1

Third Party Risk Manager Jobs in Washington, DC (NOW HIRING)

Global Risk Financing Manager

Mclean, VA

  • Medical

  • Dental

  • Retirement

  • PTO

An MBA in Risk Management or Business (Finance) is a plus. * 5+ years with increasing ... as 3rd party contract review. Work experience, which involved frequently visiting local plants ...

Global Risk Financing Manager

Mclean, VA ยท On-site

  • Medical

  • Dental

  • Retirement

  • PTO

An MBA in Risk Management or Business (Finance) is a plus. * 5+ years with increasing ... as 3rd party contract review. Work experience, which involved frequently visiting local plants ...

Governance, Risk and Compliance Analyst

Reston, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Third-Party Risk Management * Perform security reviews of vendors, suppliers, and third-party service providers. * Track vendor assessment findings and remediation activities. * Support ongoing ...

Communicate enterprise-wide risk management issues and emerging risks and monitor effective and ... Attend Seller/Servicer Forum and Third-Party Risk oversight meetings * Monitor Transfers of ...

Communicate enterprise-wide risk management issues and emerging risks and monitor effective and ... Attend Seller/Servicer Forum and Third-Party Risk oversight meetings * Monitor Transfers of ...

HR Process Specialist

Vienna, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Stay updated on industry trends and regulatory changes related to third-party risk management that may impact HR and industry best practices in vendor management. * Assist in the integration of ...

HR Process Specialist

Vienna, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Stay updated on industry trends and regulatory changes related to third-party risk management that may impact HR and industry best practices in vendor management. * Assist in the integration of ...

HR Process Specialist

Vienna, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Stay updated on industry trends and regulatory changes related to third-party risk management that may impact HR and industry best practices in vendor management. * Assist in the integration of ...

HR Process Specialist

Vienna, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Stay updated on industry trends and regulatory changes related to third-party risk management that may impact HR and industry best practices in vendor management. * Assist in the integration of ...

HR Process Specialist

Vienna, VA ยท On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Stay updated on industry trends and regulatory changes related to third-party risk management that may impact HR and industry best practices in vendor management. * Assist in the integration of ...

Showing results 41-60

Third Party Risk Manager information

See Washington, DC salary details

$58.3K

$126.3K

$192.5K

How much do third party risk manager jobs pay per year?

As of Aug 13, 2026, the average yearly pay for third party risk manager in Washington, DC is $126,301.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,900.00 and $146,100.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a third party risk manager?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a third party risk manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a third party risk manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
Infographic showing various Third Party Risk Manager job openings in Washington, DC as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 12% Part Time, and 2% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $126,301 per year, or $60.7 per hour.

Director, Cybersecurity and IT Risk Management

Socket.dev

Vienna, VA โ€ข On-site

$170 - $180/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 6 days ago


Job description

About SourceAmerica

SourceAmerica is a mission-driven nonprofit and AbilityOne-authorized enterprise that helps create employment opportunities for people with disabilities by building strong partnerships with the federal government and a nationwide network of nonprofit agencies. We connect federal customers with high-quality products and services while strengthening the capabilities of nonprofit agencies and the people they employ. More information can be found at www.SourceAmerica.org/who-we-are

About the Role

We are seeking a Director, Cybersecurity and IT Risk Management to provide strategic leadership and operational oversight for SourceAmericaโ€™s cybersecurity, technology risk management, security governance, incident response, third-party risk management, security awareness, and compliance readiness programs. This leader will serve as a trusted advisor to IT leadership, executive leadership, business stakeholders, governance bodies, and partners on cybersecurity risk, regulatory and contractual obligations, cyber resilience, and secure technology enablement.

This is a high-impact leadership opportunity for a cybersecurity executive who can balance mission, risk, compliance, and business enablement in a federal-contracting and nonprofit environment. The Director will help protect SourceAmericaโ€™s information assets, systems, mission, and federal contracting obligations while also supporting nonprofit agency partners where federal contracts, Controlled Unclassified Information, or technology risk obligations apply.

SourceAmerica offers both a hybrid and remote work model. **Due to the requirements of this position, the ideal candidate would live within 30 commuting miles or less of the SourceAmerica's National Office in Vienna, VA and work 2-3 days per week in the office.

What Youโ€™ll Do
  • Lead SourceAmericaโ€™s cybersecurity, technology risk management, and security governance functions.
  • Develop and execute the enterprise cybersecurity strategy and roadmap aligned to organizational goals, federal contractor obligations, AbilityOne operational responsibilities, and risk tolerance.
  • Own the cybersecurity risk management framework, including risk assessment methodology, risk register, mitigation tracking, accepted risk documentation, and executive-level reporting.
  • Lead readiness and ongoing compliance activities for CMMC, NIST SP 800-171, Controlled Unclassified Information protection requirements, GSA CUI handling requirements, and other applicable federal, contractual, and regulatory security obligations.
  • Oversee security operations, including threat monitoring, vulnerability management, incident response, threat mitigation, control validation, and user awareness training.
  • Lead cybersecurity incident response activities, including investigation, containment, recovery, executive communication, lessons learned, and remediation tracking.
  • Build and lead cybersecurity components of third-party risk management, including vendor risk tiering, due diligence, contract security requirements, cloud/SaaS assessments, ongoing monitoring, and remediation tracking.
  • Provide security oversight for enterprise systems, cloud platforms, data platforms, artificial intelligence solutions, automation, and major technology initiatives.
  • Support AI governance by assessing cybersecurity, privacy, data protection, vendor, and operational risks associated with approved and emerging AI tools.
  • Present cybersecurity metrics, risk posture, control effectiveness, incident trends, vulnerability remediation, compliance readiness, and security program maturity to inform executive decision-making.
Salary Range

The salary for this position falls in a range between $170,000 - $180,000 depending on your experience and geographic location in the United States.

What You Bring
  • Bachelorโ€™s degree required; masterโ€™s degree, MBA, or relevant advanced training preferred.
  • 15+ years of relevant cybersecurity, technology risk, security governance, or compliance experience.
  • 10+ years of management experience, with demonstrated ability to lead staff, vendors, managed security service providers, and cross-functional partners.
  • Current CISSP, CISM, CRISC, CISA, CGRC, or equivalent cybersecurity, risk, or compliance certification.
  • Strong knowledge of cybersecurity technologies, security operations, technology risk management, security governance, and regulatory compliance practices.
  • Working knowledge of NIST SP 800-171, CMMC, NIST Cybersecurity Framework, Controlled Unclassified Information requirements, and federal contractor cybersecurity expectations.
  • Experience interpreting federal contract cybersecurity and CUI requirements and translating them into practical guidance for business, technology, vendor, and partner audiences.
  • Experience communicating cybersecurity risk, compliance readiness, incident response matters, and mitigation priorities to executive and non-technical stakeholders.
  • Ability to work independently, solve complex problems under time pressure, build relationships across a national organization, and support a mission-driven culture.
Preferred Qualifications
  • Experience leading cybersecurity programs within federal contractors, government organizations, regulated industries, or mission-driven nonprofit organizations.
  • Experience supporting CMMC certification efforts, NIST SP 800-171 compliance programs, and CUI protection initiatives.
  • Experience supporting cloud-first and SaaS-centric environments, including Microsoft 365, Azure, Dynamics 365, and related Microsoft security technologies.
  • Experience leading third-party risk management programs, vendor security assessments, contract security reviews, and supply chain risk management initiatives.
  • Experience developing cybersecurity strategy, governance structures, executive reporting, risk registers, security metrics, and policy frameworks.
  • Experience presenting cybersecurity and technology risk matters to executive leadership, governance councils, audit committees, or boards.
Work Environment

Our organization offers both a hybrid work modelโ€”where employees work in our office two to three days per week and work from home the balance of the workweekโ€”as well as a fully remote work model, depending on the job requirements. *Due to the requirements of this position, the ideal candidate would live within 30 commuting miles or less of the SourceAmerica's National Office in Vienna, VA and work 2-3 days per week in the office.

Employee Benefits

We offer a comprehensive employee benefits package that includes paid holidays, vacation time, sick leave, medical, dental, and vision insurance, a solid retirement plan, and more!

Accessibility Support

Weโ€™re committed to offering reasonable accommodation to job applicants with disabilities. If you need assistance or accommodation due to disability, please contact us at Human Resources (888) 411-8424 or hr@sourceamerica.org.

Equal Opportunity Employment

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. View our EEO Policy https://www.sourceamerica.org/sites/default/files/2022-01/eeo-policy.pdf.

#J-18808-Ljbffr