1

Third Party Risk Manager Jobs in Oregon (NOW HIRING)

GRC Analyst - Remote

$80K - $137K/yr

... managing control and risk workflows, as well as performing third-party risk assessments. This position is pivotal in ensuring compliance with industry standards and regulations, identifying and ...

OR · On-site

Establishes and formalizes AI Governance, Privacy & Third-Party Risk requirements by defining ... management, CI/CD guardrails, and hardened training and inference environments across AWS and Azure.

Compliance (particularly in B2B relationships), Financial Crimes, and Third-Party Risk Management. * Demonstrated experience in a role that required balancing regulatory rigor with business ...

Understanding of software supply chain security practices, including SBOM development and third-party risk management. * Experience working across cross-functional and global teams to drive ...

Lead Security & Compliance Analyst

OR · On-site +1

$80K - $135K/yr

... management, security findings remediation, cloud security reviews, and third-party risk. Responsibilities Compliance & Audi t * Own SOC 1, SOC 2, HITRUST CSF, and HITRUST AI audits end-to-end ...

OR · On-site

$100K - $133K/yr

Understanding of fronting carrier operations, delegated authority arrangements, MGA oversight, reinsurance structures, and third-party service provider risk management. Knowledge of statutory ...

Risk & Trading Associate

OR · Remote

$15.50 - $19.25/hr

This role is not for narrow risk management, this role is for taking risk management on the full ... Understand the interaction between Vegas & 3rd-party provider consoles and identify where to take ...

Showing results 21-40

Third Party Risk Manager information

See Oregon salary details

$54.5K

$117.9K

$179.7K

How much do third party risk manager jobs pay per year?

As of Aug 12, 2026, the average yearly pay for third party risk manager in Oregon is $117,947.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,200.00 and $136,400.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
What cities in Oregon are hiring for Third Party Risk Manager jobs? Cities in Oregon with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Oregon as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, 2% Contract, and 1% Nights. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $117,947 per year, or $56.7 per hour.

Compliance and Risk Specialist

METROPOLITAN PEDIATRICS LLC

Portland, OR • On-site

$68K - $85K/yr

Full-time

Medical

Posted 19 hours ago

Posted today


Job description

Want to giggle while you work? We love to work with kids and their families, providing important care, which is both fun and purposeful.
As an Equal Opportunity Employer our team of experienced, talented professionals honors the company values of compassion, stewardship, excellence, integrity, flexibility, service, and inclusivity in everything we do - it is an integral part of who we are and what we seek in future employees.
Metro Pediatrics is your best choice for a career in pediatric medicine. If you enjoy a fast-paced, upbeat, and supportive work environment taking care of kids, we invite you to apply and become part of our outstanding team! Start your pediatric medical career today.
We encourage applicants to read more about our company and what we do at https://www.metropediatrics.com/medical-careers/
This position is eligible for our $1000 sign on bonus.
The Compliance and Risk Specialist is responsible for monitoring organizational compliance with applicable governmental regulations related to the Administrative Simplification elements of the Health Insurance Portability and Accountability Act of 1996 (a.k.a. HIPAA). They will research available resources and coordinate implementation of this highly specialized and technical information with various clinical, administrative and support departments. A significant responsibility will include the coordination of the organization's implementation of all HIPAA standards and practices. In addition, the Compliance and Risk Specialist will support clinical and security risk management within the organization.
Regulatory Monitoring and Policy Development
  • Monitor changes in HIPAA and related federal/state regulations.
  • Develop, update, and maintain HIPAA privacy and security policies, including our organizational Compliance Plan, ensuring alignment with current laws, regulations, and statutes.
  • Conduct assessments to identify vulnerabilities in handling protected health information (PHI).
  • Maintain knowledge and relationship with key third-party risk support organizations to understand and complete any documentation of clinical incidents or potential at-risk situations.
  • Collaborate with our IT teams and leaders to ensure completion of any identified security risk findings.
  • Collaborate with clinical and administrative teams to develop and optimize compliance, privacy, and security processes while promoting an understanding of the intricacies of regulatory requirements.
  • Stay up to date with HIPAA regulations and laws to ensure our organization minimizes risk through proper processes and workflows.
  • Build and maintain relationships with key third-party compliance team members, security personnel, and any legal counsel we might need.

Training and Workforce Readiness
  • Oversee HIPAA training for staff, including onboarding, periodic refreshers, and targeted training for high-risk departments.
  • Ensure employees understand their obligations under HIPAA and know how to respond to privacy/security incidents.
  • Provide education to staff and providers on best privacy and compliance practices, such as phishing awareness, workstation security, MyHealth proxy policy, and other privacy or security issues.
  • Maintain records of compliance and risk related committees including any activities, training, or policy updates.
  • Prepare reports for internal audits, external regulators, or risk committees.

Program Implementation
  • Coordinate with clinical, administrative, IT, legal, and finance departments to implement HIPAA-compliant processes.
  • Work with information systems to ensure technical safeguards (e.g., encryption, access controls) meet HIPAA Security Rule requirements.

Patient Rights and External Inquiries
  • Develop and manage processes for patient access, amendment requests, accounting of disclosures, and restrictions on PHI use.
  • Serve as a resource for affiliates or other entities when compliance or risk questions arise.

Incident Response and Breach Management
  • Investigate all potential privacy or security breach events, coordinate and document findings and present this information to Compliance team members for outcomes and decisions.
  • Organize and summarize incident reports and report out summaries to applicable teams such as the Compliance team and the Peer Review committee.
  • Coordinate breach notifications and remediation efforts in compliance with HIPAA requirements.
  • Analyze, monitor, report and follow up on identified trends in incidents.

Additional Responsibilities
  • Always maintain confidentiality of sensitive patient and organizational information.
  • Display high standards of office conduct.
  • Actively participate in team development and collaborative processes.
  • Punctual, regular, timely, and dependable attendance.
  • Flexible with capacity to work in a fast-paced and changing environment.

  • Bachelor's degree or equivalent work experience in a relevant field or industry preferred.
  • Certification from the International Compliance Association, AAPC, or another recognized compliance group required or ability to obtain certification within the first 90 days of hire. CHC, CHPC, or CPCO preferred.
  • 1+ years of relevant work experience preferred.
  • Strong communication, presentation, and organizational skills