1

Third Party Risk Jobs in Frederick, MD (NOW HIRING)

... FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling ...

Organize and manage RFI and Value Engineering logs, and Risk logs. * Document meetings with ... Manage RFPs for subcontractors and third-party engineering scopes, including bid leveling and scope ...

Project Manager (IPT)

Rockville, MD · On-site

$115K - $140K/yr

Organize and manage RFI and Value Engineering logs, and Risk logs. * Document meetings with ... Manage RFPs for subcontractors and third-party engineering scopes, including bid leveling and scope ...

The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and ...

The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and ...

The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and ...

The Cybersecurity Risk Manager will work directly with the Cybersecurity Program Manager and the agency's CIO and CISO in cybersecurity tasks such as information security policy development and ...

next page

Showing results 1-20

Third Party Risk information

See Frederick, MD salary details

$14

$30

$73

How much do third party risk jobs pay per hour?

As of Jul 27, 2026, the average hourly pay for third party risk in Frederick, MD is $30.16, according to ZipRecruiter salary data. Most workers in this role earn between $19.38 and $38.46 per hour, depending on experience, location, and employer.

What are some common challenges faced in a Third Party Risk role and how can they be managed?

Professionals in Third Party Risk often encounter challenges such as managing a large and diverse vendor portfolio, staying updated on regulatory requirements, and ensuring timely risk assessments. Navigating communication gaps between internal stakeholders and external vendors can also be demanding. These challenges are typically managed by implementing robust risk assessment frameworks, fostering cross-functional collaboration, and leveraging technology to streamline due diligence and monitoring processes. Continuous training and clear communication protocols further help in addressing these complexities and maintaining effective third-party risk management.

What is the difference between Third Party Risk vs Vendor Risk Management?

AspectThird Party RiskVendor Risk Management
FocusAssessing risks from all external entities, including vendors, partners, and contractorsEvaluating risks specifically associated with third-party vendors
CredentialsRisk management certifications, compliance knowledgeVendor management certifications, procurement experience
Work EnvironmentCorporate risk teams, compliance departmentsProcurement, vendor management teams
Industry UsageFinancial, healthcare, technology sectorsPrimarily in supply chain and procurement functions

Third Party Risk encompasses a broader scope, including all external entities, while Vendor Risk Management specifically focuses on vendors. Both roles require risk assessment skills and industry knowledge, but Third Party Risk roles often involve broader compliance and strategic oversight.

What are the key skills and qualifications needed to thrive as a Third Party Risk professional, and why are they important?

To thrive as a Third Party Risk professional, you need a solid understanding of risk management principles, vendor assessment processes, and relevant regulatory frameworks, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) software, and certifications such as Certified Third Party Risk Professional (CTPRP) are common requirements. Strong analytical thinking, attention to detail, and effective communication skills help you evaluate vendors and influence stakeholders. These skills are vital for identifying, mitigating, and managing risks associated with third-party relationships to protect organizational integrity and compliance.

What is Third Party Risk?

Third Party Risk refers to the potential risks and vulnerabilities an organization faces when working with external vendors, suppliers, or service providers. These risks can include data breaches, compliance violations, operational disruptions, and reputational damage resulting from the actions or failures of third parties. Managing third party risk involves identifying, assessing, monitoring, and mitigating these risks to protect the organization’s interests and ensure regulatory compliance.
What are the most commonly searched types of Third Party Risk jobs in Frederick, MD? The most popular types of Third Party Risk jobs in Frederick, MD are:
What are popular job titles related to Third Party Risk jobs in Frederick, MD? For Third Party Risk jobs in Frederick, MD, the most frequently searched job titles are:
What job categories do people searching Third Party Risk jobs in Frederick, MD look for? The top searched job categories for Third Party Risk jobs in Frederick, MD are:
What cities near Frederick, MD are hiring for Third Party Risk jobs? Cities near Frederick, MD with the most Third Party Risk job openings:
Infographic showing various Third Party Risk job openings in Frederick, MD as of July 2026, with employment types broken down into 1% As Needed, 77% Full Time, 20% Part Time, and 2% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $62,738 per year, or $30.2 per hour.
FY27: IT Systems Engineer, Information Security and Compliance, Dept Infrastructure/Operations, 8...

FY27: IT Systems Engineer, Information Security and Compliance, Dept Infrastructure/Operations, 8...

Montgomery County Public Schools

Rockville, MD

Full-time

Posted 3 days ago


Montgomery County Public Schools (Virginia) rating

7.3

Company rating: 7.3 out of 10

Based on 5 frontline employees who took The Breakroom Quiz

212th of 616 rated elementary and secondary schools


Job description

Summary Description:
Under direction of the Director of the Department of Cybersecurity and Technology Infrastructure, coordinates, designs, and maintains system-wide information security and compliance initiatives; safeguards enterprise systems and data by defining access privileges, control structures, and resources, as determined by best practices, industry standards, and stakeholder needs; identifies and mitigates system vulnerabilities, violations, and inefficiencies through routine audits; provides status updates on system performance through multiple means; acts on privacy breaches and malware threats. Executes and supports Risk Management Framework (RMF) activities and ensures compliance with Maryland Department of IT processes and documentation standards. Supports enterprise architecture governance by maintaining architecture artifacts, system documentation, and technical configuration diagrams. Lead engineer on network Disaster Recovery solutions, reviewing vendor security reports, and cybersecurity strategies. Effectively communicates with staff and stakeholders, including senior leadership.Physical Demands: Position is required to work at computer workstations for sustained periods of time. Special Requirements: Ability to work extended hours, especially during peak periods and when urgent work requirements exist.

Knowledge Skills Abilities:
Thorough knowledge and experience with risk management processes, cybersecurity and privacy policies and procedures, vulnerability and threat management, vulnerability assessment tools and techniques, network security principles and practices. Ability to identify and mitigate network vulnerabilities, as well as communicate best practices to avoid security flaws. Thorough knowledge of disaster recovery and business continuity best practices for critical systems required. Ability to construct high level and detail level network security and disaster recovery diagrams to be shared with management, other departments, and coworkers. Ability to manage multiple complex projects and tasks while paying close attention to details. Thorough knowledge of risk management framework and system risk assessments to prepare school system for state and county audits by documenting the environment and providing guidance to system stakeholders. Strong analytical and problem-solving skills. Skilled in decision making with a track record of exercising good judgment. Must be detail-oriented, highly organized, and an effective communicator. Excellent oral and written communication and human relations skills.
Education Training Experience:
Bachelor of Science or Bachelor of Arts degree in Computer Science, Information Technology systems, or related field from an accredited university required. Master?s degree preferred. Five years or more documented professional experience in technology. Proven experience in information system security operation, information system security assessment, system documentation, risk mitigation, vulnerability management, networking systems and/or network security (i.e., DNS, firewalls, proxies), agentless security, and XaaS (e.g., SaaS, IaaS, PaaS, DaaS, FaaS). Experience implementing industry standard information security frameworks, policies and procedures. Experience supporting GRC capabilities such as policy management, security awareness training, third-party risk management, and metrics and reporting. Experience in deploying various solutions to scale GRC processes including but not limited to security questionnaires, risk assessment, evidence collection, and control testing. Experience designing, reviewing, deploying, and auditing AI-powered solutions (including agents) and apply LLMs/NLP to analyze policies, audit findings, and regulatory requirements preferred. Certificate License: Professional certification in one or more of the following: CISSP, CompTIA Security , CISA preferred.


What Montgomery County Public Schools (Virginia) employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom