Position Overview The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third ...
Position Overview The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third ...
Position Overview The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third ...
Position Overview The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third ...
... Third Party Risk Management (TPRM) to lead a high-performing team responsible for assessing and ... Evaluate vendor security posture, compliance certifications (SOC 2, ISO 27001, etc.), and ...
... Third Party Risk Management (TPRM) to lead a high-performing team responsible for assessing and ... Evaluate vendor security posture, compliance certifications (SOC 2, ISO 27001, etc.), and ...
... Third Party Risk Management (TPRM) to lead a high-performing team responsible for assessing and ... Evaluate vendor security posture, compliance certifications (SOC 2, ISO 27001, etc.), and ...
... Third Party Risk Management (TPRM) to lead a high-performing team responsible for assessing and ... Evaluate vendor security posture, compliance certifications (SOC 2, ISO 27001, etc.), and ...
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle-from tiering and onboarding to ...
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle-from tiering and onboarding to ...
Experience supporting Third-Party Risk Management (TPRM), vendor risk, or enterprise risk management processes. * Experience gathering and documenting business requirements. * Hands-on experience ...
Experience supporting Third-Party Risk Management (TPRM), vendor risk, or enterprise risk management processes. * Experience gathering and documenting business requirements. * Hands-on experience ...
Vendor Risk Manager
Westport, CT · On-site
Expert knowledge of third-party/vendor risk management * Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and ...
Vendor Risk Manager
Westport, CT · On-site
Expert knowledge of third-party/vendor risk management * Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and ...
$110K - $167K/yr
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle--from tiering and onboarding to ...
New
$110K - $167K/yr
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle--from tiering and onboarding to ...
New
GRC Analyst - Third Party Risk
Boston, MA · On-site
$70K - $110K/yr
You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows. Success in this role requires strong attention to detail ...
GRC Analyst - Third Party Risk
Boston, MA · On-site
$70K - $110K/yr
You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows. Success in this role requires strong attention to detail ...
Vendor Risk Manager
Westport, CT · Hybrid
Expert knowledge of third-party/vendor risk management * Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and ...
Vendor Risk Manager
Westport, CT · Hybrid
Expert knowledge of third-party/vendor risk management * Strong risk assessment and analytical skills * Technical understanding of enterprise security architecture * Excellent communication and ...
GRC Analyst - Third Party Risk
Boston, MA · On-site
$70K - $110K/yr
You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows. Success in this role requires strong attention to detail ...
GRC Analyst - Third Party Risk
Boston, MA · On-site
$70K - $110K/yr
You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows. Success in this role requires strong attention to detail ...
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle--from tiering and onboarding to ...
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle--from tiering and onboarding to ...
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle-from tiering and onboarding to ...
As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle-from tiering and onboarding to ...
Third-Party Risk Management Manager
Souderton, PA · On-site
$90K - $125K/yr
Overview Join Univest as a Third-Party Risk Management Manager and play a key role in strengthening our enterprise vendor risk program. In this role, you'll oversee third-party risk management ...
Third-Party Risk Management Manager
Souderton, PA · On-site
$90K - $125K/yr
Overview Join Univest as a Third-Party Risk Management Manager and play a key role in strengthening our enterprise vendor risk program. In this role, you'll oversee third-party risk management ...
As CrowdStrike's ecosystem of vendors, partners, and suppliers continues to grow, this role will be ... Third Party Risk Program Management: Develop, implement, and maintain CrowdStrike's TPRM policies ...
As CrowdStrike's ecosystem of vendors, partners, and suppliers continues to grow, this role will be ... Third Party Risk Program Management: Develop, implement, and maintain CrowdStrike's TPRM policies ...
$160K/yr
Third Party Risk Management Lead Professional US 2 days ago Requisition ID: 1286 Salary: $160,000 ... Vendor intake and risk tiering * Security assessments and due diligence * Ongoing monitoring and ...
$160K/yr
Third Party Risk Management Lead Professional US 2 days ago Requisition ID: 1286 Salary: $160,000 ... Vendor intake and risk tiering * Security assessments and due diligence * Ongoing monitoring and ...
Summary: We are seeking a Third-Party Cybersecurity Risk Analyst to support the assessment ... Manage vendor security questionnaires and documentation review processes * Ensure assessments align ...
Summary: We are seeking a Third-Party Cybersecurity Risk Analyst to support the assessment ... Manage vendor security questionnaires and documentation review processes * Ensure assessments align ...
Third Party Risk Mgmt Consultant II
Chicago, IL · On-site
$63 - $76/hr
Support communications related to vendor incidents, CVEs, and zero-day vulnerabilities ... years of Third Party Risk Management (TPRM) or Vendor Risk Management experience * Hands-on ...
Third Party Risk Mgmt Consultant II
Chicago, IL · On-site
$63 - $76/hr
Support communications related to vendor incidents, CVEs, and zero-day vulnerabilities ... years of Third Party Risk Management (TPRM) or Vendor Risk Management experience * Hands-on ...
... third party information security risk management to foster business-enabling insights. RISK ... Perform timely assessments of Vendor controls to identify, document, and communicate key ...
... third party information security risk management to foster business-enabling insights. RISK ... Perform timely assessments of Vendor controls to identify, document, and communicate key ...
Security Third Party Risk Management Lead Cloudflare · United States, Austin, TX Not specified ... Lead the vendor risk assessment process day to day, applying and refining the security policies and ...
Security Third Party Risk Management Lead Cloudflare · United States, Austin, TX Not specified ... Lead the vendor risk assessment process day to day, applying and refining the security policies and ...
Third Party Vendor Risk Management information
See salary details
$43.5K - $54.8K
8% of jobs
$54.8K - $66K
14% of jobs
$71.2K is the 25th percentile. Wages below this are outliers.
$66K - $77.3K
6% of jobs
$77.3K - $88.6K
8% of jobs
$88.6K - $99.9K
11% of jobs
The median wage is $102.2K / yr.
$99.9K - $111.1K
13% of jobs
$111.1K - $122.4K
11% of jobs
$125.8K is the 75th percentile. Wages above this are outliers.
$122.4K - $133.7K
15% of jobs
$133.7K - $145K
8% of jobs
$145K - $156.2K
4% of jobs
$156.2K - $167.5K
2% of jobs
$43.5K
$103.7K
$167.5K
How much do third party vendor risk management jobs pay per year?
What are the key skills and qualifications needed to thrive in third party vendor risk management?
What are some common challenges faced in third party vendor risk management roles, and how can they be addressed?
What is the difference between Third Party Vendor Risk Management vs Vendor Compliance Specialist?
| Aspect | Third Party Vendor Risk Management | Vendor Compliance Specialist |
|---|---|---|
| Primary Focus | Assessing and mitigating risks associated with third-party vendors | Ensuring vendors comply with legal, regulatory, and internal standards |
| Certifications | Certifications like CRISC, CTPRP, or vendor risk management courses | Certifications such as CCEP, CCEP-I, or compliance-specific credentials |
| Work Environment | Risk management teams within finance, IT, or procurement departments | Compliance departments or legal teams within organizations |
| Industry Usage | Common in finance, healthcare, and technology sectors | Prevalent across regulated industries like finance, healthcare, and manufacturing |
While both roles focus on vendor-related activities, Third Party Vendor Risk Management emphasizes assessing and mitigating risks posed by vendors, whereas Vendor Compliance Specialists concentrate on ensuring vendors adhere to applicable standards and regulations. Both roles are essential for maintaining organizational integrity and reducing operational risks.
What is third-party vendor risk management?
What cities are hiring for Third Party Vendor Risk Management jobs?
Cities with the most Third Party Vendor Risk Management job openings:
What states have the most Third Party Vendor Risk Management jobs?
States with the most job openings for Third Party Vendor Risk Management jobs include:
What job categories do people searching Third Party Vendor Risk Management jobs look for?
The top searched job categories for Third Party Vendor Risk Management jobs are:

Sr. Manager, Third Party Risk Management
On-site
Full-time
Re-posted 12 days ago
Key responsibilities
Lead the end-to-end third-party risk lifecycle, including intake, inherent-risk classification, due diligence, contract controls, continuous monitoring, reassessment, and offboarding.
Partner with Procurement, Legal, Privacy, and security teams to translate vendor information into risk decisions and embed risk gates within sourcing, onboarding, and offboarding processes.
Evaluate vendor dependencies, systemic risks, and address risks related to AI tooling, SaaS sprawl, and vendor concentration, translating findings into risk narratives and remediation plans.
Asurion rating
7.2
Based on 84 frontline employees who took The Breakroom Quiz
Job description
The Senior Manager, Third Party Risk Management leads Asurion's enterprise vendor and supply-chain risk program as a second line of defense. This role owns the end-to-end third-party risk lifecycle-intake, inherent-risk tiering, due diligence, contract controls, continuous monitoring, reassessment, and secure offboarding-protecting Asurion and its carrier and partner ecosystem from risks introduced by vendors, service providers, and technology suppliers. The leader partners closely with Procurement, Legal, Privacy, business portfolio owners, and security control owners to translate fragmented vendor information into clear, defensible risk decisions. This is both a program-building and people-leadership role, maturing the vendor risk function in alignment with NIST CSF 2.0 and strengthening supply chain risk outcomes while embedding modern practices for emerging risks such as third-party AI tooling, SaaS sprawl, and vendor concentration.
Key Responsibilities- Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program aligned to NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and regulatory obligations.
- Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology; secure governance approval and drive consistent adoption across the enterprise.
- Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership and apply them to vendor risk decisions.
- Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding in partnership with Procurement and Legal.
- Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination, treatment/acceptance, contracting, continuous monitoring, reassessment, and offboarding.
- Operationalize inherent-risk tiering to scope assessment depth and cadence based on data sensitivity, access, criticality, and business impact.
- Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments and evidence including SOC 2 Type II, ISO 27001, PCI AOC, and penetration test results.
- Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk across the supplier portfolio.
- Establish and lead risk reviews for third-party AI/GenAI tooling with security and privacy teams; address model and data-handling risks and shadow AI.
- Translate findings into concise, business-relevant risk narratives and actionable remediation plans with owners and timelines.
- Operate continuous monitoring leveraging external risk ratings, periodic attestations, threat/breach intelligence, and event-driven triggers.
- Coordinate third-party incident response with SOC/IR; assess impact, drive containment, and track remediation to closure.
- Manage the third-party risk register and findings inventory; escalate aging or accepted risks through governance.
- Maintain visibility into critical vendor resilience and BC/DR posture for high-impact suppliers.
- Partner with Legal and Procurement to define and negotiate security, privacy, and resilience terms (control requirements, right-to-audit, breach notification SLAs, data protection, subprocessor controls).
- Develop a standardized library of contractual security requirements scaled to vendor risk tier.
- Define and report outcome-driven metrics and KRIs (e.g., residual risk trends, assessment cycle time/coverage, time-to-remediate, monitoring coverage, exception aging); deliver executive-ready reporting to governance forums.
- Serve as the primary point of contact for internal/external audits, regulatory exams, and carrier-partner due diligence.
- Build, lead, and develop a high-performing team of vendor risk analysts; set objectives, coach performance, and scale capability through playbooks, training, and quality reviews.
- Drive operational efficiency via process automation and analyst-assistive tooling to focus effort on judgment-intensive decisions.
- 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party/vendor risk management.
- 2+ years of direct people leadership managing analysts or a risk team.
- Demonstrated experience designing or maturing a TPRM program lifecycle end to end.
- Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and assessment standards such as SIG/Shared Assessments.
- Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports) and translating them into risk decisions.
- Hands-on experience with TPRM/GRC platforms and continuous monitoring/security-rating tools (e.g., ProcessUnity, OneTrust, Prevalent/Mitratech, Whistic, BitSight, SecurityScorecard, or comparable).
- Experience partnering with Procurement and Legal on vendor contracting and security/privacy terms.
- Excellent written and verbal communication, including executive briefing and defensible risk narratives.
- Bachelor's degree in a related field or equivalent professional experience.
- Preferred: certifications such as CTPRP, CISSP, CISA, CRISC, or CISM; experience in regulated consumer or financial environments (e.g., GLBA, PCI DSS, state privacy laws); experience with AI/GenAI risk assessment; familiarity with three lines of defense; experience with automation or AI-assisted workflows in GRC.
- Sound risk judgment balancing rigor with business enablement and speed-to-value.
- Ability to influence without authority across Procurement, Legal, Privacy, Security, and business stakeholders.
- Program design, policy/standard development, and governance execution for TPRM.
- Expertise in vendor risk tiering, due diligence, continuous monitoring, issue management, and secure offboarding.
- Strong analytical skills to assess concentration, systemic risk, and fourth-party dependencies.
- Advanced communication skills; distills complex third-party risk into actionable executive decisions.
- Team leadership, talent development, and operational scaling through playbooks, training, and QA.
- Proficiency with metrics/KRIs, dashboards, and executive reporting.
- Negotiation of contractual security/privacy/resilience terms and control requirements.
N/A
Physical Demands- Stationary Position: Frequently
- Vision: 20/20 corrected vision
- Hearing: Receive detailed information if spoken to
About Asurion
Sourced by ZipRecruiter
As the world's leading tech care company, Asurion eliminates the fears and frustrations associated with technology, to ensure our 300 million customers get the most out of their devices, appliances and connections. We provide insurance, repair, replacement, installation and 24/7 support for everything from cellphones to laptops and household appliances. Our experts are available online, on the phone, at one of our more than 700 stores, or can even come to you.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Nashville, TN, US