1

Third Party Risk Manager Jobs in Spring, TX (NOW HIRING)

Cyber Security Manager

Houston, TX ยท On-site

$93.30K - $126K/yr

Build and run the third-party risk program covering CIED device vendors, EMR integration partners ... Experience managing or running an MDR or SOC function * Proven incident response leadership ...

Cyber Security Manager

Houston, TX

$106K - $143.20K/yr

Build and run the third-party risk program covering CIED device vendors, EMR integration partners ... Experience managing or running an MDR or SOC function * Proven incident response leadership ...

... third party contractors * Assist with the department risk management budget to ensure accuracy and allocation of expenditures, in areas of responsibility * Assist with financial and loss data summary ...

... third party contractors * Assist with the department risk management budget to ensure accuracy and allocation of expenditures, in areas of responsibility * Assist with financial and loss data summary ...

Review and approve third party invoices and forward for payment * Ensure that surveys are completed ... Professional designations such as Associate in Risk Management (ARM), Certified Protection ...

Continuously evaluate and enhance the company's compliance programs for export controls, trade sanctions, and third-party risk management. Primary Responsibilities As a Global Trade Compliance ...

Continuously evaluate and enhance the company's compliance programs for export controls, trade sanctions, and third-party risk management. Primary Responsibilities As a Global Trade Compliance ...

Monitor and report daily price exposure, mark-to-market and P&L to management. * Monitor market ... NO THIRD-PARTY CANDIDATES ACCEPTED

next page

Showing results 1-20

Third Party Risk Manager information

See Spring, TX salary details

$45.8K

$99.3K

$151.3K

How much do third party risk manager jobs pay per year?

As of Jun 1, 2026, the average yearly pay for third party risk manager in Spring, TX is $99,273.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,100.00 and $114,800.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.

What is a Third Party Risk Manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are popular job titles related to Third Party Risk Manager jobs in Spring, TX? For Third Party Risk Manager jobs in Spring, TX, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Manager jobs in Spring, TX look for? The top searched job categories for Third Party Risk Manager jobs in Spring, TX are:
What cities near Spring, TX are hiring for Third Party Risk Manager jobs? Cities near Spring, TX with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Spring, TX as of May 2026, with employment types broken down into 86% Full Time, 12% Part Time, and 2% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $99,273 per year, or $47.7 per hour.
Cyber Security Manager

Cyber Security Manager

OCTAGOS HEALTH, INC.

Houston, TX โ€ข On-site

$93.30K - $126K/yr

Full-time

Posted 9 days ago


Job description

About Octagos Health

Octagos is modernizing remote cardiac monitoring with AI-powered automation, seamless EHR integrations, and accuracy proven in high-volume, real-world clinics. Atlas AIโ„ข triages cardiac device transmissions to filter nonactionable alerts and highlights the events that need true clinical attention. Through our Two-Brain Approachโ„ข โ€“ combining Atlas AIโ„ข with IBHRE-certified oversight โ€“ Octagos delivers 99%+ accuracy, sensitivity, and specificity for near-perfect clinical performance. With fast bi-directional EHR integrations, and flexible, cost-effective implementation, Octagos helps clinics scale care efficiently without compromise. Recognized by TIME and Statista as one of the Worldโ€™s Top HealthTech Companies 2025, Octagos is redefining how cardiac care is delivered.

The Role

We are hiring a Cyber Security Manager to lead and operationalize the security program across Octagos. This role owns the full lifecycle: governance, risk, compliance, application security, cloud security, vendor risk, incident response, and customer-facing security assurance. The role partners closely with Engineering, IT, Product, Compliance, and Customer Success.

This is a hands-on leadership role. You will set strategy, build the program, and execute against it. You will own the MDR partner relationship, drive the next SOC 2 Type II and HITRUST cycles, and serve as the security voice in architecture, vendor, and customer conversations as we scale toward Series C.

This is an in-office position located in Houston, Texas.

Key Responsibilities

Governance, Risk, and Compliance

  • Own the HIPAA, SOC 2 Type II, and HITRUST roadmap and audit execution
  • Maintain and evolve security policies, standards, and procedures aligned to NIST CSF and HITRUST CSF
  • Manage the enterprise risk register and quarterly executive risk review
  • Drive completion of customer security questionnaires, BAAs, and trust portal artifacts

Cloud and Application Security

  • Own Azure security posture across all subscriptions: Defender for Cloud, Sentinel, Entra ID, Key Vault, Private Link, and Azure Policy
  • Partner with Engineering to embed secure SDLC practices: threat modeling, SAST, DAST, SCA, dependency scanning, and PR security gates
  • Define and enforce identity, secrets management, encryption, key rotation, and network segmentation standards
  • Lead vulnerability management across cloud, application, container, endpoint, and third-party library layers

Detection, Response, and Operations

  • Manage the MDR provider relationship and tune detection content for our environment
  • Own the incident response plan, tabletop exercises, and breach response playbooks
  • Lead investigations end to end: evidence preservation, root cause, customer notification, and any regulatory reporting under the HIPAA Breach Notification Rule
  • Operate the security monitoring stack, alert routing, on-call rotation, and SLAs

Third-Party and Customer-Facing Security

  • Build and run the third-party risk program covering CIED device vendors, EMR integration partners, and SaaS suppliers
  • Review architecture and contracts for new integrations: data flow, PHI handling, authentication, and security controls
  • Own the customer trust portal, security questionnaires, and pre-sales security support
  • RepresentOctagossecurity in customer, prospect, auditor, and partner conversations

Workforce Security and Awareness

  • Run security awareness training, phishing simulations, and role-based training for engineering and clinical operations staff
  • Define onboarding and offboarding controls for workforce access to PHI systems
  • Partner with IT on endpoint security, MDM, and identity lifecycle management

Leadership and Org Building

  • Build ahigh-performingsecurity team, including a Security Engineer and a GRC Analyst
  • Represent security in board, customer, and investor conversations
  • Partner with the VP of Engineering on Series C security and compliance readiness

Required Qualifications

  • 8+ years in cyber security with 3+ years inleadershipor program management role
  • Direct experienceoperatinga security program in a HIPAA-regulated environment
  • Hands-on ownership of at least one full SOC 2 Type II audit cycle
  • Deep working knowledge of Azure security services: Defender for Cloud, Sentinel, Entra ID, Key Vault, Private Link, Azure Policy
  • Strong application security background covering OWASP Top 10, secure SDLC, and modern web and API security patterns
  • Experience managing or running an MDR or SOC function
  • Proven incident response leadership, including at least one significant production incident managed end to end
  • Excellent written and verbal communication, with the ability to brief executives, customers, and auditors

Preferred Qualifications

  • Healthcare SaaS, medicaldevices, or remote patient monitoring industry experience
  • CISSP, CISM, CCSP, HCISPP, or equivalent certification
  • Experience driving a HITRUST CSF r2 certification
  • Familiarity with Auth0, .NET, Angular, and SQL Server security hardening
  • Working knowledge of FDA cybersecurity guidance for connected medical devices and SaMD
  • Prior experience scaling a security program through a Series B to Series C inflection

What We Offer

  • High-impact role with direct executive and board visibility
  • Mission-driven work with measurable patient outcomes
  • Modern Azure-native stack and a Claude-first engineering culture
  • Competitive base, equity, and comprehensive benefits
  • Headquarteredin theHouston,Texas Medical ecosystem with deep clinical partnerships