1

Third Party Risk Manager Jobs in Frederick, MD (NOW HIRING)

Senior Program Manager

Leesburg, VA · On-site

$117K - $117K/yr

Establish program steering committees, corporate risk management frameworks, and KPIs to track ... HCM and third-party systems using Oracle Integration Cloud (OIC) and Fast Formulas. * Ensure ...

Grievance Coordinator

Frederick, MD

$19.75 - $24.75/hr

The Coordinator works collaboratively with the Performance Improvement, Risk Management ... Joint Commission, or other third party companies related to patient/family complaints.

Grievance Coordinator

Frederick, MD · On-site

$28.86 - $41.22/hr

The Coordinator works collaboratively with the Performance Improvement, Risk Management ... Joint Commission, or other third party companies related to patient/family complaints.

Project Manager (IPT)

Rockville, MD · On-site

$115K - $140K/yr

Organize and manage RFI and Value Engineering logs, and Risk logs. * Document meetings with ... Manage RFPs for subcontractors and third-party engineering scopes, including bid leveling and scope ...

Organize and manage RFI and Value Engineering logs, and Risk logs. * Document meetings with ... Manage RFPs for subcontractors and third-party engineering scopes, including bid leveling and scope ...

next page

Showing results 1-20

Third Party Risk Manager information

See Frederick, MD salary details

$51.2K

$110.9K

$169K

How much do third party risk manager jobs pay per year?

As of Jul 27, 2026, the average yearly pay for third party risk manager in Frederick, MD is $110,917.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,500.00 and $128,300.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a Third Party Risk Manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
What cities near Frederick, MD are hiring for Third Party Risk Manager jobs? Cities near Frederick, MD with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Frederick, MD as of July 2026, with employment types broken down into 89% Full Time, 10% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $110,917 per year, or $53.3 per hour.
FY27: IT Systems Engineer, Information Security and Compliance, Dept Infrastructure/Operations, 8...

FY27: IT Systems Engineer, Information Security and Compliance, Dept Infrastructure/Operations, 8...

Montgomery County Public Schools

Rockville, MD

Full-time

Posted 2 days ago


Montgomery County Public Schools (Virginia) rating

7.3

Company rating: 7.3 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

212th of 616 rated elementary and secondary schools


Job description

Summary Description:
Under direction of the Director of the Department of Cybersecurity and Technology Infrastructure, coordinates, designs, and maintains system-wide information security and compliance initiatives; safeguards enterprise systems and data by defining access privileges, control structures, and resources, as determined by best practices, industry standards, and stakeholder needs; identifies and mitigates system vulnerabilities, violations, and inefficiencies through routine audits; provides status updates on system performance through multiple means; acts on privacy breaches and malware threats. Executes and supports Risk Management Framework (RMF) activities and ensures compliance with Maryland Department of IT processes and documentation standards. Supports enterprise architecture governance by maintaining architecture artifacts, system documentation, and technical configuration diagrams. Lead engineer on network Disaster Recovery solutions, reviewing vendor security reports, and cybersecurity strategies. Effectively communicates with staff and stakeholders, including senior leadership.Physical Demands: Position is required to work at computer workstations for sustained periods of time. Special Requirements: Ability to work extended hours, especially during peak periods and when urgent work requirements exist.

Knowledge Skills Abilities:
Thorough knowledge and experience with risk management processes, cybersecurity and privacy policies and procedures, vulnerability and threat management, vulnerability assessment tools and techniques, network security principles and practices. Ability to identify and mitigate network vulnerabilities, as well as communicate best practices to avoid security flaws. Thorough knowledge of disaster recovery and business continuity best practices for critical systems required. Ability to construct high level and detail level network security and disaster recovery diagrams to be shared with management, other departments, and coworkers. Ability to manage multiple complex projects and tasks while paying close attention to details. Thorough knowledge of risk management framework and system risk assessments to prepare school system for state and county audits by documenting the environment and providing guidance to system stakeholders. Strong analytical and problem-solving skills. Skilled in decision making with a track record of exercising good judgment. Must be detail-oriented, highly organized, and an effective communicator. Excellent oral and written communication and human relations skills.
Education Training Experience:
Bachelor of Science or Bachelor of Arts degree in Computer Science, Information Technology systems, or related field from an accredited university required. Master?s degree preferred. Five years or more documented professional experience in technology. Proven experience in information system security operation, information system security assessment, system documentation, risk mitigation, vulnerability management, networking systems and/or network security (i.e., DNS, firewalls, proxies), agentless security, and XaaS (e.g., SaaS, IaaS, PaaS, DaaS, FaaS). Experience implementing industry standard information security frameworks, policies and procedures. Experience supporting GRC capabilities such as policy management, security awareness training, third-party risk management, and metrics and reporting. Experience in deploying various solutions to scale GRC processes including but not limited to security questionnaires, risk assessment, evidence collection, and control testing. Experience designing, reviewing, deploying, and auditing AI-powered solutions (including agents) and apply LLMs/NLP to analyze policies, audit findings, and regulatory requirements preferred. Certificate License: Professional certification in one or more of the following: CISSP, CompTIA Security , CISA preferred.


What Montgomery County Public Schools (Virginia) employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom