1

Third Party Risk Jobs in Philadelphia, PA (NOW HIRING)

This role handles vendor lifecycle administration, third-party and AI-related risk intake and assessment, contract and renewal tracking, and SaaS/portfolio data, applying the frameworks, scoring ...

Support third-party risk management activities, including vendor assessments, tracking remediation actions, collecting supporting documentation, and maintaining risk registers * Research security ...

New

Manager, IT Security, GRC

Burlington, NJ · On-site

$150K - $175K/yr

Manage third-party risk processes, including assessments and reviews. Continuously identify opportunities for improvement to enhance its effectiveness and efficiency * Escalate high-risk vendor ...

Showing results 21-40

Third Party Risk information

See Philadelphia, PA salary details

$14

$30

$74

How much do third party risk jobs pay per hour?

As of Aug 22, 2026, the average hourly pay for third party risk in Philadelphia, PA is $30.61, according to ZipRecruiter salary data. Most workers in this role earn between $19.66 and $39.04 per hour, depending on experience, location, and employer.

What is third party risk?

Third Party Risk refers to the potential risks and vulnerabilities an organization faces when working with external vendors, suppliers, or service providers. These risks can include data breaches, compliance violations, operational disruptions, and reputational damage resulting from the actions or failures of third parties. Managing third party risk involves identifying, assessing, monitoring, and mitigating these risks to protect the organization’s interests and ensure regulatory compliance.

What are the key skills and qualifications needed to thrive as a third party risk professional?

To thrive as a Third Party Risk professional, you need a solid understanding of risk management principles, vendor assessment processes, and relevant regulatory frameworks, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) software, and certifications such as Certified Third Party Risk Professional (CTPRP) are common requirements. Strong analytical thinking, attention to detail, and effective communication skills help you evaluate vendors and influence stakeholders. These skills are vital for identifying, mitigating, and managing risks associated with third-party relationships to protect organizational integrity and compliance.

What are some common challenges faced in a third party risk role and how can they be managed?

Professionals in Third Party Risk often encounter challenges such as managing a large and diverse vendor portfolio, staying updated on regulatory requirements, and ensuring timely risk assessments. Navigating communication gaps between internal stakeholders and external vendors can also be demanding. These challenges are typically managed by implementing robust risk assessment frameworks, fostering cross-functional collaboration, and leveraging technology to streamline due diligence and monitoring processes. Continuous training and clear communication protocols further help in addressing these complexities and maintaining effective third-party risk management.

What is the difference between Third Party Risk vs Vendor Risk Management?

AspectThird Party RiskVendor Risk Management
FocusAssessing risks from all external entities, including vendors, partners, and contractorsEvaluating risks specifically associated with third-party vendors
CredentialsRisk management certifications, compliance knowledgeVendor management certifications, procurement experience
Work EnvironmentCorporate risk teams, compliance departmentsProcurement, vendor management teams
Industry UsageFinancial, healthcare, technology sectorsPrimarily in supply chain and procurement functions

Third Party Risk encompasses a broader scope, including all external entities, while Vendor Risk Management specifically focuses on vendors. Both roles require risk assessment skills and industry knowledge, but Third Party Risk roles often involve broader compliance and strategic oversight.

What are the most commonly searched types of Third Party Risk jobs in Philadelphia, PA?

The most popular types of Third Party Risk jobs in Philadelphia, PA are:

What are popular job titles related to Third Party Risk jobs in Philadelphia, PA?

For Third Party Risk jobs in Philadelphia, PA, the most frequently searched job titles are:

What job categories do people searching Third Party Risk jobs in Philadelphia, PA look for?

The top searched job categories for Third Party Risk jobs in Philadelphia, PA are:

What cities near Philadelphia, PA are hiring for Third Party Risk jobs?

Cities near Philadelphia, PA with the most Third Party Risk job openings:

Infographic showing various Third Party Risk job openings in Philadelphia, PA as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution, with an average salary of $63,673 per year, or $30.6 per hour.

Manager, IT Security, Governance, Risk and Compliance

Burlington Stores

Edgewater Park, NJ • On-site

$115 - $167.50/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 2 days ago

New


Burlington rating

4.5

Company rating: 4.5 out of 10

Based on 942 frontline employees who took The Breakroom Quiz

20th of 21 rated department stores


Job description

Position OverviewThe Manager of Governance, Risk and Compliance (GRC) plays a critical mid-level leadership role within the Information Security function, responsible for translating strategy into operational execution across the GRC program. Reporting to the Director of GRC, this role provides daily oversight of analysts and leads, drives process maturity, and ensures consistent delivery of risk, audit, policy, and continuity efforts. The Manager of GRC helps shape the enterprise’s risk posture while mentoring a high-performing team and fostering cross-functional collaboration. This role requires a deep understanding of regulatory frameworks and an ability to communicate complex risk concepts in clear, actionable terms. The ideal candidate will proactively identify control gaps, coordinate effective mitigation, and ensure security efforts remain aligned with evolving business needs.A Day in the LifeEnterprise Cyber Risk Management:Lead enterprise-wide cybersecurity risk assessments across business units and IT domains.Own the accuracy and ongoing maintenance of the enterprise risk register, ensuring it is consistently updated and informed by stakeholder input.Collaborate with business and IT leaders to define and apply enterprise risk tolerance thresholds.Translate technical risk findings into actionable, business-relevant recommendations.Identify and escalate systemic risks that could materially impact operations or compliance.Monitor industry trends, threat intelligence, and regulatory changes to adjust risk posture.Deliver clear, timely risk reports and dashboards to senior leadership and governance bodies.Implement structured risk governance processes, including review cycles and escalation protocols.Implement automated GRC tools and data analytics to improve cybersecurity risk management efficiency and accuracy.Develop KPIs and KRIs for the security organization and maintain tactical and strategic dashboards to monitor risk and compliance efforts.Management & Collaboration:Oversee GRC team operations, assigning work, setting priorities, and ensuring effective collaboration.Partner with senior leadership and business stakeholders to align GRC efforts with enterprise goals.Foster a high-performing, collaborative team culture through coaching, accountability, and career development.Business Continuity and Disaster Recovery (BC/DR):Lead collaboration with IT and business leaders to identify mission-critical applications and conduct comprehensive BIA, define RTO/RPO, and recovery procedures.Develop dependency mappings for critical systems with application and infrastructure teams.Oversee documentation of recovery procedures, including technical and business continuity procedures.Lead tabletop exercises and failover/failback recovery testing with IT and business users.Identify gaps in the BC/DR program and take ownership of remediation.Ensure business continuity objectives are effectively aligned with IT capabilities to support organizational resilience during disruptions.Contribute to recovery planning efforts and facilitate coordination among IT and business teams to ensure effective response during disruptions.Vendor Risk Management:Partner with the procurement and legal teams to integrate cybersecurity function into the overall process, mitigating supply chain risks for the company.Manage third-party risk processes, including assessments and reviews. Continuously identify opportunities for improvement to enhance its effectiveness and efficiencyEscalate high-risk vendor issues to leadership and work with business stakeholders to develop and execute mitigation plans.Oversee monthly reporting on security assessments of AI vendors, provide expert analysis to leadership on AI-related risks and recommend strategic actions to resolve identified issues.Establish and manage a comprehensive set of criteria and assessment questions to support third-party risk management activities.Managed Security Service Provider (MSSP) and Third-Party Security Incidents:Own vendor incident response governance program and playbooks.Ensure vendors provide formal evidence of incident containment and remediation and ensure compliance with security requirements before closing a third incident.Consolidate third party incident and GRC-owned MSSP results into executive dashboards.Embed incident response obligations into contracts and procurement.Audit and Compliance:Oversee internal/external audit readiness and evidence collection.Ensure compliance with SOX, PCI, and privacy frameworks.Serve as audit liaison for the GRC function.Act as the primary contact for internal audit and take ownership of recreating risk and compliance assessment findings.Policy Implementation:Manage the policy lifecycle from creation through enforcement.Ensure policies align with frameworks like NIST and PCI DSS.Ensure the organization adheres to all relevant policies and standards.Cybersecurity Education:Manage company-wide security training programs.Strategically identify education and awareness needs based on enterprise-wide cybersecurity threats and business priorities.Establish metrics to evaluate the success of training initiatives, including trends in knowledge retention, behavior changes, and overall effectiveness of the security culture.Oversee continuous improvement of the training curriculum, ensuring it evolves to address new threats and compliance requirements.You'll Come With8+ years in security governance, risk, or compliance roles.Demonstrated success in leading cross-functional projects.Deep understanding of controls, audits, and frameworks.Maintain relevant certifications such as CISM, CISSP, or CISA.Communicate effectively with technical and non-technical stakeholders.Resolve conflicts and drive consensus across teams.Provided leadership and oversight for a cybersecurity team of 3+ membersMentor team members and model professional behavior.Bachelor's degree in Information Systems, Cybersecurity or related field required; Master's preferred.Target Pay Range: $115,000 – $167,500 annuallyThis position has a target starting salary range of $115,000 – $167,500 annually. Actual pay is determined by a variety of factors, including but not limited to, qualifications, education, job-related skills, relevant experience, and geographic location.#LI-JL2Come join our team. You’re going to like it here!You will enjoy competitive wages, flexible hours, and an associate discount. Burlington’s benefits package includes medical, dental and vision coverage including life and disability insurance. Full-time associates are also eligible for paid time off, paid holidays and a 401(k) plan.We are a rapidly growing brand and provide a variety of training and development opportunities so our associates can grow with us. Our teams work hard and have fun together! Burlington associates make a difference in the lives of customers, colleagues, and the communities where we live and work every day. Burlington Stores, Inc. is an equal opportunity employer committed to workplace diversityIndividual pay decisions will be based on a variety of factors, such as but not limited to, qualifications, education, job-related skills, relevant experience, and geographic location. #J-18808-Ljbffr

What Burlington employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Burlington logo

About Burlington

Sourced by ZipRecruiter

At Burlington, we embrace the many facets of diversity that strengthen our communities where we live and work every day. If you want to grow your retail career with a caring and inclusive organization, come join the Burlington Stores team as a Customer Service Supervisor, Selling Floor Supervisor or Receiving Team Supervisor!

Industry

Retail

Company size

10,000+ Employees

Headquarters location

Burlington, NJ, US