... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...
Governance, Risk, and Compliance Officer
Washington, DC · On-site
$175K - $190K/yr
Vendor & Third-Party Risk Management • Oversee vendor relationships to ensure compliance with security, data handling, and risk requirements. • Manage third-party risk assessment processes and ...
Governance, Risk, and Compliance Officer
Washington, DC · On-site
$175K - $190K/yr
Vendor & Third-Party Risk Management • Oversee vendor relationships to ensure compliance with security, data handling, and risk requirements. • Manage third-party risk assessment processes and ...
Governance, Risk, and Compliance Officer
Washington, DC · On-site
$175K - $190K/yr
Vendor & Third-Party Risk Management • Oversee vendor relationships to ensure compliance with security, data handling, and risk requirements. • Manage third-party risk assessment processes and ...
Quick apply
Governance, Risk, and Compliance Officer
Washington, DC · On-site
$175K - $190K/yr
Vendor & Third-Party Risk Management • Oversee vendor relationships to ensure compliance with security, data handling, and risk requirements. • Manage third-party risk assessment processes and ...
Vendor & Third-Party Risk Management • Oversee vendor relationships to ensure compliance with security, data handling, and risk requirements. • Manage third-party risk assessment processes and ...
Vendor & Third-Party Risk Management • Oversee vendor relationships to ensure compliance with security, data handling, and risk requirements. • Manage third-party risk assessment processes and ...
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
Sr. Cyber Supply Chain Risk Management Analyst with Security Clearance
$104.60K - $134.90K/yr
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
Sr. Cyber Supply Chain Risk Management Analyst with Security Clearance
$104.60K - $134.90K/yr
Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as ... Familiarity with C-SCRM/Third-Party Risk Management tools such as Exiger and eMAS * Security ...
Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility. * Act as a subject matter expert, providing guidance on risk ...
New
Quick apply
Oversee audits, certifications, third-party assessments, and vulnerability management to maintain compliance and operational credibility. * Act as a subject matter expert, providing guidance on risk ...
New
Support third-party risk management and vendor security assessments * Prepare and present regular reports on risk management activities, compliance status, and remediation efforts to management.
Support third-party risk management and vendor security assessments * Prepare and present regular reports on risk management activities, compliance status, and remediation efforts to management.
Familiarity with supply chain operations, procurement, logistics, or third-party risk management. * Exposure to data tools such as Excel, SQL, or Python for data analysis (working knowledge preferred ...
Familiarity with supply chain operations, procurement, logistics, or third-party risk management. * Exposure to data tools such as Excel, SQL, or Python for data analysis (working knowledge preferred ...
Specific Responsibilities for the team include Third Party Risk Management, Business Continuity, Crisis Management, Operational Risk Scenarios, Resolution Planning and responding to audits, * Ability ...
Specific Responsibilities for the team include Third Party Risk Management, Business Continuity, Crisis Management, Operational Risk Scenarios, Resolution Planning and responding to audits, * Ability ...
Specific Responsibilities for the team include Third Party Risk Management, Business Continuity, Crisis Management, Operational Risk Scenarios, Resolution Planning and responding to audits, * Ability ...
Specific Responsibilities for the team include Third Party Risk Management, Business Continuity, Crisis Management, Operational Risk Scenarios, Resolution Planning and responding to audits, * Ability ...
Familiarity with third-party risk management, supply chain risk, or compliance technology preferred. * Hands-on experience with Customer Success platforms like Gainsight or Planhat. * Exceptional ...
Familiarity with third-party risk management, supply chain risk, or compliance technology preferred. * Hands-on experience with Customer Success platforms like Gainsight or Planhat. * Exceptional ...
Experience with third-party risk management, vendor assessments, or SCRM programs. * Familiarity with AI/ML security risks and emerging cybersecurity trends * Strong analytical and risk assessment ...
Experience with third-party risk management, vendor assessments, or SCRM programs. * Familiarity with AI/ML security risks and emerging cybersecurity trends * Strong analytical and risk assessment ...
Principal IT Risk Management Analyst
Herndon, VA · On-site +1
... Third Party Risk Management. * 3+ yrs experience with Artificial Intelligence, Cloud Platforms, and DevSecOps. * 3+ with incident response, crisis management, and business continuity planning.
Principal IT Risk Management Analyst
Herndon, VA · On-site +1
... Third Party Risk Management. * 3+ yrs experience with Artificial Intelligence, Cloud Platforms, and DevSecOps. * 3+ with incident response, crisis management, and business continuity planning.
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
$62.64K - $89.49K/yr
... of third-party vendor security documentation, evaluating cybersecurity controls, governance practices, and risk management approaches against DoD and federal requirements. • Reviews independent ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
Fairfax, VA · On-site
$62.64K - $89.49K/yr
... of third-party vendor security documentation, evaluating cybersecurity controls, governance practices, and risk management approaches against DoD and federal requirements. • Reviews independent ...
Experience with third-party risk management, vendor assessments, or SCRM programs. * Familiarity with AI/ML security risks and emerging cybersecurity trends * Strong analytical and risk assessment ...
Quick apply
Experience with third-party risk management, vendor assessments, or SCRM programs. * Familiarity with AI/ML security risks and emerging cybersecurity trends * Strong analytical and risk assessment ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
$62.64K - $89.49K/yr
... of third-party vendor security documentation, evaluating cybersecurity controls, governance practices, and risk management approaches against DoD and federal requirements. • Reviews independent ...
Supply Chain Risk Management (SCRM) Audit Analyst (Logistics Management Analyst 2)
$62.64K - $89.49K/yr
... of third-party vendor security documentation, evaluating cybersecurity controls, governance practices, and risk management approaches against DoD and federal requirements. • Reviews independent ...
Communicate enterprise-wide risk management issues and emerging risks and monitor effective and ... Attend Seller/Servicer Forum and Third-Party Risk oversight meetings * Monitor Transfers of ...
Communicate enterprise-wide risk management issues and emerging risks and monitor effective and ... Attend Seller/Servicer Forum and Third-Party Risk oversight meetings * Monitor Transfers of ...
Work closely with other Enterprise Risk teams, including Credit, Model Risk, Compliance, and Third-Party Risk Management, to support end-to-end risk governance across credit, capital, model, and ...
Work closely with other Enterprise Risk teams, including Credit, Model Risk, Compliance, and Third-Party Risk Management, to support end-to-end risk governance across credit, capital, model, and ...
Work closely with other Enterprise Risk teams, including Credit, Model Risk, Compliance, and Third-Party Risk Management, to support end-to-end risk governance across credit, capital, model, and ...
Work closely with other Enterprise Risk teams, including Credit, Model Risk, Compliance, and Third-Party Risk Management, to support end-to-end risk governance across credit, capital, model, and ...
Third Party Risk Manager information
See Reston, VA salary details
$53.6K - $64.8K
4% of jobs
$64.8K - $76K
6% of jobs
$76K - $87.2K
11% of jobs
$91.4K is the 25th percentile. Wages below this are outliers.
$87.2K - $98.4K
11% of jobs
The median wage is $107.3K / yr.
$98.4K - $109.6K
23% of jobs
$109.6K - $120.8K
13% of jobs
$128.2K is the 75th percentile. Wages above this are outliers.
$120.8K - $132K
12% of jobs
$132K - $143.2K
8% of jobs
$143.2K - $154.4K
6% of jobs
$154.4K - $165.7K
4% of jobs
$165.7K - $176.9K
2% of jobs
$53.6K
$116.1K
$176.9K
How much do third party risk manager jobs pay per year?
What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?
How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?
What is a Third Party Risk Manager?
What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?
| Aspect | Third Party Risk Manager | Vendor Risk Analyst |
|---|---|---|
| Credentials | Certifications like CRISC, CTPRP often preferred | Certifications such as CRISC, CTPRP common |
| Work Environment | Oversees multiple vendors and third-party relationships at strategic level | Focuses on assessing specific vendor risks and compliance |
| Employer & Industry Usage | Used in finance, healthcare, and large corporations managing third-party risks | Common in IT, finance, and procurement departments |
| Search & Comparison Intent | Often compared for broader risk management roles | Compared for detailed vendor risk assessments |
The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.
Job description
The War Data Platform (WDP) is a key initiative within the U.S. Department of War's (DoW) AI-First strategy introduced in early 2026. The WDP focuses on operational warfighting data and aims to accelerate the deployment of artificial intelligence (AI) on the battlefield. The WDP extends to Unclassified, Secret, and Top Secret environments, and supports collaboration between Combatant Commands, Joint Staff directorates, Senior Executive Service leaders, and operational analysts.
• The Supply Chain Risk Management (SCRM) Lead SME serves as the senior enterprise authority for software and vendor supply chain risk governance across the WDP Core Integration program, directing the full lifecycle of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements, and federal cybersecurity mandates. In this role, the specialist integrates automated supply chain risk tooling, Software Bill of Materials governance, vendor security assessment programs, and threat intelligence monitoring to reduce WDP exposure to supply chain-based attacks and sustain authoritative, audit-ready risk transparency for Authorizing Officials, program leadership, and Government oversight personnel.
• Leads enterprise Supply Chain Risk Management activities supporting Department of War information systems across unclassified and classified environments.
• Designs and executes supply chain risk governance frameworks addressing third-party vendors, commercial software, open-source components, and external service providers throughout the system lifecycle.
• Directs vendor security assessments evaluating cybersecurity posture, access controls, data handling practices, and compliance with federal and DoW requirements.
• Oversees software supply chain reviews including component provenance analysis, dependency mapping, and Software Bill of Materials validation to identify exposure to compromised or high-risk suppliers.
• Coordinates closely with contracting officers, acquisition teams, legal advisors, and system owners to integrate security requirements into procurement actions, vendor onboarding, and contract modifications.
• Maintains risk registers documenting third-party threats, mitigation strategies, residual risk, and acceptance decisions supporting Risk Management Framework activities.
• Provides advisory support to Authorizing Officials, Senior Information Security Officers, and program leadership on supply chain risk posture and emerging threat vectors.
• Monitors threat intelligence, Government advisories, and industry reporting related to supply chain compromise to inform proactive mitigation actions.
• Produces supply chain risk assessments, vendor security reports, and executive briefings supporting authorization decisions and continuous monitoring.
• Drives consistent risk transparency, lifecycle accountability, and mission resilience by reducing exposure to supply chain-based attacks and strengthening trust in system dependencies.
• Performs other duties as assigned.
• Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
• 15 or more years of progressive experience in cybersecurity, with demonstrated specialization in Supply Chain Risk Management, vendor risk governance, or software assurance programs supporting large-scale federal or defense information systems.
• Active DoW/DoD IAM Level I baseline certification, satisfied by one of the following: CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• Demonstrated experience designing and operating enterprise SCRM governance frameworks that address third-party software components - including COTS, GOTS, and open-source AI technologies - through automated vulnerability detection and scanning, component provenance analysis, and transitive dependency mapping across the full system development lifecycle.
• Proven ability to create, maintain, and govern Software Bill of Materials documentation for complex software platforms, including management of SBOM artifacts across 150 or more systems with recurring authorization obligations and integration into automated ingest-time scanning pipelines.
• Experience coordinating SCRM activities with contracting officers, acquisition teams, legal advisors, and system owners to embed supply chain security requirements into procurement actions, vendor onboarding agreements, and contract modification packages in compliance with DFARS 252.204-7020, NIST SP 800-171, and applicable DoW acquisition policy.
• Demonstrated experience supporting Risk Management Framework authorization activities, including generation and maintenance of supply chain risk artifacts in eMASS or Xacta, management of Plan of Action and Milestone remediation activities, and preparation of Body of Evidence packages supporting formal Government risk adjudication and audit defense.
• Proven ability to develop and present supply chain risk assessments, vendor security evaluation reports, and executive briefings to Authorizing Officials, Senior Information Security Officers, and program leadership audiences in support of authorization decisions and continuous monitoring obligations.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).