1

Third Party Risk Jobs in Frederick, MD (NOW HIRING)

... third party assessors [3PAOs]) in support of FedRAMP requirements to ensure that cloud services maintain an appropriate risk * Create, track, and manage system Plans of Action and Milestones (POA&Ms)

EHS Manager

Rockville, MD · On-site

$84K - $114K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Leads OSHA inspections, insurance audits, and third-party evaluations * Represents DAVIS procedures ... Ensures compliance, risk mitigation, and legal defensibility across projects * Leadership and ...

IT Project Manager

Rockville, MD · On-site

$100K - $118K/yr

... and third-party stakeholders * Plan and facilitate kickoff, weekly status, change control ... risk remediation * Establish QA/QC and release-readiness practices; ensure deliverables, data ...

IT Project Manager

Rockville, MD · On-site

$100K - $118K/yr

... and third-party stakeholders * Plan and facilitate kickoff, weekly status, change control ... risk remediation * Establish QA/QC and release-readiness practices; ensure deliverables, data ...

Solution Architect

Gaithersburg, MD · Remote

$120K - $160K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Coordinate and support Third-Party Assessment Organization (3PAO) activities; assist with Authority ... Successful completion of a Moderate Risk background investigation and FBI fingerprinting

IT Project Manager

Rockville, MD · On-site

$100K - $118K/yr

... risk, change management, transition, and turnover plansEnsure work remains within scope and ... third-party stakeholdersPlan and facilitate kickoff, weekly status, change control, technical ...

Assistant EHS Manager

Rockville, MD · On-site

$84K - $114K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Safety PlanningandHigh-Risk Work * Reviews and approves Pre-Task Plans, Job Hazard Analyses, and ... Interfaces with OSHA, insurance carriers, and third-party auditors; may lead inspections, site ...

Assistant EHS Manager

Rockville, MD · On-site

$84K - $114K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Safety Planning and High-Risk Work * Reviews and approves Pre-Task Plans, Job Hazard Analyses, and ... Interfaces with OSHA, insurance carriers, and third-party auditors; may lead inspections, site ...

Application Architect

Rockville, MD · On-site

$120K - $165K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... third-party solutions for architectural fit and long-term supportability * Partner with business stakeholders, technology teams, information security, risk, compliance, and vendors throughout ...

Principal Analyst, Risk Monitoring

Rockville, MD · Hybrid

$112K - $211K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead risk monitoring activities for complex and elevated-risk member firms, exercising independent judgment with the support of a Risk Monitoring Director * Identify emerging and existing risks ...

Showing results 41-60

Third Party Risk information

See Frederick, MD salary details

$14

$30

$73

How much do third party risk jobs pay per hour?

As of Aug 20, 2026, the average hourly pay for third party risk in Frederick, MD is $30.16, according to ZipRecruiter salary data. Most workers in this role earn between $19.38 and $38.46 per hour, depending on experience, location, and employer.

What is third party risk?

Third Party Risk refers to the potential risks and vulnerabilities an organization faces when working with external vendors, suppliers, or service providers. These risks can include data breaches, compliance violations, operational disruptions, and reputational damage resulting from the actions or failures of third parties. Managing third party risk involves identifying, assessing, monitoring, and mitigating these risks to protect the organization’s interests and ensure regulatory compliance.

What are the key skills and qualifications needed to thrive as a third party risk professional?

To thrive as a Third Party Risk professional, you need a solid understanding of risk management principles, vendor assessment processes, and relevant regulatory frameworks, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) software, and certifications such as Certified Third Party Risk Professional (CTPRP) are common requirements. Strong analytical thinking, attention to detail, and effective communication skills help you evaluate vendors and influence stakeholders. These skills are vital for identifying, mitigating, and managing risks associated with third-party relationships to protect organizational integrity and compliance.

What are some common challenges faced in a third party risk role and how can they be managed?

Professionals in Third Party Risk often encounter challenges such as managing a large and diverse vendor portfolio, staying updated on regulatory requirements, and ensuring timely risk assessments. Navigating communication gaps between internal stakeholders and external vendors can also be demanding. These challenges are typically managed by implementing robust risk assessment frameworks, fostering cross-functional collaboration, and leveraging technology to streamline due diligence and monitoring processes. Continuous training and clear communication protocols further help in addressing these complexities and maintaining effective third-party risk management.

What is the difference between Third Party Risk vs Vendor Risk Management?

AspectThird Party RiskVendor Risk Management
FocusAssessing risks from all external entities, including vendors, partners, and contractorsEvaluating risks specifically associated with third-party vendors
CredentialsRisk management certifications, compliance knowledgeVendor management certifications, procurement experience
Work EnvironmentCorporate risk teams, compliance departmentsProcurement, vendor management teams
Industry UsageFinancial, healthcare, technology sectorsPrimarily in supply chain and procurement functions

Third Party Risk encompasses a broader scope, including all external entities, while Vendor Risk Management specifically focuses on vendors. Both roles require risk assessment skills and industry knowledge, but Third Party Risk roles often involve broader compliance and strategic oversight.

What are the most commonly searched types of Third Party Risk jobs in Frederick, MD?

The most popular types of Third Party Risk jobs in Frederick, MD are:

What are popular job titles related to Third Party Risk jobs in Frederick, MD?

For Third Party Risk jobs in Frederick, MD, the most frequently searched job titles are:

What job categories do people searching Third Party Risk jobs in Frederick, MD look for?

The top searched job categories for Third Party Risk jobs in Frederick, MD are:

What cities near Frederick, MD are hiring for Third Party Risk jobs?

Cities near Frederick, MD with the most Third Party Risk job openings:

Infographic showing various Third Party Risk job openings in Frederick, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $62,738 per year, or $30.2 per hour.

Information Assurance Support Analyst

Astrion

Rockville, MD • On-site

Full-time

Re-posted 19 days ago


Job description

Overview
Information Assurance Support Analyst
LOCATION: Rockville, MD
CLEARANCE: NRC Clearance
JOB STATUS: Full-Time
TRAVEL: 10% Occasional Domestic Travel
Astrion has an exciting opportunity for a Information Assurance Support Analyst for the NRC-CPSS Contract, supporting the Civilian Division.
REQUIRED QUALIFICATIONS / SKILLS
  • BA/BS or 5 years additional equivalent experience
  • 6 years IT experience, with 4 years specialized in Information Assurance
  • Secret Clearance; the ability to obtain an NRC Security Clearance; US citizenship required
  • Must hold at least one of the following certifications: CompTIA Security+, CISSP, ISACA CISA, GIAC GSEC, GIAC GSNA, GIAC GPEN, CEH, CAP, CASP+, CRISC, or CCSK

PREFERRED QUALIFICATIONS / SKILLS
  • A strong understanding of FISMA and NIST Special Publications, especially NIST SP 800-37 and NIST SP 800-53
  • Excellent written and oral communication skills; attention to detail is a must
  • Experience with vulnerability scanning tools, such as Tenable Security Center
  • Working knowledge of DISA STIGs, SCAP content/ audit files, and CIS Benchmarks
  • Understanding of cloud service models (SaaS, PaaS, IaaS) and protections as described in FedRAMP security documentation
  • Experience reviewing FedRAMP authorization packages and understanding how to ensure customer responsibilities are addressed in accordance with the shared responsibility model
  • Experience with performing technical architecture reviews of complex systems with a strong understanding of a system's authorization
  • Knowledge of major cloud platforms (Azure/ Amazon Web Services [AWS]), virtualization, networking devices (e.g., routers and switches), web services (e.g., IIS, Apache Tomcat), network security appliances (e.g., firewalls, VPNs), databases (e.g., Microsoft SQL), and intrusion prevention/ anti-malware software
  • Knowledge of system and application security threats and vulnerabilities
  • Proficiency with Microsoft Office applications
  • Ability to prioritize and complete tasks efficiently and effectively
  • Comfortable working individually and as part of a team
  • Scripting ability (e.g., PowerShell, VBA) is a plus
  • Familiarity with the use of artificial intelligence (AI) tools such as chat technologies to enhance personal productivity

RESPONSIBILITIES
  • Work closely with all levels of personnel, including system administrators, Information System Security Officers (ISSOs), and Authorizing Official (AO), to support FISMA systems through the Security Assessment & Authorization (SA&A)
  • Assess the confidentiality, integrity, and availability impact levels of information stored, possessed, and transmitted by systems to determine the FIPS 199 security categorization
  • Develop and maintain system security documentation throughout all phases of the NIST Risk Management Framework (RMF). This includes security categorizations, digital identity risk assessments, system security plans, system policy and procedures, privacy impact assessments, contingency plans, configuration management plans, incident response plans, vulnerability assessment reports, deviation requests, and any other documents necessary to support systems' authorization and continuous monitoring
  • Analyze risks identified during security control assessments and continuous monitoring activities in accordance with NIST SP 800-30. This includes making a determination regarding the likelihood and impact of the risk being exploited, along with a supporting rationale, and providing recommendations for mitigation/remediation
  • Perform and document the results of vulnerability scans and configuration compliance checks against configuration standards such as DISA STIGs and CIS Benchmarks
  • Analyze FedRAMP security packages to document and assess customer responsibility for cloud-based
  • Assist in the review of monthly continuous monitoring deliverables produced by Cloud Service Providers (CSPs) and annual assessments (produced by third party assessors [3PAOs]) in support of FedRAMP requirements to ensure that cloud services maintain an appropriate risk
  • Create, track, and manage system Plans of Action and Milestones (POA&Ms)
  • Attend project meetings and collaborate with stakeholders to ensure security is addressed throughout the entire system lifecycle

#CJ