You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
Service Now Business Analyst
Seattle, WA · On-site
Integrated Risk Management (IRM), Security Incident Response (SIR), Security Operations (SecOps), Third-party Risk Management (TPRM, previously VRM), and Vulnerability Response (VR), as bonus. The ...
Quick apply
Service Now Business Analyst
Seattle, WA · On-site
Integrated Risk Management (IRM), Security Incident Response (SIR), Security Operations (SecOps), Third-party Risk Management (TPRM, previously VRM), and Vulnerability Response (VR), as bonus. The ...
... management ... and third party risk issues and vulnerabilities by working with multiple stakeholder teams ...
... management ... and third party risk issues and vulnerabilities by working with multiple stakeholder teams ...
Internal and third-party risk assessments and remediation tracking * * Collaborate with product and ... Strong risk management mindset: ability to assess risk, articulate tradeoffs, and drive practical ...
Internal and third-party risk assessments and remediation tracking * * Collaborate with product and ... Strong risk management mindset: ability to assess risk, articulate tradeoffs, and drive practical ...
Internal and third-party risk assessments and remediation tracking * * Collaborate with product and ... Strong risk management mindset: ability to assess risk, articulate tradeoffs, and drive practical ...
Internal and third-party risk assessments and remediation tracking * * Collaborate with product and ... Strong risk management mindset: ability to assess risk, articulate tradeoffs, and drive practical ...
Internal and third-party risk assessments and remediation tracking * * Collaborate with product and ... Strong risk management mindset: ability to assess risk, articulate tradeoffs, and drive practical ...
Internal and third-party risk assessments and remediation tracking * * Collaborate with product and ... Strong risk management mindset: ability to assess risk, articulate tradeoffs, and drive practical ...
... management ... and third party risk issues and vulnerabilities by working with multiple stakeholder teams ...
... management ... and third party risk issues and vulnerabilities by working with multiple stakeholder teams ...
Review and guide enterprise risk assessments across cyber, IT, third-party, and operational domains, ensuring risks are understood, prioritized, and actively managed * Oversee internal and external ...
Review and guide enterprise risk assessments across cyber, IT, third-party, and operational domains, ensuring risks are understood, prioritized, and actively managed * Oversee internal and external ...
... management ... and third party risk issues and vulnerabilities by working with multiple stakeholder teams ...
... management ... and third party risk issues and vulnerabilities by working with multiple stakeholder teams ...
Cyber Risk Manager
$62.59 - $93.90/hr
The Cyber Risk Manager is responsible for leading the cyber risk management function, ensuring that ... Directly conduct or support third-party/consultant conducting of cyber risk assessments. Risk ...
Cyber Risk Manager
$62.59 - $93.90/hr
The Cyber Risk Manager is responsible for leading the cyber risk management function, ensuring that ... Directly conduct or support third-party/consultant conducting of cyber risk assessments. Risk ...
CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS-Vulnerability Response (CIS-VR), CIS-Third-Party Risk Management (CIS-TPRM), CIS-Hardware Asset Management (CIS-HAM ...
CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS-Vulnerability Response (CIS-VR), CIS-Third-Party Risk Management (CIS-TPRM), CIS-Hardware Asset Management (CIS-HAM ...
Cyber Risk Manager
Seattle, WA · On-site
$62.59 - $93.90/hr
The Cyber Risk Manager is responsible for leading the cyber risk management function, ensuring that ... Directly conduct or support third-party/consultant conducting of cyber risk assessments. Risk ...
Cyber Risk Manager
Seattle, WA · On-site
$62.59 - $93.90/hr
The Cyber Risk Manager is responsible for leading the cyber risk management function, ensuring that ... Directly conduct or support third-party/consultant conducting of cyber risk assessments. Risk ...
Risk Manager II - AMZ9674709
Seattle, WA · On-site
$84.24K - $129.80K/yr
Risk Manager II Job Location: Seattle, Washington Job Number: AMZ9674709 Position Responsibilities ... Manage cross-functional teams and/or third party-vendors for implementation of project/program ...
Risk Manager II - AMZ9674709
Seattle, WA · On-site
$84.24K - $129.80K/yr
Risk Manager II Job Location: Seattle, Washington Job Number: AMZ9674709 Position Responsibilities ... Manage cross-functional teams and/or third party-vendors for implementation of project/program ...
ServiceNow Developer - Senior Consultant
Seattle, WA · On-site
$61.50 - $84.50/hr
CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS-Vulnerability Response (CIS-VR), CIS-Third-Party Risk Management (CIS-TPRM), CIS-Hardware Asset Management (CIS-HAM ...
ServiceNow Developer - Senior Consultant
Seattle, WA · On-site
$61.50 - $84.50/hr
CIS-Risk and Compliance (CIS-RC), CIS-Security Incident Response (CIS-SIR), CIS-Vulnerability Response (CIS-VR), CIS-Third-Party Risk Management (CIS-TPRM), CIS-Hardware Asset Management (CIS-HAM ...
Director Fraud Risk Management
Bellevue, WA · On-site +1
$238.82K/yr
Proven ability to manage third-party risk vendors, negotiate contracts, and lead cross-functional initiatives. * Strong relationship, interpersonal and leadership skills. * Strong analytical, problem ...
Quick apply
Director Fraud Risk Management
Bellevue, WA · On-site +1
$238.82K/yr
Proven ability to manage third-party risk vendors, negotiate contracts, and lead cross-functional initiatives. * Strong relationship, interpersonal and leadership skills. * Strong analytical, problem ...
Risk Manager III - AMZ9442485
Seattle, WA · On-site
$125.53K - $163.90K/yr
Risk Manager III Job Location: Seattle, Washington Job Number: AMZ9442485 Position Responsibilities ... Evaluate and negotiate contracts for third party data needed for improved underwriting. Define ...
Risk Manager III - AMZ9442485
Seattle, WA · On-site
$125.53K - $163.90K/yr
Risk Manager III Job Location: Seattle, Washington Job Number: AMZ9442485 Position Responsibilities ... Evaluate and negotiate contracts for third party data needed for improved underwriting. Define ...
Director Fraud Risk Management
Bellevue, WA · On-site +1
$238.82K/yr
Proven ability to manage third-party risk vendors, negotiate contracts, and lead cross-functional initiatives. * Strong relationship, interpersonal and leadership skills. * Strong analytical, problem ...
Director Fraud Risk Management
Bellevue, WA · On-site +1
$238.82K/yr
Proven ability to manage third-party risk vendors, negotiate contracts, and lead cross-functional initiatives. * Strong relationship, interpersonal and leadership skills. * Strong analytical, problem ...
Director Fraud Risk Management
Bellevue, WA · On-site +1
$238.82K/yr
Proven ability to manage third-party risk vendors, negotiate contracts, and lead cross-functional initiatives. * Strong relationship, interpersonal and leadership skills. * Strong analytical, problem ...
Director Fraud Risk Management
Bellevue, WA · On-site +1
$238.82K/yr
Proven ability to manage third-party risk vendors, negotiate contracts, and lead cross-functional initiatives. * Strong relationship, interpersonal and leadership skills. * Strong analytical, problem ...
Third Party Risk Manager information
See Renton, WA salary details
$57.9K - $70K
4% of jobs
$70K - $82.2K
6% of jobs
$82.2K - $94.3K
11% of jobs
$98.8K is the 25th percentile. Wages below this are outliers.
$94.3K - $106.4K
11% of jobs
The median wage is $116K / yr.
$106.4K - $118.5K
23% of jobs
$118.5K - $130.6K
13% of jobs
$138.6K is the 75th percentile. Wages above this are outliers.
$130.6K - $142.8K
12% of jobs
$142.8K - $154.9K
8% of jobs
$154.9K - $167K
6% of jobs
$167K - $179.1K
4% of jobs
$179.1K - $191.2K
2% of jobs
$57.9K
$125.5K
$191.2K
How much do third party risk manager jobs pay per year?
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?
What is a Third Party Risk Manager?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

Full-time
Posted 21 days ago
Amazon rating
7.4
Based on 6,788 frontline employees who took The Breakroom Quiz
7th of 39 rated national retailers
Job description
The Benefits Experience and Technology Risk team (BXT Risk) is responsible for managing employee benefits risk activities in countries where we do business. As a Senior Security Risk Specialist on the BXT Risk team, you will serve as a subject matter expert and strategic contributor to our benefits third-party risk ecosystem, working across the organization with US benefits policy, process, and system owners to define strategies, evaluate complex risks, and drive scalable solutions that mitigate risks introduced by third-party vendors and service providers supporting the organization's US health and financial employee benefit programs.
This role requires both tactical execution and strategic thinking. You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management capabilities, and drive alignment across diverse stakeholders with potentially conflicting priorities
You will create predictable process paths and repeatable mechanisms that multiple teams utilize, mentor junior team members, and advise managers and directors on third-party risk matters affecting employee benefits programs.
Key job responsibilities
Third-Party Risk Strategy and Assessment:
- Lead complex third-party vendor risk assessments across multiple benefits programs and vendor relationships, evaluating security, privacy, and compliance posture against federal, state, and local regulatory requirements
- Define and iterate on risk assessment methodologies, frameworks, and mechanisms to scale for diverse vendor requirements and evolving regulatory expectations (e.g., quantitative risk models, vendor risk questionnaires, continuous monitoring approaches)
- Identify long-term risks associated with third-party vendors and influence business strategy to proactively mitigate them before they materialize into risk events
- Make diligent, independent decisions on how to engage vendors, auditors, and regulators on third-party risk matters with minimal oversight
- Drive comprehensive benefits compliance management related to third-party service delivery, ensuring adherence to federal, state, and local regulatory requirements including HIPAA, ERISA, ACA, and COBRA
- Lead risk and control assessments of vendor-managed processes, determine state of compliance, analyze risk exposure, and author reports detailing methodology, results, and remediation plans
Program Leadership and Scalable Solutions:
- Own and drive third-party risk review programs associated with benefits program launches, modifications, vendor onboarding, and transitions across the organization
- Create predictable process paths, workflows, and repeatable mechanisms (e.g., for vendor security control design, testing, implementation, and validation) that multiple teams utilize to deliver consistent risk management outcomes
- Identify opportunities to simplify approaches throughout the organization and across project boundaries; decouple dependencies and prevent duplicate or wasted effort
- Define business problems, set objectives, analyze data, drive improvements, and influence resource allocation for third-party risk initiatives
- Develop mechanisms to inspect, monitor, and improve third-party risk delivery over time; hold the team to a high standard for both solutions and practices
- Escalate when risks or blockers emerge, propose viable recommendations to resolve them, identify the correct owners, and track issues to resolution
Vendor Systems, Process, and Compliance Oversight:
- Develop deep understanding of the employee benefits solutions utilized by Amazon and the third-party vendors that support them; drive business requirements for vendor system implementations and enhancements
- Lead collaboration with vendors and external teams to evaluate security controls, negotiate remediation timelines, and ensure employee-centered benefits experiences are delivered securely
- Understand the builder and stakeholder experience with security compliance and proactively seek to align third-party risk processes with existing workflows
- Author written narratives to define strategy, evaluate trade-offs, anticipate risks, and recommend solutions on third-party risk that influence the organization and external partners
Stakeholder Engagement, Influence, and Communication:
- Drive business and technical discussions across the organization to make decisions on how to align with diverse, potentially conflicting, third-party risk and compliance expectations
- Advise managers and directors on third-party risk matters; communicate effectively with leaders up to three levels above on risk posture, compliance gaps, and strategic recommendations
- Write, speak, and network with key internal and external stakeholders to broaden influence on third-party risk management practices
- Develop and deliver documentation such as manager and employee communications, FAQs, policy positions, standard operating procedures, and strategic narratives related to third-party risk
- Mentor and develop junior team members in third-party risk assessment methodologies, compliance frameworks, and stakeholder engagement
About the team
The BXT Risk team is made up of lawyers, risk specialists, data security specialists, automation experts, and privacy specialists with global HR and benefits backgrounds. We are a dedicated collective committed to creating supportive, comprehensive benefits solutions. We provide our benefits stakeholders guidance to help them identify and manage potential risks and improve their team's risk management strategies and compliance posture
The team proactively scans the horizon for new and emerging risks not yet fully developed or understood, and performs inspections to identify compliance gaps and control weaknesses before they materialize into risk events. We provide end-to-end risk management oversight, including risk identification, risk assessments, risk quantification, compliance advisory services, inspection services, control design and testing, compliance solutions, risk monitoring and reporting, issue management, and risk training.
We cultivate an environment where every team member feels valued, empowered, and equipped to thrive both professionally and personally. Our work goes beyond benefits operations - we're building experiences that genuinely care for our employees.
About Amazon
Sourced by ZipRecruiter
Amazon.com, Inc., commonly known as Amazon, is an American multinational technology company. It was founded by Jeff Bezos in 1994 and initially started as an online marketplace for books. Since then, Amazon has expanded its operations and become one of the largest e-commerce companies in the world. Amazon's primary business is its online retail platform, where customers can purchase a vast array of products, including electronics, clothing, books, home goods, and much more. The company offers a convenient and user-friendly shopping experience, with features such as fast shipping, customer reviews, and personalized recommendations. In addition to its e-commerce platform, Amazon has diversified its business into various other areas. One of its notable ventures is Amazon Web Services (AWS), a comprehensive cloud computing platform that provides services such as storage, compute power, and database management to individuals and businesses. AWS has become a leader in the cloud computing industry, powering many websites and applications worldwide. Amazon has also developed its own consumer electronics, including the popular Amazon Kindle e-reader, Fire tablets, Fire TV streaming devices, and the Alexa-powered Echo smart speakers. The Alexa voice assistant, integrated into these devices, allows users to interact with their devices using voice commands, perform tasks, and access information. Furthermore, Amazon has expanded into media and entertainment. It operates Prime Video, a streaming service that offers a wide range of movies, TV shows, and original content. Amazon Music provides a platform for streaming and purchasing digital music, while Audible offers audiobooks and other audio content. The company's commitment to customer satisfaction and convenience is demonstrated by its membership program, Amazon Prime. Prime members receive various benefits, including free two-day shipping, access to streaming services, exclusive deals, and more.
Industry
It services, book publishers, retail, real estate and computer and electronic product manufacturing
Company size
10,000+ Employees
Headquarters location
Seattle, WA, US