The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
Third-Party Risk Management (TPRM) * Enterprise Risk Management * Operational Risk Management * Technology Risk Assessment * Information Security Risk * Privacy Risk Assessment * Cybersecurity Risk ...
Third-Party Risk Management (TPRM) * Enterprise Risk Management * Operational Risk Management * Technology Risk Assessment * Information Security Risk * Privacy Risk Assessment * Cybersecurity Risk ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
Centralized Service Manager I
Richmond, VA · On-site
$80K - $100K/yr
... and management of assigned third parties who provide Truist with outsourced services and ... Facilitate the completion of third party risk assessments, contract review/structuring, due ...
New
Centralized Service Manager I
Richmond, VA · On-site
$80K - $100K/yr
... and management of assigned third parties who provide Truist with outsourced services and ... Facilitate the completion of third party risk assessments, contract review/structuring, due ...
New
Principal Program Manager
Reston, VA · On-site
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
Principal Program Manager
Reston, VA · On-site
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
Director, Cybersecurity and IT Risk Management
Vienna, VA · On-site
$170K - $180K/yr
Build and lead cybersecurity components of third-party risk management, including vendor risk tiering, due diligence, contract security requirements, cloud/SaaS assessments, ongoing monitoring, and ...
New
Quick apply
Director, Cybersecurity and IT Risk Management
Vienna, VA · On-site
$170K - $180K/yr
Build and lead cybersecurity components of third-party risk management, including vendor risk tiering, due diligence, contract security requirements, cloud/SaaS assessments, ongoing monitoring, and ...
New
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Operational Risk Manager
Mclean, VA · On-site
Key responsibilities include managing global risk activities, monitoring program performance, managing third-party service providers, analyzing risk data and trends, coordinating audits and reviews ...
Operational Risk Manager
Mclean, VA · On-site
Key responsibilities include managing global risk activities, monitoring program performance, managing third-party service providers, analyzing risk data and trends, coordinating audits and reviews ...
Operational Risk Manager
Mclean, VA · On-site
Key responsibilities include managing global risk activities, monitoring program performance, managing third-party service providers, analyzing risk data and trends, coordinating audits and reviews ...
Operational Risk Manager
Mclean, VA · On-site
Key responsibilities include managing global risk activities, monitoring program performance, managing third-party service providers, analyzing risk data and trends, coordinating audits and reviews ...
Implementation Manager
Mclean, VA · On-site
You understand the processes, pain points, and personas in third party management, supply chain management, procurement, risk, and compliance * You lead inspirational, tailored presentations in a ...
Implementation Manager
Mclean, VA · On-site
You understand the processes, pain points, and personas in third party management, supply chain management, procurement, risk, and compliance * You lead inspirational, tailored presentations in a ...
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Quick apply
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Quick apply
Manage third-party and vendor security assessments, including contract and security control reviews * Analyze emerging threats and incorporate threat intelligence into risk evaluations to identify ...
Enterprise Cybersecurity AI Risk Analyst
Mclean, VA · On-site +1
... third-party services, and business risk. In all of this cyber and AI noise, how can teams ... Ability to independently manage assigned workstreams, prioritize competing demands, follow through ...
Enterprise Cybersecurity AI Risk Analyst
Mclean, VA · On-site +1
... third-party services, and business risk. In all of this cyber and AI noise, how can teams ... Ability to independently manage assigned workstreams, prioritize competing demands, follow through ...
Third Party Risk Manager information
See Virginia salary details
$51.1K - $61.7K
4% of jobs
$61.7K - $72.4K
6% of jobs
$72.4K - $83.1K
11% of jobs
$87.1K is the 25th percentile. Wages below this are outliers.
$83.1K - $93.8K
11% of jobs
The median wage is $102.3K / yr.
$93.8K - $104.5K
23% of jobs
$104.5K - $115.1K
13% of jobs
$122.2K is the 75th percentile. Wages above this are outliers.
$115.1K - $125.8K
12% of jobs
$125.8K - $136.5K
8% of jobs
$136.5K - $147.2K
6% of jobs
$147.2K - $157.9K
4% of jobs
$157.9K - $168.5K
2% of jobs
$51.1K
$110.6K
$168.5K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a third party risk manager?
What is a third party risk manager?
How does a third party risk manager typically collaborate with other departments to manage vendor risks?

Consultant II, Technology 3rd Party Risk Management - Tax Transformation
Arlington, VA • On-site
Full-time
Re-posted 19 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll do
The Consultant II - Technology Third Party Risk Management role in the Tax Transformation Office requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Executing TPRM review activities - coordinating intake, gathering and organizing due diligence documentation (such as security questionnaires and SOC reports), and tracking reviews through completion for new and renewing vendors under the guidance of senior team members.
- Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team leads.
- Serving as a day-to-day contact for routine TPRM process questions - responding to standard inquiries from business sponsors and vendor managers, and escalating more complex or judgment-based questions to senior team members.
- Coordinating with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - gathering required inputs, following up on outstanding items, and helping ensure consistent application of established policies and procedures.
- Supporting process improvement efforts - surfacing friction points observed during reviews and contributing to improvements in tooling, documentation standards, and workflows.
- Contributing to broader TTO Strategic Technology Services initiatives - assisting with vendor portfolio tracking, alliance program operations, and other activities that support the team's objectives.
- Strong communicator who can tailor messages for technical and non-technical audiences and keep stakeholders informed and aligned.
- Collaborative relationship builder who works effectively across functions and levels to drive consensus and move work forward.
- Adaptable, self-directed problem solver who can manage shifting priorities, multiple workstreams, and competing deadlines.
- Confident facilitator who influences without authority, resolves routine issues, and escalates effectively when needed.
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 1+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP® - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
Deloitte is committed to providing reasonable accommodations for people with disabilities. If you require a reasonable accommodation to participate in the recruiting process, please direct your inquiries to the Global Call Center (GCC) at USTalentCICInbox@deloitte.com.
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Benefits
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ways of thinking, ideas, and perspectives, and bring more creativity and innovation to help solve our clients' most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose
Deloitte's purpose is to make an impact that matters for our people, clients, and communities. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. Our purpose comes through in our work with clients that enables impact and value in their organizations, as well as through our own investments, commitments, and actions across areas that help drive positive outcomes for our communities. Learn more.
Professional development
From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
As used in this posting, "Deloitte" means Deloitte Tax LLP, a subsidiary of Deloitte LLP. Please see https://www.deloitte.com/us/about for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. Certain services may not be available to attest clients under the rules and regulations of public accounting.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Qualified applicants with criminal histories, including arrest or conviction records, will be considered for employment in accordance with the requirements of applicable state and local laws, including the Los Angeles County Fair Chance Ordinance for Employers, City of Los Angeles's Fair Chance Initiative for Hiring Ordinance, San Francisco Fair Chance Ordinance, and the California Fair Chance Act. See notices of various fair chance hiring and ban-the-box laws where available. Fair Chance Hiring and Ban-the-Box Notices | Deloitte US Careers
Requisition code: 360370
Job ID 360370