1

Third Party Risk Manager Jobs in Worcester, MA (NOW HIRING)

Senior Security Engineer

Framingham, MA ยท Hybrid

$85K - $115K/yr

Working closely with IT leadership and HealthDrive's Managed Security Service Provider (MSSP), the engineer also manages the third-party risk process from end to end. This is primarily a technical ...

Cybersecurity Manager

Smithfield, RI ยท On-site

$100K - $120K/yr

... risk reviews across infrastructure, software environments, data pathways, and third-party services ... โ€ข Manage day-to-day AI governance activities by reviewing internal and external AI usage ...

New

Category Risk & Insight Manager

Waltham, MA ยท Hybrid

$148K - $174K/yr

So, join us as a Category Risk & Insight Manager and find your superpower. About the Role Reporting ... Hands on experience with Third Party Risk and market intelligence tools * Practical exposure to AI ...

Category Risk & Insight Manager

Waltham, MA ยท On-site

$148K - $174K/yr

So, join us as a Category Risk & Insight Manager and find your superpower. About the Role Reporting ... Hands on experience with Third Party Risk and market intelligence tools * Practical exposure to AI ...

Category Risk & Insight Manager

Waltham, MA ยท On-site

$148K - $174K/yr

So, join us as a Category Risk & Insight Manager and find your superpower. About the Role Reporting ... Hands on experience with Third Party Risk and market intelligence tools * Practical exposure to AI ...

Compliance Risk Analyst

Marlborough, MA ยท On-site

$70K - $91K/yr

Senior Technology Risk & Compliance Analyst (Emerging Technologies) Role Overview We are seeking a ... Manage the enterprise inventory of systems, models, and third-party tools. Operational Enablement ...

next page

Showing results 1-20

Third Party Risk Manager information

See Worcester, MA salary details

$51.4K

$111.3K

$169.6K

How much do third party risk manager jobs pay per year?

As of Jul 27, 2026, the average yearly pay for third party risk manager in Worcester, MA is $111,313.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,800.00 and $128,700.00 per year, depending on experience, location, and employer.

What is the difference between Third Party Risk Manager vs Vendor Risk Analyst?

AspectThird Party Risk ManagerVendor Risk Analyst
CredentialsCertifications like CRISC, CTPRP often preferredCertifications such as CRISC, CTPRP common
Work EnvironmentOversees multiple vendors and third-party relationships at strategic levelFocuses on assessing specific vendor risks and compliance
Employer & Industry UsageUsed in finance, healthcare, and large corporations managing third-party risksCommon in IT, finance, and procurement departments
Search & Comparison IntentOften compared for broader risk management rolesCompared for detailed vendor risk assessments

The Third Party Risk Manager oversees the overall risk associated with third-party vendors, focusing on strategic risk mitigation. The Vendor Risk Analyst concentrates on evaluating individual vendors' risks and compliance. While both roles require similar certifications and work in related environments, the Risk Manager has a broader scope, whereas the Analyst specializes in detailed assessments.

What are the key skills and qualifications needed to thrive as a Third Party Risk Manager, and why are they important?

To thrive as a Third Party Risk Manager, you need a strong background in risk assessment, vendor management, and regulatory compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like GRC (Governance, Risk, and Compliance) platforms, and relevant certifications such as CTPRP (Certified Third Party Risk Professional) are highly beneficial. Excellent communication, analytical thinking, and stakeholder management skills set top performers apart in this role. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational assets and ensure regulatory compliance.

What is a Third Party Risk Manager?

A Third Party Risk Manager is a professional responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, or partners. Their main job is to ensure that third-party relationships do not expose the company to undue financial, operational, regulatory, or reputational risk. This includes evaluating vendor security practices, monitoring compliance with contracts and regulations, and developing risk management policies. Third Party Risk Managers often collaborate with legal, procurement, and IT teams to safeguard the organization's interests. Their work is crucial in today's interconnected business environment, where companies increasingly rely on third-party services and products.

How does a Third Party Risk Manager typically collaborate with other departments to manage vendor risks?

A Third Party Risk Manager works closely with teams such as procurement, legal, IT security, and compliance to assess and monitor the risks associated with external vendors. They coordinate with these departments to perform due diligence, review contracts, and establish ongoing monitoring processes. Regular cross-functional meetings and clear communication channels are essential, as the role often requires aligning risk management strategies with organizational objectives and ensuring that vendor-related risks are identified and mitigated promptly.
What cities near Worcester, MA are hiring for Third Party Risk Manager jobs? Cities near Worcester, MA with the most Third Party Risk Manager job openings:
Infographic showing various Third Party Risk Manager job openings in Worcester, MA as of July 2026, with employment types broken down into 80% Full Time, 18% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $111,313 per year, or $53.5 per hour.
Senior Security Engineer

Senior Security Engineer

Healthdrive Corporation

Framingham, MA โ€ข Hybrid

$85K - $115K/yr

Full-time

Posted 21 days ago


Job description

Overview

About HealthDrive:

HealthDrive delivers on-site healthcare services to residents of long-term care facilities, offering a comprehensive suite of specialties including primary care, behavioral health, dentistry, optometry, podiatry, and audiology. Our mission is to improve the quality of life for patients through compassionate and consistent care, while supporting our partners with reliable, integrated healthcare solutions tailored to the unique needs of senior populations.

About the Role:

The Senior Security Engineer is a hands-on, implementation-focused role responsible forย protectingย HealthDrive's sensitive patient data and strengthening security across on-premises and Microsoft Azure environments.ย Thisย engineer builds, configures, and operates security controls, includingย firewalls, endpoint and email protection, cloud security, and vulnerability management, while leadingย incident detection, investigation, and response. Working closely with IT leadership and HealthDrive's Managed Security Service Provider (MSSP), the engineer alsoย manages theย third-party risk processย fromย end to end. This isย primarilyย a technical build-and-operate role, not a policy or oversight position.

Work Environment:

Based at HealthDrive's Framingham, MA office (off Route 9, near Routes 90 and 495) on a hybrid schedule.ย 

Compensation Range:

$85,000 to $115,000 / experience dependent

#INDHDCORPREC

Responsibilities

Security infrastructure management:

Build, configure, deploy, and maintain security infrastructure - firewalls, MDM, identity platforms, email security, and cloud - using Fortinet (preferred), Microsoft Active Directory, Microsoft 365, and Azure; hands-on experience with comparable firewalls such as Palo Alto is transferable.ย 

Cloud security:

Implementย and manage cloud security controls in Microsoft Azure, focusing on identity and access management, network security, and data protection.ย 

Secure network & server design:

Partnerย hands-on with infrastructure teams to design and harden secure network and server configurations, including firewall, VPN, and access controls.ย 

Endpoint & data protection:

Ownย and maintain the policy configuration for HealthDrive's Proofpoint platforms - Email Security, Email DLP, Endpoint DLP, and Data Security Posture Management (DSPM)ย tuning detection and prevention rules, triaging alerts, and refining controls to protect against phishing, malware, and data exfiltration.ย 

Vulnerability management:ย ย 

Conduct regular vulnerability assessments using tools such as SecureWorks or Qualys, and coordinate remediation efforts with IT teams.ย 

Incident response:

Leadย incident detection, investigation, containment, and recovery in collaboration with internal teams and externalย partners andย operationalize threat intelligence to inform detection and response priorities.ย 

Security automation:

Developย scripts in PowerShell, Python, or Bash to automate routine security tasks and improve operational efficiency.ย 

Third-party risk management:ย ย 

Own and drive HealthDrive's Third-Party Risk Management (TPRM) program end to end, including inbound and outbound security-questionnaire processes - assessing vendor and partner security posture, maintaining the vendor risk-scoring framework, responding to security assessments HealthDrive receives from partners and payers, and managing ongoing third-party risk in line with HIPAA and HealthDrive's data-protection obligations.ย 

Compliance & risk management:

Ensureย adherence to HIPAA and other regulatory requirements through policy enforcement and risk-mitigation strategies.ย 

Documentation & training:

Maintainย detailed documentation of security configurations andย procedures andย provide guidance to business and IT staff on security best practices.ย 

Security awareness training:ย 

Manage HealthDrive's security awareness training program - building and scheduling campaigns and phishing simulations, tracking completion and results, and reporting on workforce risk to ITย leadership.ย 

Collaborationย with MSSP:

Serveย as liaison with HealthDrive's Managed Security Service Provider to ensure effective threat monitoring and response.ย 

Qualifications

Must have:

  • Infrastructure-focused security engineering background, able to both set strategy and execute hands-on.ย 
  • Deep understanding of network security fundamentals (TCP/IP, DNS, routing, firewalls).ย 
  • Hands-on experience with enterprise-grade firewalls and network security tools.ย 
  • Proficiency in Microsoft Active Directory and Azure Active Directory (Microsoft Entra ID).ย 
  • Strong knowledge of Azure cloud security best practices.ย 
  • Experience with endpoint protection and data loss prevention (DLP) technologies, preferably Proofpoint tools.ย 
  • Experience leading or running third-party risk / vendor security assessment processes.ย 
  • Excellent problem-solving, communication, and collaboration skills, with the ability to work both independently and across cross-functional teams.ย 

Nice to have:ย 

  • Microsoft Intune (MDM).ย 
  • Scripting with PowerShell, Python, or Bash.ย 
  • SIEM / XDR platforms such as Microsoft Sentinel or SecureWorks; experience with comparable platforms is transferable.ย 
  • Experience working with MSSPs and vulnerability detection and response platforms.ย 
  • Knowledge of healthcare compliance standards (HIPAA, HITECH).ย 
  • Experience managingย securityย awareness training.ย 
  • Experience with Okta MFAย configuration.

Education & Qualifications:

  • Bachelor's degree in Cybersecurity, Computer Science, or a related field.ย 
  • Approximately 10+ years of security engineering experience, with demonstrated depth in infrastructure and cloud security.ย 

Certifications & Licenses:

(Preferred)ย CISSP; or at least one relevant security certification, such as Microsoft Certified: Azure Security Engineer Associate (AZ-500), CompTIA Security+, CISM, CCSP, or HCISPP

Core Competencies:

  • Communicationย 
  • Cooperation and Team workingย 
  • Adaptabilityย 
  • Expertise and Professionalismย 
  • Problem Solving / Analysisย 
Employment Type: FULL_TIME