1

Third Party Risk Manager Jobs in Kentucky (NOW HIRING)

Establishing and leading the third-party risk management program, including vendor tiering and assessments * Coordinating regulatory and audit engagements (internal and external) * Partnering across ...

Establishing and leading the third-party risk management program, including vendor tiering and assessments * Coordinating regulatory and audit engagements (internal and external) * Partnering across ...

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional design and configuration of ServiceNow solutions, including forms, workflows, notifications, service ...

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...

Cyber Manager - ServiceNow

Louisville, KY · On-site

$106K - $143K/yr

... Third-Party Risk Management workstreams in partnership with architects and product owners • Managing stakeholder engagement and executive communications; facilitating decisions, change control, and ...

... Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions, change control, and ...

$41.75 - $55.75/hr

Support our IT risk management program to ensure both internal and third-party IT risks are identified, assessed, prioritized and remediated. Raise awareness within the organization of IT governance, ...

The Third-Party Logistics Lead will collaborate with 3PL Supplier to ensure Raytheon Logistics Key ... Project Management experience * Master's degree in supply chain, Business, or Logistics * APICS ...

next page

Showing results 1-20

Third Party Risk Manager information

See Kentucky salary details

$44.7K

$96.9K

$147.6K

How much do third party risk manager jobs pay per year?

As of Jun 16, 2026, the average yearly pay for third party risk manager in Kentucky is $96,889.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,200.00 and $112,000.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a Third Party Risk Manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
What are popular job titles related to Third Party Risk Manager jobs in Kentucky? For Third Party Risk Manager jobs in Kentucky, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Manager jobs in Kentucky look for? The top searched job categories for Third Party Risk Manager jobs in Kentucky are:
What cities in Kentucky are hiring for Third Party Risk Manager jobs? Cities in Kentucky with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Kentucky as of June 2026, with employment types broken down into 96% Full Time, 3% Part Time, and 1% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $96,889 per year, or $46.6 per hour.
Senior Manager GRC

Senior Manager GRC

Papa John's

Louisville, KY • On-site

Full-time

Posted 10 days ago


Papa John's rating

4.7

Company rating: 4.7 out of 10

Based on 733 frontline employees who took The Breakroom Quiz

21st of 22 rated food delivery companies


Job description

What's Unique About You Is What Makes Us Better! Diversity is our strength and competitive advantage. Bring your flavor to the Papa John's team today!

Position Overview

Papa Johns is seeking a Senior Manager, Governance, Risk & Compliance to establish and operate the cybersecurity governance and risk control plane across the enterprise. This role is responsible for enabling risk-informed decision making, clear accountability, and consistent control governance across business, IT, cloud, and third-party environments. The ideal candidate will bring strong judgment, the ability to operate across organizational boundaries, and experience building and scaling GRC capabilities in complex environments.

Responsibilities

The primary responsibilities of this role include:

  • Establishing and operating the enterprise cybersecurity risk management program, including risk identification, prioritization, and tracking
  • Defining and enforcing risk acceptance, escalation, and accountability frameworks
  • Developing executive and board-level risk reporting aligned to business impact
  • Defining and governing cybersecurity policies, standards, and control frameworks aligned to industry standard frameworks
  • Ensuring consistent control implementation and enforcement across IT, cloud, and business environments
  • Leading exception management processes to ensure risk is explicitly understood and accepted at the right levels
  • Establishing and leading the third-party risk management program, including vendor tiering and assessments
  • Coordinating regulatory and audit engagements (internal and external)
  • Partnering across Security, IT, Legal, Compliance, and Procurement (among others as relevant) to align risk and control expectations
  • Establishing and governing the cybersecurity awareness and training program, ensuring it is aligned to enterprise risk and tailored user roles
  • Overseeing control validation, testing, and assurance activities
  • Ensuring governance of vulnerability management, logging, and detection capabilities
  • Driving continuous improvement through risk insights, incident learnings, and control effectiveness reviews
  • Managing and optimizing budget and resources to support governance, risk, and compliance capabilities

Qualifications

The successful candidate will possess the following:

  • 6-10+ years of experience in cybersecurity risk management
  • Proven leadership experience in building, scaling, and maturing teams and operating models
  • Strong understanding of cybersecurity control frameworks
  • Demonstrated ability to translate technical risk into business impact and action
  • Experience building or maturing GRC programs in complex organizations
  • Strong judgment in prioritization, tradeoff decisions, and stakeholder alignment
  • Experience supporting or leading SOX ITGC and/or application control environments in a complex organization
  • Experience establishing or evolving security awareness and behavior change programs
  • Excellent communication skills and ability to influence across technical and business stakeholders
  • Experience working with third-party risk, audit, and compliance functions

Day in the Life

This role is less about managing a checklist and more about orchestrating how the organization understands and acts on risk.

A typical day may include:

  • Reviewing the enterprise risk register, identifying where risks are aging, stuck, or no longer aligned to business priorities
  • Coaching and developing team members and leaders, ensuring clarity in priorities, accountability, and execution
  • Meeting with Security and IT leaders to challenge and refine risk prioritization, ensuring the highest-impact issues are being addressed first
  • Partnering with a business or product team to translate a technical control gap into business impact, helping them understand tradeoffs and required actions
  • Working through a risk acceptance decision, ensuring the right level of leadership is engaged and the decision is documented and understood
  • Aligning with Procurement and Legal on a high-risk third-party engagement, ensuring appropriate controls and risk mitigation strategies are in place
  • Coordinating with vulnerability management, detection, or testing teams to ensure findings are being tracked, prioritized, and driven to resolution
  • Preparing or refining executive-level reporting, focusing on what has improved, what remains at risk, and where decisions are needed
  • Resolving cross-team friction where ownership, accountability, or priorities are unclear, bringing structure and clarity to move work forward

Work Environment

This is a leadership role operating across a complex, cross-functional environment. Success requires the ability to influence without authority, bring clarity to ambiguity, and align diverse stakeholders toward common risk outcomes.

Our Values

  • EVERYONE BELONGS - We believe connectedness and belonging are the essential ingredients to our success.
  • DO THE RIGHT THING -We are relentlessly focused on quality and integrity and make the right choices, even when it's difficult.
  • PEOPLE FIRST - To craft positive experiences for our customers, we take care of each other first.
  • INNOVATE TO WIN - We champion and challenge for a better way in all we do.
  • HAVE FUN - We find joy, create meaningful impact and celebrate the journey together

Our Core Competencies

  • EVERYONE BELONGS - We believe connectedness and belonging are the essential ingredients to our success.
  • DO THE RIGHT THING -We are relentlessly focused on quality and integrity and make the right choices, even when it's difficult.
  • PEOPLE FIRST - To craft positive experiences for our customers, we take care of each other first.
  • INNOVATE TO WIN - We champion and challenge for a better way in all we do.
  • HAVE FUN - We find joy, create meaningful impact and celebrate the journey together

Papa Johns is an equal opportunity employer.

Papa Johns is a federal contractor that participates in the E-Verify program to confirm employment eligibility for each new team member. We also comply with all Right to Work requirements. Official E-Verify and Right to Work notices are available for applicants to review in both English and Spanish.

Everybody loves pizza, which means they also love the people who are behind the scenes working to deliver it. This is complex and challenging work - but let's face it - it's also pizza! If you want a fulfilling career with a company that's always moving forward, we're the right place.

Papa John's is a Federal Contract employer who participates in E-Verify to confirm employment eligibility for each new team member. For more information please view the following PDFs:E-Verify Poster (English)-Right to Work Poster (English)-E-Verify Poster (Spanish)- Right to Work Poster (Spanish) Papa John's is an Affirmative Action and Equal Opportunity Employer. For more information please click on the followingPDF. Seeterms & conditionsfor site use.


What Papa John's employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom