including operational risk, business continuity, third-party risk management, and regulatory resilience frameworks.
Proven experience advising senior executives on operational resilience, including operational risk, business continuity, third-party risk management, and regulatory resilience frameworks.
Vice President - Compliance
Lenexa, KS · Remote
$117.20K - $157.20K/yr
... Third-Party Risk Management Identity Theft Red Flags Rule * Consumer Protection & UDAAP UDAAP Standards Debt Collection Rules CFPB Complaint Management Expectations Advertising & Marketing Compliance
Vice President - Compliance
Lenexa, KS · Remote
$117.20K - $157.20K/yr
... Third-Party Risk Management Identity Theft Red Flags Rule * Consumer Protection & UDAAP UDAAP Standards Debt Collection Rules CFPB Complaint Management Expectations Advertising & Marketing Compliance
Vice President - Compliance
Lenexa, KS · On-site
$117.20K - $157.20K/yr
... Third-Party Risk Management Identity Theft Red Flags Rule * Consumer Protection & UDAAP UDAAP Standards Debt Collection Rules CFPB Complaint Management Expectations Advertising & Marketing Compliance
Vice President - Compliance
Lenexa, KS · On-site
$117.20K - $157.20K/yr
... Third-Party Risk Management Identity Theft Red Flags Rule * Consumer Protection & UDAAP UDAAP Standards Debt Collection Rules CFPB Complaint Management Expectations Advertising & Marketing Compliance
... third-party excavation/activity, and other conditions that could threaten pipeline/facility integrity. The role emphasizes relationship management and risk-based communications across the asset ...
... third-party excavation/activity, and other conditions that could threaten pipeline/facility integrity. The role emphasizes relationship management and risk-based communications across the asset ...
Vice President - Compliance
Lenexa, KS · Remote
$117.20K - $157.20K/yr
... Third-Party Risk Management Identity Theft Red Flags Rule * Consumer Protection & UDAAP UDAAP Standards Debt Collection Rules CFPB Complaint Management Expectations Advertising & Marketing Compliance
Vice President - Compliance
Lenexa, KS · Remote
$117.20K - $157.20K/yr
... Third-Party Risk Management Identity Theft Red Flags Rule * Consumer Protection & UDAAP UDAAP Standards Debt Collection Rules CFPB Complaint Management Expectations Advertising & Marketing Compliance
$98.30K - $134.70K/yr
Own vendor security and third-party risk management, including assessments, risk evaluation, and mitigation strategies * Lead audit readiness and execution for SOC 2 and ISO 27001, including control ...
$98.30K - $134.70K/yr
Own vendor security and third-party risk management, including assessments, risk evaluation, and mitigation strategies * Lead audit readiness and execution for SOC 2 and ISO 27001, including control ...
Personal Risk Advisor
Overland Park, KS · On-site
$115K - $150K/yr
Design risk management insurance programs to protect the personal assets, exposures and lifestyles ... Engage, introduce and position value-added third-party subject matter experts in response to client ...
Personal Risk Advisor
Overland Park, KS · On-site
$115K - $150K/yr
Design risk management insurance programs to protect the personal assets, exposures and lifestyles ... Engage, introduce and position value-added third-party subject matter experts in response to client ...
... Management (VRM) program by reviewing third-party security documentation, SOC reports, and due-diligence artifacts in accordance with established risk assessment standards. • Maintain and update ...
... Management (VRM) program by reviewing third-party security documentation, SOC reports, and due-diligence artifacts in accordance with established risk assessment standards. • Maintain and update ...
Third Party Risk Manager information
See Kansas salary details
$45.9K - $55.5K
4% of jobs
$55.5K - $65.1K
6% of jobs
$65.1K - $74.8K
11% of jobs
$78.4K is the 25th percentile. Wages below this are outliers.
$74.8K - $84.4K
11% of jobs
The median wage is $92K / yr.
$84.4K - $94K
23% of jobs
$94K - $103.6K
13% of jobs
$109.9K is the 75th percentile. Wages above this are outliers.
$103.6K - $113.2K
12% of jobs
$113.2K - $122.8K
8% of jobs
$122.8K - $132.4K
6% of jobs
$132.4K - $142K
4% of jobs
$142K - $151.6K
2% of jobs
$45.9K
$99.5K
$151.6K
How much do third party risk manager jobs pay per year?
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?
What is a Third Party Risk Manager?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

Full-time
Posted 6 days ago
CommunityAmerica Credit Union rating
8.5
Based on 5 frontline employees who took The Breakroom Quiz
Job description
The Director of Enterprise Risk Management (“ERM”) is responsible for developing, implementing, and overseeing the credit union’s enterprise-wide risk management program across a complex, nationwide financial institution with $9 billion in assets. This position involves managing and mitigating risk across all organizational departments and channels. This role provides strategic and operational leadership of enterprise risk functions, including physical security, vendor and third-party risk management, business continuity and disaster recovery, emergency preparedness, operational risk assessments, risk scoring methodologies, and enterprise tabletop exercises.
The Director of ERM partners closely with executive leadership, business units and regulators to identify, assess, mitigate, and monitor risks that could impact the organization’s operations, reputation, members, employees, or strategic objectives.
This position requires a proactive leader who can build scalable enterprise risk management frameworks while supporting innovation, growth, and operational resilience across a geographically dispersed organization.
Enterprise Risk Management
- Lead and administer the credit union’s enterprise risk management framework, including risk identification, assessment, mitigation, monitoring, continual improvement, and reporting activities.
- Develop and maintain enterprise risk methodologies, risk scoring models, risk appetite metrics, and key risk indicators (KRIs).
- Coordinate enterprise-wide risk assessments, ensure risks are appropriately documented, tracked, and monitor risk metrics to ensure timely escalation and containment of concerns.
- Monitor and assess the impact of enterprise risks, ensuring effective risk identification, prioritization, and mitigation strategies are in place across all organizational functions, creating a unified approach to risk management throughout the credit union.
- Oversee swift triage, containment, and resolution efforts across cross-functional teams.
- Lead root-cause investigations and lessons learned when incidents occur.
- Manage remediation, recommend and validate risk reduction actions and monitor for effectiveness.
- Provide strategic guidance and data-backed reports, dashboards, and presentations for executive leadership ensuring they are informed of the emerging risks, risk mitigation strategies, and the overall risk landscape.
- Assess risks associated with strategic objectives and key initiatives, ensuring informed decision-making by integrating risk analysis into planning processes and confirming that all credit union initiatives are supported by thorough, data-driven risk assessments.
- Stay ahead of emerging risk trends, evaluate new technologies, and ensure that enterprise risk management frameworks remain agile to address evolving threats, safeguarding the credit union’s reputation, and financial stability.
- Support executive leadership in defining and refining the credit union’s risk appetite and tolerance, ensuring that risk management practices align with the credit union’s mission, vision, and business objectives.
- Promote a strong culture of risk awareness and accountability throughout the organization by collaborating with department heads across the organization to integrate risk management practices into operational processes, ensuring consistency, accuracy, and compliance throughout the credit union’s operations.
Business Continuity, Disaster Recovery & Emergency Management
- Oversee the credit union’s business continuity, disaster recovery, and emergency preparedness programs.
- Lead and maintain the enterprise Business Impact Analysis (BIA) program to identify critical processes, recovery time objectives, recovery point objectives, and resource dependencies.
- Ensure disaster recovery and business continuity plans are maintained, tested, and updated regularly.
- Coordinate and facilitate enterprise-wide tabletop exercises, incident simulations, and continuity testing.
- Lead response coordination during operational disruptions, emergencies, or crisis events.
- Assess and monitor third-party and vendor business continuity capabilities to ensure resilience across critical external dependencies.
- Partner with Information Security, Facilities, Operations, and executive leadership to strengthen organizational resilience.
- Establish and track recovery priorities and service restoration timelines to minimize operational and member impact during disruptions.
- Provide reporting and insights to executive leadership on continuity risks, testing results, gaps, and remediation progress.
Vendor & Third-Party Risk Management
- Direct the third-party/vendor risk management program, including risk assessments, due diligence, contract review coordination, ongoing monitoring, and issue remediation.
- Assess and validate vendors’ information security, business continuity, and disaster recovery capabilities to ensure resilience of outsourced services.
- Establish and maintain a risk-tiering framework to classify vendors based on criticality, inherent risk, and impact to operations and member services.
- Ensure vendor oversight activities align with applicable regulatory guidance, company policies, and industry best practices.
- Track, escalate, and report third-party risks, control gaps, and remediation efforts to executive leadership and governance committees.
- Collaborate with Legal, Procurement, Compliance, Information Security, and business owners regarding vendor governance and risk mitigation.
- Monitor critical vendors and concentration risks affecting business operations.
- Drive continuous improvement of the vendor risk management program by incorporating regulatory updates, industry best practices, and lessons learned.
Physical Security
- Provide strategic oversight of the enterprise physical security program, including policies, standards, and risk governance for all locations nationwide.
- Lead and develop physical security leadership and staff, ensuring appropriate staffing models, capabilities, and performance aligned with organizational risk tolerance and regulatory expectations.
- Oversee the effectiveness of physical security controls, including access management, surveillance, alarm systems, and incident response programs, ensuring risks are identified, prioritized, and addressed.
- Oversee access governance, including role-based access, periodic reviews, and segregation of duties, to ensure appropriate controls over physical entry points.
- Ensure compliance with applicable regulatory requirements and industry standards related to physical security, workplace safety, and facility protection.
- Monitor and analyze physical security incidents, trends, and threat intelligence to proactively address emerging risks and enhance defensive strategies.
- Coordinate with third-party security vendors and service providers to ensure consistent service delivery, performance standards, and risk management across all locations.
- Partner with Facilities, Operations, Human Resources, and executive leadership to support employee and member safety, workplace security, and incident preparedness across the organization.
- Establish and maintain crisis management and workplace safety frameworks, including escalation protocols, response playbooks, and postincident review processes to promote continuous improvement.
Governance & Regulatory Coordination
- Support regulatory examinations, audits, and independent reviews related to enterprise risk functions.
- Maintain awareness of evolving regulatory expectations impacting enterprise risk management and operational resilience.
- Assist in developing policies, procedures, and governance standards related to risk management functions.
- Coordinate with organizational departments to ensure alignment across risk disciplines.
Leadership & Strategic Planning
- Lead, mentor, and develop risk management personnel and cross-functional teams.
- Build scalable risk management processes suitable for a growing and increasingly complex financial institution.
- Participate in strategic initiatives, mergers, acquisitions, and organizational projects from a risk management perspective.
- Serve as a trusted advisor to executive leadership regarding operational and strategic risk matters.
- Performs other duties as assigned.
Required Knowledge, Skills & Abilities:
- Strong understanding of enterprise risk management frameworks and operational resilience principles.
- Ability to balance risk mitigation with strategic and operational objectives.
- Excellent leadership, analytical, communication, presentation, project management, and organizational skills.
- Ability to influence and drive accountability across business units without direct authority.
- Strong business acumen with the ability to translate complex risk concepts into actionable insights for executive leadership.
- Strong knowledge of NCUA regulations, FFIEC expectations, and financial institution risk management practices.
- Proficiency in developing and leveraging metrics, dashboard, and reporting to support risk-informed decision-making.
- Strong problem-solving and decision-making capabilities under pressure.
- Ability to manage multiple complex initiatives simultaneously.
- High level of professionalism, discretion, and judgment.
- Strategic thinker with operational discipline.
- Collaborative and solutions-oriented leadership style.
- Ability to thrive in a fast-paced, evolving regulatory and operational environment.
- Professional presence with the ability to communicate effectively with stakeholders, with regulators and executive leadership and collaborate effectively across all organizational levels.