1

Third Party Risk Manager Jobs in New York (NOW HIRING)

The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across ...

The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across ...

The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across ...

Risk Manager

New York, NY ยท On-site

$140K - $155K/yr

As a Risk Manager, you will own a portfolio of risk processes, perform risk assessments, and ... Proactively monitor risks related to third-party vendors. * Follow up on open issues to drive ...

Spanning commercial risk support, third-party risk management, controls assurance, AI safety operations, and risk issue management, this role serves as the operational center of gravity for the Risk ...

ServiceNow Risk Platform Manager

Stamford, CT ยท On-site

$152K - $250K/yr

Third-Party Risk Management (TPRM) * Model Risk Management (MRM), where applicable * Collaborate with the ServiceNow platform team to establish and maintain platform governance, standards, and ...

ServiceNow Risk Platform Manager

Holmdel, NJ ยท On-site

$152K - $250K/yr

Third-Party Risk Management (TPRM) * Model Risk Management (MRM), where applicable * Collaborate with the ServiceNow platform team to establish and maintain platform governance, standards, and ...

Showing results 41-60

Third Party Risk Manager information

See New York salary details

$56.3K

$122K

$186K

How much do third party risk manager jobs pay per year?

As of Sep 6, 2026, the average yearly pay for third party risk manager in New York is $122,046.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,500.00 and $141,100.00 per year, depending on experience, location, and employer.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

Is third party risk manager a good career?

A third party risk manager plays a key role in assessing and mitigating risks associated with external vendors and partners, often requiring knowledge of compliance standards and risk management tools. The role offers opportunities for advancement in industries such as finance, healthcare, and technology, with a growing demand for professionals skilled in risk assessment and regulatory requirements. It can be a stable and rewarding career for those with strong analytical skills and attention to detail.

What cities in New York are hiring for Third Party Risk Manager jobs?

Cities in New York with the most Third Party Risk Manager job openings:

Infographic showing various Third Party Risk Manager job openings in New York as of August 2026, with employment types broken down into 86% Full Time, 13% Part Time, and 1% Contract. Highlights an 83% Physical, 2% Hybrid, and 15% Remote job distribution, with an average salary of $122,046 per year, or $58.7 per hour.

Third Party Information Security Analyst

SUMITOMO MITSUI TRUST BANK, LIMITED

Manhattan, NY โ€ข On-site

$90K - $125K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 15 days ago


Key responsibilities

  • Conduct initial and continuous information security risk assessments of third (Nth) parties.

  • Review third party provided security documentation including SOC reports, ISO 27001 certifications, security questionnaires, and Business Continuity and Disaster Recovery documentation.

  • Perform ongoing monitoring of information security-related incidents involving third parties and coordinate with relevant stakeholders.


Job description


This role is located in New York City and will require a hybrid work schedule of at least 2 days in office per week.


This role is for Officer level candidates. 


About the Bank

Sumitomo Mitsui Trust Bank, Limited was established through the merger of The Sumitomo Trust and Banking Co., Ltd with Chuo Mitsui Trust and Banking, Ltd. on April 1, 2012. We are one of the largest asset managers in Asia and number one among Japanese financial institutions by AUM, with approximately $850 Billion USD in AUM. The Bank provides an assortment of financial solutions and manages a broad spectrum of financial products across its global branches.
Department Overview:

The Americas Division (“AD”) was established in the Sumitomo Mitsui Trust Bank, Limited, New York Branch) (“SMTBNY”) to perform corporate functions and supervise U.S. entities. Established under the AD are the “Global Banking Unit (“GBU”), Americas Division” and “Global Markets Unit (“GMU”), Americas Division” which performs business functions. Information Risk Governance (“IRG”) provides oversight to information and cyber security risk by maintaining and improving branch wide framework that is in-line with the Head Office and regulatory requirements and addresses Confidentiality, Integrity, and Availability for information assets. IRG establishes appropriate policies, procedures, measurement, and monitoring processes to proactively assess and evaluate and cyber security and information security risks inherent in the Branch Operations. IRG is directly involved in all information and cyber security related projects, matters and issues.


Your Role Overview:

The Third Party Information Security Analyst supports the Bank’s Third Party Risk Management function by focusing on assessing and monitoring information security risks associated with 3rd, 4th, Nth parties. This role assists with vendor due diligence, security reviews, information security risk assessments, and ongoing monitoring activities to ensure these third party relationships align with the organization’s security requirements.


Your Duties and Responsibilities:

  1. Conduct initial and continuous information security risk assessments of third (Nth) parties.
  2. Review third party provided security documentation including SOC reports, ISO 27001 certifications, security questionnaires, and Business Continuity and Disaster Recovery documentation. 
  3. Document assessment findings and risk ratings in the Bank’s TPRM platform and maintain an up-to-date tracking sheet that provides management with clear visibility into the status, due date, and completion of each assessment and related follow-up actions.
  4. For vendor due-diligence, with a focus on information security risks, coordinate with relevant Teams (Administration, Legal, etc.) for vendor onboarding and offboarding activities
  5. Perform on-going monitoring of information security-related incidents involving third-parties and coordinate with relevant stakeholders to facilitate requests for necessary information from the relevant third-parties and support the assessment of potential impact to the Bank.
  6. Participate in internal audits and external examinations related to the information security risk domains of third party risk management
  7. Assist in maintaining information security-related TPRM policies and procedures. 
  8. Performs other duties and responsibilities as assigned by management.


Your Qualifications:
  1. 3+ Years of experience with risk assessment methodologies and techniques as well as Third Party Risk Management Lifecycle. 
  2. Prior experience with financial industry structure and concepts a plus. 
  3. Prior experience working on a Third Party Risk Management (TPRM) platform, such as Prevalent.
  4. Prior experience working with and assessing information security-related documentation such as SOC 2 reports, ISO 27001 certification, etc.
  5. Strong knowledge of information security and risk management frameworks, including NIST Cybersecurity Framework, ISO/IEC 27001, and the Cyber Risk Institute Profile.
  6. Strong Microsoft Office skills
  7. Strong verbal and written communication skills.
  8. Strong analytical skills
  9. Self-motivated with good time management skills.



Why you should join SuMi Trust:SuMi Trust embraces flexible ways of working when the business and role permits. We provide employees with a hybrid working model, allowing for in-office work and work from home. Our diverse and inclusive environment along with our global presence enables us to collaborate and communicate to meet our business needs. We believe that efficient teams need truth, loyalty, and a strong sense of purpose to balance risk and their targets. We make sustainable business decisions to improve our society and the world. We believe that each person brings a unique value that drives the business though their creativity and passion.
  • The Employee Benefits package includes: Paid Time Off, medical, HSA, vision, dental, FSA, 401(k), profit sharing, legal plan, cancer indemnity plan, disability insurance, life insurance, employee assistance program, commuter benefits, business travel accident, paid volunteer day, paid memberships, paid seminars, and tuition assistance.
  • We offer many socialization opportunities for wellness, financial wellbeing, runs/walks, team building, happy hours, and activities to support the Sustainable Developmental Goals.

Check out our LinkedIn for our employee experience: https://www.linkedin.com/company/smtbny



We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, national origin, disability status, protected veteran status or any other characteristic protected by law. SuMi Trust provides reasonable accommodations for employees and applicants with disabilities consistent with applicable law. If you need a reasonable accommodation during the application