1

Third Party Risk Manager Jobs in Fort Mill, SC (NOW HIRING)

Third Party Account Manager

Charlotte, NC · Hybrid

$22.85 - $34.27/hr

In the Third Party world, Account Managers are often the engine behind every successful Non-QM transaction, ensuring all conditions are cleared, files are accurate, and pipelines move swiftly. If you ...

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...

... Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions, change control, and ...

Reporting to the Head of Sourcing, this leader will work within a third-party risk management (TPRM) framework, including established policies, standards, and compliance requirements, and will be ...

Showing results 21-40

Third Party Risk Manager information

See Fort Mill, SC salary details

$45.3K

$98K

$149.4K

How much do third party risk manager jobs pay per year?

As of Aug 19, 2026, the average yearly pay for third party risk manager in Fort Mill, SC is $98,030.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,100.00 and $113,400.00 per year, depending on experience, location, and employer.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

Is third party risk manager a good career?

A third party risk manager plays a key role in assessing and mitigating risks associated with external vendors and partners, often requiring knowledge of compliance standards and risk management tools. The role offers opportunities for advancement in industries such as finance, healthcare, and technology, with a growing demand for professionals skilled in risk assessment and regulatory requirements. It can be a stable and rewarding career for those with strong analytical skills and attention to detail.

What cities near Fort Mill, SC are hiring for Third Party Risk Manager jobs?

Cities near Fort Mill, SC with the most Third Party Risk Manager job openings:

Infographic showing various Third Party Risk Manager job openings in Fort Mill, SC as of August 2026, with employment types broken down into 90% Full Time, 9% Part Time, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $98,030 per year, or $47.1 per hour.

Senior Manager Cybersecurity

Duke Energy Corporation

Charlotte, NC • On-site

$108K - $146K/yr

Full-time

Posted 5 days ago


Duke Energy rating

8.6

Company rating: 8.6 out of 10

Based on 167 frontline employees who took The Breakroom Quiz

12th of 87 rated oil and gas companies


Job description

Important Application Submission Information
In order to ensure your application is successfully received before the job posting expires, please submit your application by 11:59 PM on Sunday, August 23, 2026
More than a career - a chance to make a difference in people's lives.
Build an exciting, rewarding career with us - help us make a difference for millions of people every day. Consider joining the Duke Energy team, where you'll find a friendly work environment, opportunities for growth and development, recognition for your work, and competitive pay and benefits.
Job Summary
Leads Duke Energy's Cybersecurity Supply Chain Risk Management (C-SCRM), Third-Party Risk Management (TPRM), and Cybersecurity Culture & Awareness programs. Responsible for establishing strategy, governance, operational processes, and performance metrics that identify, assess, mitigate, monitor, and report cybersecurity risk arising from suppliers, vendors, service providers, software providers, cloud providers, and other external dependencies. Oversees the enterprise cybersecurity culture and awareness program to strengthen employee security behaviors, reduce human risk, and improve organizational cyber resilience.
Leads managers and cybersecurity professionals responsible for supplier and third-party cyber risk assessments, continuous monitoring, contractual cybersecurity requirements, secure software supply chain governance, awareness training, phishing resilience, culture measurement, and executive engagement programs. Ensures alignment with cybersecurity strategy, regulatory obligations, business objectives, and industry frameworks.
Responsibilities
  • Develop and maintain the enterprise Cybersecurity Supply Chain Risk Management (C-SCRM) and TPRM governance framework.
  • Provide clear risk mitigating directives for projects/initiatives/services including the application of controls to protect company assets.
  • Maintain and support a document framework of continuously up-to-date cybersecurity policies, standards and guidelines for the TPRM and Cybersecurity Awareness programs.
  • Help create the necessary internal networks among the cybersecurity team and line-of-business areas to ensure alignment as required.
  • Manage end-to-end third-party cyber risk lifecycle activities including:
    • Intake
    • Risk assessment
    • Remediation tracking
    • Exception management
    • Periodic reassessment
    • Offboarding
  • Oversee cyber assessments utilizing:
    • SIG questionnaires
    • SOC 1/SOC 2 reports
    • ISO certifications
    • Independent assessments
    • Continuous monitoring platforms
  • Provide regular reporting on the status of the Third-Party Risk Management (TPRM) and Cybersecurity Awareness programs as part of a strategic enterprise risk management program, thus supporting business positive outcomes.
  • Support a process for monitoring and periodically re-assessing third parties to ensure compliance with obligations.
  • Work with Legal and Supply Chain to ensure that cybersecurity requirements and the right to assess third parties be included in contracts/agreements.
  • Oversee the cybersecurity awareness and training program for all employees, contractors and approved system users, including formation, evaluation and action plans based on metrics regarding program effectiveness.

Required/Basic Qualifications
  • Bachelors degree in Cybersecurity, Computer Science, Management Information Systems, or Other Related Degree
  • Minimum 10 years related work experience
  • In lieu of Bachelors degree(s) AND 10 year(s) related work experience listed above, High School/GED AND 14 year(s) related work experience

Desired Qualifications
  • Experience designing, implementing, and leading Third Party Risk Management (TPRM) programs at scale.
  • Knowledge of applicable NIST and ISO 27001/27036 Cybersecurity standards along with SOC1/SOC2 Type 1/Type 2 reports.
  • Strong experience addressing senior-level leadership and the ability to collaborate and lead cross-functional teams and initiatives.
  • Experience in inspiring change and leading a large-scale risk management framework in a large company.
  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate cybersecurity and risk-related concepts to technical and nontechnical audiences at various hierarchical levels, ranging from individual contributors to senior staff.
  • Excellent analytical skills, the ability to manage multiple projects under strict timelines, as well as the ability to work well in a demanding, dynamic environment and meet overall objectives.
  • Ability to lead and motivate the cybersecurity team to achieve tactical and strategic goals.
  • Professional security management certification is desirable, such as Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.
  • Experience with contract and vendor negotiations
  • High degree of initiative, dependability and ability to work with little supervision while being resilient to change
  • Works effectively with a variety of personalities and can adapt his/her approach to effectively reach and develop his/her team. Uses this skill as well as his/her functional knowledge to both earn and maintain a high level of credibility with the team.

Working Conditions
  • Hybrid Mobility Classification - Work will be performed from both remote and onsite locations after the onboarding period. However, hybrid employees should live within a reasonable daily commute to a Duke Energy facility.
  • Office Environment

Specific Requirements
  • Bachelor of Science or Bachelor of Arts degree, preferably in Cybersecurity, Information Security, Computer Science, Management Information Systems or other closely related fields
  • 10+ years of experience in Cybersecurity fields, or roles focused on cybersecurity or IT functions, to include at least 1 year of managerial experience in addition to a degree OR 14+ years of Cybersecurity related experience, to include at least 1 year of managerial experience in lieu of a degree
  • Ability to obtain one of the following within three years of hire: Certified Information Systems Security Professional (CISSP), Certified Cybersecurity Manager (CISM), Certified Information Systems Auditor (CISA) or other similar credentials.

Travel Requirements
5-15%
Relocation Assistance Provided (as applicable)
No
Represented/Union Position
No
Visa Sponsored Position
No. This is not a Visa Sponsored Position. This role requires the ability to work lawfully in the U.S. without employment-based immigration sponsorship, now or in the future.
Please note that in order to be considered for this position, you must possess all of the basic/required qualifications.
Privacy
Do Not Sell My Personal Information (CA)
Terms of Use
Accessibility

What Duke Energy employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Duke Energy logo

About Duke Energy

Sourced by ZipRecruiter

Duke Energy, a Fortune 150 company headquartered in Charlotte, N.C., is one of America’s largest energy holding companies. Our electric utilities serve 8.2 million customers in North Carolina, South Carolina, Florida, Indiana, Ohio and Kentucky, and collectively own 50,000 megawatts of energy capacity. Our natural gas unit serves 1.6 million customers in North Carolina, South Carolina, Tennessee, Ohio and Kentucky. Our company employs 28,000 people.

Industry

Utilities

Company size

10,000+ Employees

Headquarters location

Charlotte, NC, US

Year founded

1904