The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the ...
Third-Party Risk Management (TPRM) * Enterprise Risk Management * Operational Risk Management * Technology Risk Assessment * Information Security Risk * Privacy Risk Assessment * Cybersecurity Risk ...
Third-Party Risk Management (TPRM) * Enterprise Risk Management * Operational Risk Management * Technology Risk Assessment * Information Security Risk * Privacy Risk Assessment * Cybersecurity Risk ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Evaluate vendor and third-party cybersecurity risks * Conduct security assessments and due ... NIST Risk Management Framework (RMF) * NIST SP 800-53 / 800-171 * Experience supporting audits ...
GRC Lead / Cyber Risk Manager
$125K - $169K/yr
Evaluate vendor and third-party cybersecurity risks * Conduct security assessments and due ... NIST Risk Management Framework (RMF) * NIST SP 800-53 / 800-171 * Experience supporting audits ...
GRC Lead / Cyber Risk Manager
Washington, DC · On-site
$125K - $169K/yr
... Third-Party Risk Management Evaluate vendor and third-party cybersecurity risks Conduct security assessments and due diligence reviews Ensure contractual security and compliance requirements are met ...
GRC Lead / Cyber Risk Manager
Washington, DC · On-site
$125K - $169K/yr
... Third-Party Risk Management Evaluate vendor and third-party cybersecurity risks Conduct security assessments and due diligence reviews Ensure contractual security and compliance requirements are met ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · On-site +1
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Washington, DC · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory ...
Quick apply
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory ...
Quick apply
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... Third-Party Risk Management, Country Risk, Technology Risk Management). * Executes challenge ... activities to elevate areas of suspected risk and escalates appropriately to Operational Risk ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... expansion opportunities and design integrated risk advisory solutions. * Establish and maintain ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... expansion opportunities and design integrated risk advisory solutions. * Establish and maintain ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... expansion opportunities and design integrated risk advisory solutions. * Establish and maintain ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... expansion opportunities and design integrated risk advisory solutions. * Establish and maintain ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory ...
Vendor Security Manager
Washington, DC · On-site
$58 - $72/hr
Lead the organization's third-party risk management and vendor security program. * Manage and oversee vendor security assessments, ensuring compliance with internal policies and regulatory ...
Principal Program Manager
Reston, VA · On-site
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
Principal Program Manager
Reston, VA · On-site
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
Principal Program Manager
Reston, VA · On-site
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
Principal Program Manager
Reston, VA · On-site
As a Principal Program Manager on the Cybersecurity Risk team, you will own and evolve our ... Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ...
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Manage 30-80 third-party vendor relationships requiring security assessment. * Conduct 20-40 vendor security assessments annually. * Review 50-150 commercial software products for supply chain risk.
Support compliance-related third-party risk identification, assessment, and mitigation activities by facilitating implementation of policies, processes, and controls designed to manage vendor and ...
Support compliance-related third-party risk identification, assessment, and mitigation activities by facilitating implementation of policies, processes, and controls designed to manage vendor and ...
Implementation Manager
Mclean, VA · On-site
You understand the processes, pain points, and personas in third party management, supply chain management, procurement, risk, and compliance * You lead inspirational, tailored presentations in a ...
Implementation Manager
Mclean, VA · On-site
You understand the processes, pain points, and personas in third party management, supply chain management, procurement, risk, and compliance * You lead inspirational, tailored presentations in a ...
Evaluate governance, cybersecurity, technology and data controls, fraud risk management, and third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and regulatory ...
Evaluate governance, cybersecurity, technology and data controls, fraud risk management, and third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and regulatory ...
Support compliance-related third-party risk identification, assessment, and mitigation activities by facilitating implementation of policies, processes, and controls designed to manage vendor and ...
Support compliance-related third-party risk identification, assessment, and mitigation activities by facilitating implementation of policies, processes, and controls designed to manage vendor and ...
Evaluate governance, cybersecurity, technology and data controls, fraud risk management, and third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and regulatory ...
Evaluate governance, cybersecurity, technology and data controls, fraud risk management, and third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and regulatory ...
Third Party Risk Manager information
See Lanham, MD salary details
$51.5K - $62.3K
4% of jobs
$62.3K - $73.1K
6% of jobs
$73.1K - $83.9K
11% of jobs
$87.9K is the 25th percentile. Wages below this are outliers.
$83.9K - $94.7K
11% of jobs
The median wage is $103.2K / yr.
$94.7K - $105.5K
23% of jobs
$105.5K - $116.2K
13% of jobs
$123.3K is the 75th percentile. Wages above this are outliers.
$116.2K - $127K
12% of jobs
$127K - $137.8K
8% of jobs
$137.8K - $148.6K
6% of jobs
$148.6K - $159.4K
4% of jobs
$159.4K - $170.1K
2% of jobs
$51.5K
$111.6K
$170.1K
How much do third party risk manager jobs pay per year?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
What are the key skills and qualifications needed to thrive as a third party risk manager?
What is a third party risk manager?
How does a third party risk manager typically collaborate with other departments to manage vendor risks?

Full-time
Re-posted 24 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll do
The Consultant II - Technology Third Party Risk Management role in the Tax Transformation Office requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Executing TPRM review activities - coordinating intake, gathering and organizing due diligence documentation (such as security questionnaires and SOC reports), and tracking reviews through completion for new and renewing vendors under the guidance of senior team members.
- Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team leads.
- Serving as a day-to-day contact for routine TPRM process questions - responding to standard inquiries from business sponsors and vendor managers, and escalating more complex or judgment-based questions to senior team members.
- Coordinating with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - gathering required inputs, following up on outstanding items, and helping ensure consistent application of established policies and procedures.
- Supporting process improvement efforts - surfacing friction points observed during reviews and contributing to improvements in tooling, documentation standards, and workflows.
- Contributing to broader TTO Strategic Technology Services initiatives - assisting with vendor portfolio tracking, alliance program operations, and other activities that support the team's objectives.
A successful candidate would possess these skills:
- Strong communicator who can tailor messages for technical and non-technical audiences and keep stakeholders informed and aligned.
- Collaborative relationship builder who works effectively across functions and levels to drive consensus and move work forward.
- Adaptable, self-directed problem solver who can manage shifting priorities, multiple workstreams, and competing deadlines.
- Confident facilitator who influences without authority, resolves routine issues, and escalates effectively when needed.
The Team
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 1+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
Preferred:
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $76,600 to $157,000.
The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll do
The Consultant II - Technology Third Party Risk Management role in the Tax Transformation Office requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Executing TPRM review activities - coordinating intake, gathering and organizing due diligence documentation (such as security questionnaires and SOC reports), and tracking reviews through completion for new and renewing vendors under the guidance of senior team members.
- Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team leads.
- Serving as a day-to-day contact for routine TPRM process questions - responding to standard inquiries from business sponsors and vendor managers, and escalating more complex or judgment-based questions to senior team members.
- Coordinating with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - gathering required inputs, following up on outstanding items, and helping ensure consistent application of established policies and procedures.
- Supporting process improvement efforts - surfacing friction points observed during reviews and contributing to improvements in tooling, documentation standards, and workflows.
- Contributing to broader TTO Strategic Technology Services initiatives - assisting with vendor portfolio tracking, alliance program operations, and other activities that support the team's objectives.
A successful candidate would possess these skills:
- Strong communicator who can tailor messages for technical and non-technical audiences and keep stakeholders informed and aligned.
- Collaborative relationship builder who works effectively across functions and levels to drive consensus and move work forward.
- Adaptable, self-directed problem solver who can manage shifting priorities, multiple workstreams, and competing deadlines.
- Confident facilitator who influences without authority, resolves routine issues, and escalates effectively when needed.
The Team
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 1+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
Preferred:
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $76,600 to $157,000.