1

Third Party Risk Manager Jobs in Hanover, MD (NOW HIRING)

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...

... Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions, change control, and ...

Procurement Manager

Washington, DC · On-site

$130K - $160K/yr

Contribute to and help refine third-party risk management frameworks, standards, and practices. * Monitor vendor performance against cost, service, and delivery expectations, and partner with TPRM to ...

Be Seen First

Credit Manager

Baltimore, MD · On-site

$80K - $120K/yr

Analyze financial statements, cash flow, and credit risk for commercial customers. * Manage a portfolio of accounts and make credit recommendations based on financial data and third-party reporting.

Title: Director, Risk Management We are KBR When you become part of our KBR team, your ... and third-party administrators to mitigate financial exposure and drive favorable outcomes.

Showing results 21-40

Third Party Risk Manager information

See Hanover, MD salary details

$51.2K

$111K

$169.1K

How much do third party risk manager jobs pay per year?

As of Aug 9, 2026, the average yearly pay for third party risk manager in Hanover, MD is $110,998.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,500.00 and $128,400.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
What cities near Hanover, MD are hiring for Third Party Risk Manager jobs? Cities near Hanover, MD with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Hanover, MD as of August 2026, with employment types broken down into 78% Full Time, 21% Part Time, and 1% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $110,998 per year, or $53.4 per hour.

Senior Supply Chain Risk Management Threat Intelligence Analyst

Leidos

Washington, DC

Full-time

Posted 8 days ago


Leidos rating

8.3

Company rating: 8.3 out of 10

Based on 151 frontline employees who took The Breakroom Quiz

77th of 485 rated business services


Job description

Leidos is seeking a Senior Supply Chain Risk Management Threat Intelligence Lead Analyst to provide advanced, high-level technical and analytical support to the FAA's Counterintelligence (CI) Supply Chain Risk Management (SCRM) program. The program is responsible for identifying, assessing, and mitigating foreign intelligence, nation-state, and cybersecurity threats to the FAA's supply chain, critical infrastructure, and enterprise networks. Embedded as a senior leader within a 4-person team, this position focuses on threat landscapes, adversarial intent, and geopolitical vulnerability modeling. Providing independent, authoritative all-source intelligence analysis, the senior analyst designs analytic methodologies using Open Source Intelligence (OSINT) and corporate registries to uncover hidden Foreign Ownership, Control, or Influence (FOCI), technology transfer risks, and strategic threat trends targeting the aviation industrial base. This role oversees the evaluation of physical, technical, and personnel vulnerabilities, including sophisticated hardware/firmware threats and insider risks, to produce exquisite intelligence briefings that guide FAA executive leadership and empower the broader SCRM framework.

Primary Responsibilities:

  • Act as lead analyst ensuring strict quality control, mentoring, and analytical integrity across all FAA CI SCRM products.
  • Conduct proactive threat analysis of foreign suppliers, third-party software developers, and hardware manufacturers to identify nation-state activity and strategic threat trends targeting the FAA.
  • Utilize OSINT and corporate registries to screen prospective FAA vendors and evaluate the supply chain for Foreign Ownership, Control, or Influence (FOCI) indicators, foreign partnerships, and technology transfer threats.
  • Monitor specialized threat feeds, nation-state activities, and geopolitical shifts to identify, evaluate, and mitigate strategic supply chain risks to the FAA.
  • Support the FAA Insider Risk Program by identifying and analyzing personnel concerns, anomalous vendor behaviors, and internal vulnerabilities.
  • Evaluate threat vectors including malicious hardware or software modifications, supply chain transit interdiction, and counterfeit electronic components.
  • Synthesize complex data to produce clear, actionable Supplier Threat Profiles, Country Risk Profiles, link-analysis diagrams, and timely threat alerts/advisories for FAA program managers, technical teams, and executive decision-makers.
  • Translate highly complex counterintelligence findings, technical hardware/software vulnerabilities, and macroeconomic geopolitical risks into exquisite intelligence briefings, dashboards, and executive decision packages tailored specifically for senior FAA leadership.
  • Formulate performance metrics and program reports for executive leadership.
  • Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
  • Coordinate and facilitate SCRM training and awareness campaigns for acquisition personnel and program offices.

Basic Qualifications:

  • Citizenship: U.S. Citizenship required.
  • Clearance: Active Top Secret/SCI clearance is required.
  • Education: Bachelor's or Master's degree in Supply Chain, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science, Computer Engineering, or a related technical discipline. (Equivalent professional experience or specialized military/federal training may be substituted).
  • Experience: 12+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or Open-Source Intelligence) or senior-level experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, IT auditing, cybersecurity risk management, or infrastructure defense in a federal or highly regulated commercial environment.
  • Analytical Capability: Proven experience using corporate registries, commercial databases, and OSINT techniques to analyze corporate structures, trace components, and evaluate FOCI.
  • Technical Skills: Proficiency with due diligence or corporate intelligence platforms (e.g., Sayari, Altana, Interos, Maltego) and/or data modeling.
  • Communication Skills: Exceptional written and verbal communication skills, with a proven track record of translating complex intelligence and technical risk data into clear, concise executive briefs and formal written reports for non-technical stakeholders and delivering briefing materials to C-suite or flag-level leadership.

Preferred Qualifications:

  • Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
  • High proficiency with advanced OSINT search techniques, corporate filing retrieval systems, and international trade/shipping databases.
  • Familiarity with the acquisition frameworks and an understanding of how supply chain intelligence feeds into federal procurement lifecycles.
  • Prior experience supporting threat intelligence or counterintelligence infrastructure defense missions specifically for critical infrastructure or a federal agency.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 - and moving faster than anyone else dares.

Original Posting:July 31, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:Pay Range $116,350.00 - $210,325.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.


What Leidos employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Leidos logo

About Leidos

Sourced by ZipRecruiter

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Reston, VA, US

Social media