1

Third Party Risk Manager Jobs in Rhode Island (NOW HIRING)

Cybersecurity Manager

Smithfield, RI ยท On-site

$100K - $120K/yr

... risk reviews across infrastructure, software environments, data pathways, and third-party services ... Manage day-to-day AI governance activities by reviewing internal and external AI usage, partnering ...

Category Team Manager-Core Banking

Johnston, RI

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Knowledge of third-party risk management frameworks and regulatory environments. * Experience managing large, complex spend portfolios. * MBA or professional certification (CPSM, CIPS, or similar)

Category Team Manager-Core Banking

Johnston, RI

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Knowledge of third-party risk management frameworks and regulatory environments. * Experience managing large, complex spend portfolios. * MBA or professional certification (CPSM, CIPS, or similar)

Category Team Manager-Core Banking

Johnston, RI ยท On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Knowledge of third-party risk management frameworks and regulatory environments. * Experience managing large, complex spend portfolios. * MBA or professional certification (CPSM, CIPS, or similar)

Showing results 41-60

Third Party Risk Manager information

See Rhode Island salary details

$50.4K

$109.2K

$166.5K

How much do third party risk manager jobs pay per year?

As of Aug 14, 2026, the average yearly pay for third party risk manager in Rhode Island is $109,248.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,100.00 and $126,300.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.

What cities in Rhode Island are hiring for Third Party Risk Manager jobs?

Cities in Rhode Island with the most Third Party Risk Manager job openings:

Infographic showing various Third Party Risk Manager job openings in Rhode Island as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 16% Part Time, and 1% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $109,248 per year, or $52.5 per hour.

Senior Technology Risk Analyst - Monitoring and Testing

Citizens

Johnston, RI โ€ข On-site

Full-time

Re-posted 3 days ago


Job description

Description

The Enterprise Technology & Security (ETS) Risk Senior Analyst leads the identification, assessment, and mitigation of technology-related risks, ensuring the organization's risk management practices are robust and effective. Serving as a key contributor within a first-line risk team, this role works directly with Risk Managers to execute control monitoring and testing that aligns with the bank's risk appetite framework, regulatory expectations, and industry standards. You will oversee end-to-end testing execution, apply advanced risk judgment, and mentor analysts to strengthen testing consistency and documentation quality. This role requires the ability to influence stakeholders through data-driven insights, proactively identify emerging risks, and drive continuous improvements in monitoring, analytics, and automation. This role requires strong professional judgment, high quality documentation, and timely communication to support a resilient control environment and informed risk decisions. The Senior Analyst applies deep knowledge of frameworks such as Cybersecurity Risk Institute (CRI) Profile, NIST 800-53, and NIST Cybersecurity Framework to assess risk and drive meaningful improvements in the bank's security and technology risk posture.

Responsibilities

  • Lead planning and execution of control monitoring and testing across multiple complex technology and cybersecurity processes, ensuring adherence to methodology, timelines, and quality standards.

  • Independently perform and/or oversee control design and operating effectiveness testing; review workpapers and evidence for completeness, accuracy, and audit readiness.

  • Assess material controls and evaluate whether enhanced controls and remediation actions are effective to support issue validation and closure.

  • Ensure testing results are documented clearly and accurately in the system of record and supporting tools, producing audit-ready documentation suitable for QA, Internal Audit, and Regulatory review.

  • Proactively escalate significant control deficiencies, emerging risks, and delivery risks; drive follow-up with stakeholders to achieve timely resolution.

  • Lead issue validation testing to confirm remediation effectiveness and provide evidence-based recommendations to support issue closure.

  • Support and/or lead Risk and Control Self-Assessments (RCSAs), including creation and validation of process maps that reflect key processes, risks, and controls.

  • Lead identification and prioritization of opportunities to enhance testing through automation, data analytics, and improved key control metrics (KRIs/KCMs); partner with stakeholders to support implementation.

  • Strengthen continuous monitoring by refining metrics, improving coverage, and leveraging trend and anomaly analysis to increase risk signal and reduce noise.

  • Build and expand trusted relationships across business and technology stakeholders; influence outcomes through compelling, fact-based analysis and clear recommendations.

  • Mentor junior analysts on risk methodology, documentation standards, and analytical techniques.

  • Stay current on regulatory changes, emerging technology risks, and evolving industry frameworks.

  • Proactively pursue ongoing professional development, including relevant certifications, industry training, etc. to maintain current knowledge in a rapidly evolving field.ย 

Experience & Skills

Required:

  • 5-7 years of progressive experience in IT risk management, information security, or internal audit.

  • Working knowledge of control frameworks including CRI Profile, NIST 800-53, NIST CSF, COBIT, and/or ITIL.

  • Experience conducting or supporting RCSAs, control testing, and risk assessments in a regulated environment.

  • Strong analytical and problem-solving skills with the ability to interpret complex data and translate findings into actionable recommendations.

  • Demonstrated ability to manage multiple concurrent priorities with minimal oversight.

  • Strong interpersonal and written communication skills; able to convey technical risk concepts to non-technical stakeholders.

  • Proficiency with GRC platforms (e.g., Archer), ITSM tools (e.g., ServiceNow, Jira), and security tools (e.g., Splunk, Qualys, DataDog, Wiz, and/or CyberArk).

  • Experience with cloud platforms such as AWS, Azure

  • Familiarity with reporting tools (Tableau, PowerBi)

Preferred:

  • Experience in a regulated financial institution or banking environment.

  • Familiarity with cloud infrastructure risk, cyber recovery, or third-party risk management.

  • Prior experience responding to regulatory exams or supporting audit remediation.

Education

  • Bachelor's degree in Information Technology, Cybersecurity, Business, or a related field required; Master's degree preferred.

  • One or more of the following certifications are preferred:
  • CISA (Certified Information Systems Auditor)
  • CRISC (Certified in Risk and Information Systems Control)
  • CISM (Certified Information Security Manager)
  • AWS Cloud Practitioner or Microsoft Azure Fundamentals

Hours & Work Schedule

  • Hours per Week: 40ย 
  • Work Schedule: Monday-Friday
  • Hybrid: 4 days per week onsite, 1 day remote

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Education:Why Work for UsEmployment Type: 1ST