Raritan, New Jersey, United States of America Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk ...
Raritan, New Jersey, United States of America Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk ...
The Role We are looking for an Associate Director, Third-Party Risk Management (TPRM) to own the TPRM pillar at Flex. This is not a program management role. It is a pillar ownership role: you set the ...
The Role We are looking for an Associate Director, Third-Party Risk Management (TPRM) to own the TPRM pillar at Flex. This is not a program management role. It is a pillar ownership role: you set the ...
The Role We are looking for an Associate Director, Third-Party Risk Management (TPRM) to own the TPRM pillar at Flex. This is not a program management role. It is a pillar ownership role: you set the ...
The Role We are looking for an Associate Director, Third-Party Risk Management (TPRM) to own the TPRM pillar at Flex. This is not a program management role. It is a pillar ownership role: you set the ...
Operational Risk Management Department Third Party Risk Management Intern
Manhattan, NY · On-site
$18/hr
Responsibilities Responsibilities include but not limited to supporting the third party risk management of ORD in following aspects: Develop monthly ORC/RMICC reporting metrics meetings; Assist with ...
Operational Risk Management Department Third Party Risk Management Intern
Manhattan, NY · On-site
$18/hr
Responsibilities Responsibilities include but not limited to supporting the third party risk management of ORD in following aspects: Develop monthly ORC/RMICC reporting metrics meetings; Assist with ...
Head of Technology Risk Management
Parsippany, NJ · On-site
$164K - $266K/yr
Third-Party Risk Management: * Direct the execution of third-party risk management activities, including vendor risk assessments, ongoing monitoring, escalations, and remediation. * Proactively ...
Head of Technology Risk Management
Parsippany, NJ · On-site
$164K - $266K/yr
Third-Party Risk Management: * Direct the execution of third-party risk management activities, including vendor risk assessments, ongoing monitoring, escalations, and remediation. * Proactively ...
Head of Technology Risk Management
Parsippany, NJ · On-site
$164K - $266K/yr
Third-Party Risk Management: * Direct the execution of third-party risk management activities, including vendor risk assessments, ongoing monitoring, escalations, and remediation. * Proactively ...
Head of Technology Risk Management
Parsippany, NJ · On-site
$164K - $266K/yr
Third-Party Risk Management: * Direct the execution of third-party risk management activities, including vendor risk assessments, ongoing monitoring, escalations, and remediation. * Proactively ...
Head of Technology Risk Management
$164K - $266K/yr
Third-Party Risk Management: * Direct the execution of third-party risk management activities, including vendor risk assessments, ongoing monitoring, escalations, and remediation. * Proactively ...
Head of Technology Risk Management
$164K - $266K/yr
Third-Party Risk Management: * Direct the execution of third-party risk management activities, including vendor risk assessments, ongoing monitoring, escalations, and remediation. * Proactively ...
Job Overview TheDirector,ThirdParty Risk Management Programprovidesstrategic leadershipandenablement ofaneffectiveenterprise-wide third-party risk management (TPRM) program, with a focus on ...
Job Overview TheDirector,ThirdParty Risk Management Programprovidesstrategic leadershipandenablement ofaneffectiveenterprise-wide third-party risk management (TPRM) program, with a focus on ...
Expertise and support on design, configuration, testing and initial implementation of Third Party Catalog, Third Party Risk Management & Issue Management use cases in Archer Platform * Specifically ...
Expertise and support on design, configuration, testing and initial implementation of Third Party Catalog, Third Party Risk Management & Issue Management use cases in Archer Platform * Specifically ...
Corporate Controllership - Third-Party Risk Management (TPRM) Reports to: Director of Third-Party Risk Governance & Awareness Position Summary: The Senior TPRM Governance & Awareness Consultant is ...
Corporate Controllership - Third-Party Risk Management (TPRM) Reports to: Director of Third-Party Risk Governance & Awareness Position Summary: The Senior TPRM Governance & Awareness Consultant is ...
Corporate Controllership - Third-Party Risk Management (TPRM) Reports to: Director of Third-Party Risk Governance & Awareness Position Summary: The Senior TPRM Governance & Awareness Consultant is ...
Corporate Controllership - Third-Party Risk Management (TPRM) Reports to: Director of Third-Party Risk Governance & Awareness Position Summary: The Senior TPRM Governance & Awareness Consultant is ...
Expertise and support on design, configuration, testing and initial implementation of Third Party Catalog, Third Party Risk Management & Issue Management use cases in Archer Platform * Specifically ...
Expertise and support on design, configuration, testing and initial implementation of Third Party Catalog, Third Party Risk Management & Issue Management use cases in Archer Platform * Specifically ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
Director - Risk Management
Somerset, NJ · On-site
Third-Party & Operational Risk * Design and mature third-party risk segmentation, due diligence, and lifecycle oversight. * Coordinate with InfoSec and Privacy on security and data protection ...
Director - Risk Management
Somerset, NJ · On-site
Third-Party & Operational Risk * Design and mature third-party risk segmentation, due diligence, and lifecycle oversight. * Coordinate with InfoSec and Privacy on security and data protection ...
Enhance Third-Party Risk Management, including due diligence, segmentation, ongoing monitoring, and exit planning using a tiered oversight approach. * Develop enterprise risk data, analytics, and ...
Enhance Third-Party Risk Management, including due diligence, segmentation, ongoing monitoring, and exit planning using a tiered oversight approach. * Develop enterprise risk data, analytics, and ...
... third-party risk management program, including vendor tiering, security assessments, and remediation tracking • Manage the firm's response program for client security questionnaires and due ...
... third-party risk management program, including vendor tiering, security assessments, and remediation tracking • Manage the firm's response program for client security questionnaires and due ...
Senior Associate - Operational Risk
New York, NY · On-site
$90K - $130K/yr
Undertake risk assessments of new third-party services as part of our Third-Party Risk Management framework and oversee the business due diligence process * Interact and coordinate with Portfolio ...
Senior Associate - Operational Risk
New York, NY · On-site
$90K - $130K/yr
Undertake risk assessments of new third-party services as part of our Third-Party Risk Management framework and oversee the business due diligence process * Interact and coordinate with Portfolio ...
... Third-Party Risk, Model Risk, or a related discipline. * 2+ years of hands-on experience in AI Governance, Responsible AI, AI Risk Management, AI Compliance, Model Risk Management, Machine Learning ...
... Third-Party Risk, Model Risk, or a related discipline. * 2+ years of hands-on experience in AI Governance, Responsible AI, AI Risk Management, AI Compliance, Model Risk Management, Machine Learning ...
Collateral Risk Manager
Manhattan, NY · On-site
$130K - $150K/yr
Purpose of Position The Collateral Risk Manager supports the Credit Risk Management department by ... Third-Party Report Procurement & Coordination * Manage the ordering of third-party due diligence ...
Quick apply
Collateral Risk Manager
Manhattan, NY · On-site
$130K - $150K/yr
Purpose of Position The Collateral Risk Manager supports the Credit Risk Management department by ... Third-Party Report Procurement & Coordination * Manage the ordering of third-party due diligence ...
Senior Associate - Operational Risk
New York, NY · Hybrid
$90K - $130K/yr
Undertake risk assessments of new third-party services as part of our Third-Party Risk Management framework and oversee the business due diligence process * Interact and coordinate with Portfolio ...
Senior Associate - Operational Risk
New York, NY · Hybrid
$90K - $130K/yr
Undertake risk assessments of new third-party services as part of our Third-Party Risk Management framework and oversee the business due diligence process * Interact and coordinate with Portfolio ...
Third Party Risk Manager information
See Edison, NJ salary details
$53.3K - $64.5K
4% of jobs
$64.5K - $75.6K
6% of jobs
$75.6K - $86.8K
11% of jobs
$91K is the 25th percentile. Wages below this are outliers.
$86.8K - $97.9K
11% of jobs
The median wage is $106.8K / yr.
$97.9K - $109.1K
23% of jobs
$109.1K - $120.2K
13% of jobs
$127.6K is the 75th percentile. Wages above this are outliers.
$120.2K - $131.4K
12% of jobs
$131.4K - $142.5K
8% of jobs
$142.5K - $153.7K
6% of jobs
$153.7K - $164.8K
4% of jobs
$164.8K - $176K
2% of jobs
$53.3K
$115.5K
$176K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
What is a Third Party Risk Manager?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 16 days ago
Job description
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & Security
Job Sub Function:
Security & Controls
Job Category:
Scientific/Technology
All Job Posting Locations:
Raritan, New Jersey, United States of America
Job Description:
Johnson & Johnson is recruiting for a Principal - Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk Assessment Center of Excellence (CoE). This role is based in the United States with the Raritan, NJ location preferred, but also available internally to our ISRM Service Centers in São José dos Campos, São Paulo, Brasil and Warsaw, Poland.
Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s): Raritan NJ, São José dos Campos, São Paulo, Brasil and Warsaw, Poland.
São José dos Campos, Brazil- Requisition Number: R-073330
Warsaw, Poland- Requisition Number: R-073331
Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.
This role serves as a senior technical authority and thought leader for third-party cyber risk assessments across Johnson & Johnson's global ecosystem of vendors, SaaS providers, and strategic partners.
Are you ready to use your technical knowledge to change the trajectory of health for humanity? We have a position for you!
Caring for the world, one person at a time inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products, and services to advance the health and well-being of people.
At Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That's why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world's largest and most broadly-based healthcare company, we are committed to using our reach and size for good. We strive to improve access and affordability, create healthier communities, and put a healthy mind, body and environment within reach of everyone, everywhere. Every day, our more than 130,000 employees across the world are blending heart, science and ingenuity to profoundly change the trajectory of health for humanity.
Thriving on a diverse company culture, celebrating the uniqueness of our employees, and committed to inclusion. Proud to be an equal opportunity employer!
As an integral member of the ISRM Risk Assessment Center of Excellence team, you will identify and assess cyber risks within the Third-Party Risk Assessment (TPRA) service. In this role, you will work with a diverse, global team of skilled cyber security professionals.
Key Responsibilities:
- Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.
- Perform deep technical reviews of third-party security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.
- Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and cross-border data flows.
- Identify, document, and risk-rate third-party cyber issues, ensuring consistent severity determination and alignment to ISRM standards.
- Drive automation and process improvements as identified and through relevant projects and/or operations.
- Communicate cybersecurity third-party risk assessment results to senior leaders and provide input on remediation plans.
- Enhance third-party cyber risk assessment processes by defining and implementing process improvements.
- Offer consulting support to the larger cybersecurity team on third-party risk assessment understanding and remediation.
- Lead and mentor junior members of the team, ensure ongoing learning, and support special projects as needed.
Qualifications
Education:
- A bachelor's degree in Computer Science, Engineering or Information Security/Cybersecurity or equivalent degree is required.
- Security certifications such as CISSP, CCSP, CISA, CRISC etc. are preferred.
- An advanced degree is preferred.
Experience and Skills:
Required:
- 5+ years of direct third-party cybersecurity risk assessment experience, including application of third-party risk assessment concepts and internal controls.
- 5+ years using ServiceNow GRC tool to support security risk objectives.
- Proficiency in conducting and leading third-party risk assessments, including data classification, risk scoring, and mitigation planning.
- Ability to translate technical findings into business impact for key partners.
- Strong analytical and problem-solving skills.
- Strong interpersonal skills to build and maintain relationships with internal partners.
Preferred:
- Foundational knowledge of regulatory requirements (e.g., SOX404, Privacy, HIPAA, GxP, cyber regulations).
- Experience assessing third-party risk in a large, dynamic, multinational organization.
- Experience in identifying key security risks, security controls, and providing consulting services to customers throughout the third-party vendor lifecycle.
- Experience with security standards and control frameworks (e.g. FAIR, HITRUST, ISO27001, NIST, SOC 2, etc.).
- Demonstrable record of effectively collaborating with virtual, global teams, including diverse groups of people with varied backgrounds and cultural experiences.
#LI-Hybrid
#JNJTECH
#LI-RW1
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.
Required Skills:
Preferred Skills:
Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management
The anticipated base pay range for this position is :
The anticipated base pay range for this position is: $102,000- $177,100
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation -120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year Holiday pay, including Floating Holidays -13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave - 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave - 10 days Volunteer Leave - 4 days Military Spouse Time-Off - 80 hours Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits