1

Third Party Risk Manager Jobs in Bothell, WA (NOW HIRING)

Director, Cyber Security

Kirkland, WA · Remote

$165K - $200K/yr

Risk Management, Compliance & Third-Party Security · Oversee enterprise-wide cyber risk management strategy, including risk identification, prioritization, and mitigation aligned to business ...

Sr Director, Internal Audit

Seattle, WA · On-site

$200K - $320K/yr

Strengthen technology, cybersecurity, identity, and third-party risk assurance in close ... Have experience developing and leading senior audit managers and directors, building teams known ...

EE Technical Designer

Everett, WA · On-site

$50 - $80/hr

This role involves leading design efforts, managing configuration control, and collaborating with ... Familiarity with third-party risk platforms such as KY3P. * Experience in financial or technology ...

Lead AI risk assessments across the full model lifecycle - evaluating third-party AI vendors ... while managing risk intelligently * Represent the firm's AI governance posture externally ...

next page

Showing results 1-20

Third Party Risk Manager information

See Bothell, WA salary details

$57.6K

$124.7K

$190K

How much do third party risk manager jobs pay per year?

As of Jun 27, 2026, the average yearly pay for third party risk manager in Bothell, WA is $124,707.00, according to ZipRecruiter salary data. Most workers in this role earn between $100,600.00 and $144,200.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a Third Party Risk Manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
What job categories do people searching Third Party Risk Manager jobs in Bothell, WA look for? The top searched job categories for Third Party Risk Manager jobs in Bothell, WA are:
What cities near Bothell, WA are hiring for Third Party Risk Manager jobs? Cities near Bothell, WA with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Bothell, WA as of June 2026, with employment types broken down into 2% As Needed, 79% Full Time, 17% Part Time, and 2% Contract. Highlights an 88% Physical, 6% Hybrid, and 6% Remote job distribution, with an average salary of $124,707 per year, or $60 per hour.
Executive Director, InfoSec Governance, Risk, and Compliance

Executive Director, InfoSec Governance, Risk, and Compliance

The Walt Disney Company

Seattle, WA • On-site

Full-time

Posted 28 days ago


Walt Disney Company rating

7.7

Company rating: 7.7 out of 10

Based on 126 frontline employees who took The Breakroom Quiz

4th of 48 rated entertainment


Job description

Job Posting Title:

Executive Director, InfoSec Governance, Risk, and Compliance

Req ID:

10152675

Job Description:

At Disney,we'restorytellers. We make theimpossible,possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world-a passion thatremainsour touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news,moviesand a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - andwe'reconstantly looking for new ways to enhance these exciting experiences.

The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.

Team Description:

The Global Information Security (GIS)group provides services to protect the value and use of Disney's information through collaboration, standardization, enforcement, and education across The Walt Disney Company. Themain focusareas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information;Establish appropriate policiesand procedures to be followed; Educate user community to minimize risk.

Disney's InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney's global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation-not a barrier.

What You'll Do

Transform GRC at Disney

  • Drive the evolution of Disney's InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions

  • Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance

  • Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights

  • Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise

Risk Management Leadership

  • Lead the design, implementation, and continuous improvement of Disney's enterprise InfoSec Risk Management Framework

  • Establish and operationalize risk tolerance models, translating businessobjectivesinto clear prioritization, investment, and remediation decisions

  • Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data

  • Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives

  • Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)

Governance Program Leadership

  • Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs

  • Embed governance controls into the technology lifecycle (e.g.,DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation

  • Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction

  • Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems

  • Lead enterprise maturity assessments (e.g., NIST CSF) toidentifygaps and inform strategic investment decisions

Compliance Program Leadership

  • Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability

  • Build and operationalize a "compliance-as-a-service" model that enables self-service, automates evidence collection, and minimizes burden on engineering teams

  • Monitor andanticipatechanges in the regulatory landscape, proactively positioning Disney to meet evolving requirements

Organizational Leadership

  • Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement

  • Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions

WhatYou'llBring

Must-Have Qualifications

  • You will have12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions

  • You will bringstructured problem-solving, audit rigor, and enterprise advisory experience

  • You will haveindustry experience within large, complex organizations, with the ability tooperateeffectively in highly matrixed environments

  • You will havea proventrack recordof transforming GRC programs into risk-driven operating models that influence enterprise decision-making

  • You will havedeepexpertiseacross risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance)

  • You will havestrong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR

  • You will havedemonstratedexecutive presence and exceptional influence skills, with the ability tooperateas a trusted advisor to senior leadership and translate complex technical risk into clear business insights

  • You will haveexperience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions

  • You will havea strong customer-focused mindset, ensuring GRC solutions enable the business and enhance-not hinder-user and product experiences

  • You will haveexperience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders

Leadership & Transformation Profile (Critical for Success)

  • You will havea mindset of a thought partner-not just an operator-bringing a strategic, forward-looking perspective to GRC

  • You will havea track recordof askinghard questions, challenging legacy ways of working, and driving meaningful change across organizations

  • You will havethe ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy

  • You will havedemonstratedsuccess leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations

Technical Expertise

  • You will haveadvancedexpertisein audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments(must have qualification)

  • You will havehands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)

  • You will havea strong understanding of cloud security and compliance across AWS, Azure, and GCP environments

  • You will havefamiliarity withDevSecOpspractices and integrating security and governance into software development and infrastructure pipelines

Nice-to-Have Qualifications

  • You may haveexperience within media, entertainment, or similarly complex, consumer-facing industries

  • You may haveexperience from a Big 4 consulting firm.

  • You may haveexperience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities

Education

  • You will havea bachelor's degree in computer science, information security, or a related field-or equivalent practical experience

  • You may haveadvanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)

The hiring range for this position in Orlando, FL is $197,500 to $265,000 per year and in Glendale,CA is $207,400 to $278,200 per year. The hiring range for this position in Seattle, WA is $217,300 to $291,500 per year and in New York, NY is $217,300 to $291,500 per year. The base pay actually offered will take into account internal equity and also may vary depending on the candidate's geographic region, job-related knowledge, skills, and experience among other factors. A bonus and/or long-term incentive units may be provided as part of the compensation package, in addition to the full range of medical, financial, and/or other benefits, dependent on the level and position offered.

Job Posting Segment:

Enterprise Technology and Data

Job Posting Primary Business:

Global Information Security

Primary Job Posting Category:

Security Operations

Employment Type:

Full time

Primary City, State, Region, Postal Code:

Seattle, WA, USA

Alternate City, State, Region, Postal Code:

USA - CA - 1200 Grand Central Ave

Date Posted:

2026-05-29

What Walt Disney Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Walt Disney logo

About Walt Disney

Sourced by ZipRecruiter

At Disney, we're storytellers. We make the impossible, possible. We do this through utilizing and developing cutting-edge technology and pushing the envelope to bring stories to life through our movies, products, interactive games, parks and resorts, and media networks. Now is your chance to join our talented team that delivers unparalleled creative content to audiences around the world. "We create happiness." That's our motto at Walt Disney Parks and Resorts. And it permeates everything we do. At Disney, you'll help inspire that magic by enabling our teams to push the limits of entertainment and create the never-before-seen!

Industry

Amusement, gambling, and recreation

Company size

10,000+ Employees

Headquarters location

Burbank, CA, US

Social media