... Management Framework * Establish and operationalize risk tolerance models, translating ... third-party risk data * Drive risk-based prioritization across InfoSec functions to ensure ...
... Management Framework * Establish and operationalize risk tolerance models, translating ... third-party risk data * Drive risk-based prioritization across InfoSec functions to ensure ...
Director, Cyber Security
Kirkland, WA · Remote
$165K - $200K/yr
Risk Management, Compliance & Third-Party Security · Oversee enterprise-wide cyber risk management strategy, including risk identification, prioritization, and mitigation aligned to business ...
Quick apply
Director, Cyber Security
Kirkland, WA · Remote
$165K - $200K/yr
Risk Management, Compliance & Third-Party Security · Oversee enterprise-wide cyber risk management strategy, including risk identification, prioritization, and mitigation aligned to business ...
TA Specialist - TAPM - Seattle (Third-party Associate)
Seattle, WA · On-site
$32 - $40/hr
This team centrally manages the operations of new recruiting processes for our high growth teams ... Please be advised that this job posting is on behalf of a third-party agency. This is a 12-month ...
TA Specialist - TAPM - Seattle (Third-party Associate)
Seattle, WA · On-site
$32 - $40/hr
This team centrally manages the operations of new recruiting processes for our high growth teams ... Please be advised that this job posting is on behalf of a third-party agency. This is a 12-month ...
Sr Director, Internal Audit
Seattle, WA · On-site
$200K - $320K/yr
Strengthen technology, cybersecurity, identity, and third-party risk assurance in close ... Have experience developing and leading senior audit managers and directors, building teams known ...
Sr Director, Internal Audit
Seattle, WA · On-site
$200K - $320K/yr
Strengthen technology, cybersecurity, identity, and third-party risk assurance in close ... Have experience developing and leading senior audit managers and directors, building teams known ...
Technical Sourcer - E-Commerce - Seattle (Third-Party Associate)
Seattle, WA · On-site
$30 - $50/hr
You will partner closely with recruiters and hiring managers to identify, engage, and attract top ... Please be advised that this job posting is on behalf of a third-party agency. This is a 6-month ...
Technical Sourcer - E-Commerce - Seattle (Third-Party Associate)
Seattle, WA · On-site
$30 - $50/hr
You will partner closely with recruiters and hiring managers to identify, engage, and attract top ... Please be advised that this job posting is on behalf of a third-party agency. This is a 6-month ...
... who evaluate risk, and partner teams who rely on our data to make informed decisions. You'll ... You'll work with Product Managers, Security Engineers, Software Development Engineers, and Applied ...
... who evaluate risk, and partner teams who rely on our data to make informed decisions. You'll ... You'll work with Product Managers, Security Engineers, Software Development Engineers, and Applied ...
... who evaluate risk, and partner teams who rely on our data to make informed decisions. You'll ... You'll work with Product Managers, Security Engineers, Software Development Engineers, and Applied ...
... who evaluate risk, and partner teams who rely on our data to make informed decisions. You'll ... You'll work with Product Managers, Security Engineers, Software Development Engineers, and Applied ...
... who evaluate risk, and partner teams who rely on our data to make informed decisions. You'll ... You'll work with Product Managers, Security Engineers, Software Development Engineers, and Applied ...
... who evaluate risk, and partner teams who rely on our data to make informed decisions. You'll ... You'll work with Product Managers, Security Engineers, Software Development Engineers, and Applied ...
Talent Sourcer - HR & Management - Seattle (Third-party Associate)
Seattle, WA · On-site
$30 - $50/hr
This is a 6-month temporary assignment managed by a third-party agency, who will be your employer. While you may be assigned to work at TikTok, you will not be a TikTok employee. All contractual ...
Talent Sourcer - HR & Management - Seattle (Third-party Associate)
Seattle, WA · On-site
$30 - $50/hr
This is a 6-month temporary assignment managed by a third-party agency, who will be your employer. While you may be assigned to work at TikTok, you will not be a TikTok employee. All contractual ...
... risk activities - not just course completion, but demonstrated proficiency Manage the upstream training interface with third-party labor providers, defining pre-arrival requirements and on-site ...
... risk activities - not just course completion, but demonstrated proficiency Manage the upstream training interface with third-party labor providers, defining pre-arrival requirements and on-site ...
OMHS Integration Safety Lead, FEC - Facilities, Engineering and Construction
Bellevue, WA · On-site
$84K - $112K/yr
... risk activities - not just course completion, but demonstrated proficiency • Manage the upstream training interface with third-party labor providers, defining pre-arrival requirements and on-site ...
OMHS Integration Safety Lead, FEC - Facilities, Engineering and Construction
Bellevue, WA · On-site
$84K - $112K/yr
... risk activities - not just course completion, but demonstrated proficiency • Manage the upstream training interface with third-party labor providers, defining pre-arrival requirements and on-site ...
... risk activities - not just course completion, but demonstrated proficiency Manage the upstream training interface with third-party labor providers, defining pre-arrival requirements and on-site ...
... risk activities - not just course completion, but demonstrated proficiency Manage the upstream training interface with third-party labor providers, defining pre-arrival requirements and on-site ...
... and third-party risk management, supplier/partner/vendor interaction portals and integration with core applications, supplier management platforms (Ariba, Aravo, Coupa, Ivalua, HICX, and APEX ...
Quick apply
... and third-party risk management, supplier/partner/vendor interaction portals and integration with core applications, supplier management platforms (Ariba, Aravo, Coupa, Ivalua, HICX, and APEX ...
EE Technical Designer
Everett, WA · On-site
$50 - $80/hr
This role involves leading design efforts, managing configuration control, and collaborating with ... Familiarity with third-party risk platforms such as KY3P. * Experience in financial or technology ...
EE Technical Designer
Everett, WA · On-site
$50 - $80/hr
This role involves leading design efforts, managing configuration control, and collaborating with ... Familiarity with third-party risk platforms such as KY3P. * Experience in financial or technology ...
Mobility Operations Specialist - HR Operations - Seattle (Third Party Associate)
Seattle, WA · On-site
$30 - $50/hr
HR Tech & Automation - Manage, maintain, and audit mobility trackers, dashboards, and operational ... You will be an employee of a third-party agency. As of the date of this posting, a good faith ...
Mobility Operations Specialist - HR Operations - Seattle (Third Party Associate)
Seattle, WA · On-site
$30 - $50/hr
HR Tech & Automation - Manage, maintain, and audit mobility trackers, dashboards, and operational ... You will be an employee of a third-party agency. As of the date of this posting, a good faith ...
Risk and Safety Specialist
Seattle, WA · On-site
$34 - $38/hr
Collect, manage and verify certificates of insurance from third-party vendors, partners and clients, as required by company contracts and risk management policies. * Handle routine and non-complex ...
Risk and Safety Specialist
Seattle, WA · On-site
$34 - $38/hr
Collect, manage and verify certificates of insurance from third-party vendors, partners and clients, as required by company contracts and risk management policies. * Handle routine and non-complex ...
Senior AI Risk Advisor
Seattle, WA · On-site +1
Lead AI risk assessments across the full model lifecycle - evaluating third-party AI vendors ... while managing risk intelligently * Represent the firm's AI governance posture externally ...
Senior AI Risk Advisor
Seattle, WA · On-site +1
Lead AI risk assessments across the full model lifecycle - evaluating third-party AI vendors ... while managing risk intelligently * Represent the firm's AI governance posture externally ...
... risk management. Partners with programmatic work units to provide advice and counsel on ... Evaluate records requests, including former clients and other third-party requests, and provide ...
... risk management. Partners with programmatic work units to provide advice and counsel on ... Evaluate records requests, including former clients and other third-party requests, and provide ...
We are seeking a seasoned Supply Chain Manager to join our Third Party Carrier Logistics Short/Medium term planning and execution team. This role is pivotal in shaping the future of our ...
We are seeking a seasoned Supply Chain Manager to join our Third Party Carrier Logistics Short/Medium term planning and execution team. This role is pivotal in shaping the future of our ...
We are seeking a seasoned Supply Chain Manager to join our Third Party Carrier Logistics Short/Medium term planning and execution team. This role is pivotal in shaping the future of our ...
We are seeking a seasoned Supply Chain Manager to join our Third Party Carrier Logistics Short/Medium term planning and execution team. This role is pivotal in shaping the future of our ...
Third Party Risk Manager information
See Bothell, WA salary details
$57.6K - $69.6K
4% of jobs
$69.6K - $81.7K
6% of jobs
$81.7K - $93.7K
11% of jobs
$98.2K is the 25th percentile. Wages below this are outliers.
$93.7K - $105.7K
11% of jobs
The median wage is $115.3K / yr.
$105.7K - $117.8K
23% of jobs
$117.8K - $129.8K
13% of jobs
$137.8K is the 75th percentile. Wages above this are outliers.
$129.8K - $141.9K
12% of jobs
$141.9K - $153.9K
8% of jobs
$153.9K - $166K
6% of jobs
$166K - $178K
4% of jobs
$178K - $190K
2% of jobs
$57.6K
$124.7K
$190K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
What is a Third Party Risk Manager?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

Executive Director, InfoSec Governance, Risk, and Compliance
Seattle, WA • On-site
Full-time
Posted 28 days ago
Walt Disney Company rating
7.7
Based on 126 frontline employees who took The Breakroom Quiz
4th of 48 rated entertainment
Job description
Job Posting Title:
Executive Director, InfoSec Governance, Risk, and ComplianceReq ID:
10152675Job Description:
At Disney,we'restorytellers. We make theimpossible,possible. The Walt Disney Company (TWDC) is a world-class entertainment and technological leader. Walt's passion was to continuously envision new ways to move audiences around the world-a passion thatremainsour touchstone in an enterprise that stretches from theme parks, resorts and a cruise line to sports, news,moviesand a variety of other businesses. Uniting each endeavor is a commitment to creating and delivering unforgettable experiences - andwe'reconstantly looking for new ways to enhance these exciting experiences.
The Enterprise Technology mission is to deliver technology solutions that align to business strategies while enabling enterprise efficiency and promoting cross-company collaborative innovation. Our group drives competitive advantage by enhancing our consumer experiences, enabling business growth, and advancing operational excellence.
Team Description:
The Global Information Security (GIS)group provides services to protect the value and use of Disney's information through collaboration, standardization, enforcement, and education across The Walt Disney Company. Themain focusareas of this group are: Reduce the risk of both accidental and malicious data disclosure; Identify, monitor, engage with complete inventory of information;Establish appropriate policiesand procedures to be followed; Educate user community to minimize risk.
Disney's InfoSec GRC team is seeking a transformational leader to drive the next evolution of Governance, Risk, and Compliance across the enterprise. Reporting to the VP of Information Security, this role will lead the shift from a traditional compliance-driven approach to a modern, risk-intelligence-led model that enables better business decisions, strengthens security posture, and scales with Disney's global technology and content ecosystem. This leader will partner closely with GIS and business leadership to embed risk awareness into daily operations, ensuring GRC is a strategic enabler of innovation-not a barrier.
What You'll Do
Transform GRC at Disney
Drive the evolution of Disney's InfoSec GRC program from a compliance-centric model to a dynamic, risk-intelligence-led capability that informs enterprise investment and prioritization decisions
Define and elevate GRC standards by introducing innovative approaches to risk quantification, compliance automation, and integrated governance
Partner with GIS and segment technology leadership to position GRC as a strategic business enabler, translating complex risks into actionable, executive-ready insights
Champion a culture where risk awareness is embedded into daily decision-making, enabling intuitive and scalable risk-informed behaviors across the enterprise
Risk Management Leadership
Lead the design, implementation, and continuous improvement of Disney's enterprise InfoSec Risk Management Framework
Establish and operationalize risk tolerance models, translating businessobjectivesinto clear prioritization, investment, and remediation decisions
Build and mature a centralized cybersecurity risk register integrating threat intelligence, vulnerabilities, and third-party risk data
Drive risk-based prioritization across InfoSec functions to ensure measurable risk reduction and alignment to enterprise objectives
Deliver clear, credible, and decision-ready risk reporting to executive leadership and the Board, including financial risk quantification (e.g., FAIR)
Governance Program Leadership
Oversee the full lifecycle of InfoSec policies, standards, and guidelines, ensuring they are risk-based, actionable, and aligned with business needs
Embed governance controls into the technology lifecycle (e.g.,DevSecOps, cloud, infrastructure-as-code), reducing reliance on manual processes through automation
Establish a policy effectiveness framework focused on behavioral change and measurable risk reduction
Define and advance governance strategies for emerging technologies, including AI/ML, quantum security, and autonomous systems
Lead enterprise maturity assessments (e.g., NIST CSF) toidentifygaps and inform strategic investment decisions
Compliance Program Leadership
Provide oversight of global regulatory and contractual compliance programs (e.g., SOX, PCI, GDPR, ISO), ensuring consistency and scalability
Build and operationalize a "compliance-as-a-service" model that enables self-service, automates evidence collection, and minimizes burden on engineering teams
Monitor andanticipatechanges in the regulatory landscape, proactively positioning Disney to meet evolving requirements
Organizational Leadership
Lead, develop, and scale a high-performing global GRC organization, fostering a culture of accountability, innovation, and continuous improvement
Drive organizational excellence through strong leadership, talent development, and a focus on delivering scalable, forward-looking solutions
WhatYou'llBring
Must-Have Qualifications
You will have12+ years of progressive experience in cybersecurity, technology risk, or compliance, including 3+ years leading enterprise-scale GRC functions
You will bringstructured problem-solving, audit rigor, and enterprise advisory experience
You will haveindustry experience within large, complex organizations, with the ability tooperateeffectively in highly matrixed environments
You will havea proventrack recordof transforming GRC programs into risk-driven operating models that influence enterprise decision-making
You will havedeepexpertiseacross risk management, governance, and compliance, including frameworks, policy lifecycle, automation, audit, and controls assurance)
You will havestrong working knowledge of industry frameworks and regulations, including NIST CSF, NIST 800-53, ISO 27001, PCI DSS 4.0, SOX ITGC, and GDPR
You will havedemonstratedexecutive presence and exceptional influence skills, with the ability tooperateas a trusted advisor to senior leadership and translate complex technical risk into clear business insights
You will haveexperience applying financial risk quantification methodologies (e.g., FAIR) to support investment and prioritization decisions
You will havea strong customer-focused mindset, ensuring GRC solutions enable the business and enhance-not hinder-user and product experiences
You will haveexperience leading in highly matrixed, global environments, driving alignment across engineering, security, and business stakeholders
Leadership & Transformation Profile (Critical for Success)
You will havea mindset of a thought partner-not just an operator-bringing a strategic, forward-looking perspective to GRC
You will havea track recordof askinghard questions, challenging legacy ways of working, and driving meaningful change across organizations
You will havethe ability to connect cost, customer experience, and operational efficiency into a cohesive, risk-informed strategy
You will havedemonstratedsuccess leading large-scale transformation initiatives, influencing without authority, and driving adoption across complex organizations
Technical Expertise
You will haveadvancedexpertisein audit methodologies, controls testing, and assurance processes, including ITGCs and automated control environments(must have qualification)
You will havehands-on experience with leading GRC platforms (e.g., Archer, ServiceNow GRC, SailPoint)
You will havea strong understanding of cloud security and compliance across AWS, Azure, and GCP environments
You will havefamiliarity withDevSecOpspractices and integrating security and governance into software development and infrastructure pipelines
Nice-to-Have Qualifications
You may haveexperience within media, entertainment, or similarly complex, consumer-facing industries
You may haveexperience from a Big 4 consulting firm.
You may haveexperience advancing emerging risk domains such as AI/ML governance, third-party risk, or next-generation compliance capabilities
Education
You will havea bachelor's degree in computer science, information security, or a related field-or equivalent practical experience
You may haveadvanced degrees or relevant certifications (e.g., CISSP, CISM, CRISC)
Job Posting Segment:
Enterprise Technology and DataJob Posting Primary Business:
Global Information SecurityPrimary Job Posting Category:
Security OperationsEmployment Type:
Full timePrimary City, State, Region, Postal Code:
Seattle, WA, USAAlternate City, State, Region, Postal Code:
USA - CA - 1200 Grand Central AveDate Posted:
2026-05-29What Walt Disney Company employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Walt Disney
Sourced by ZipRecruiter
At Disney, we're storytellers. We make the impossible, possible. We do this through utilizing and developing cutting-edge technology and pushing the envelope to bring stories to life through our movies, products, interactive games, parks and resorts, and media networks. Now is your chance to join our talented team that delivers unparalleled creative content to audiences around the world. "We create happiness." That's our motto at Walt Disney Parks and Resorts. And it permeates everything we do. At Disney, you'll help inspire that magic by enabling our teams to push the limits of entertainment and create the never-before-seen!
Industry
Amusement, gambling, and recreation
Company size
10,000+ Employees
Headquarters location
Burbank, CA, US