1

Third Party Vendor Risk Management Jobs (NOW HIRING)

Vendor Risk Associate ABOUT THE POSITION: This position will support the identification, vetting ... Monitor and manage all supplier alerts provided by third party information services * Respond to ...

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...

Vendor Risk Manager

Westlake, TX · On-site

$36.78 - $40.87/hr

Execute a robust third-party risk management framework, conducting risk assessment and oversight activities to effectively assess, monitor, and mitigate vendor risks. * Consistently apply established ...

Maintain and update the third-party / vendor inventory within the risk management system. * Ensure vendor data is complete, accurate, and aligned with organizational standards * Perform routine data ...

Showing results 21-40

Third Party Vendor Risk Management information

See salary details

$43.5K

$103.7K

$167.5K

How much do third party vendor risk management jobs pay per year?

As of Sep 11, 2026, the average yearly pay for third party vendor risk management in the United States is $103,704.00, according to ZipRecruiter salary data. Most workers in this role earn between $72,500.00 and $132,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive in third party vendor risk management?

To thrive in Third Party Vendor Risk Management, you need a solid understanding of risk assessment, compliance frameworks, and vendor management processes, often supported by a degree in business, information security, or a related field. Familiarity with risk management software, GRC (Governance, Risk, and Compliance) tools, and certifications like CTPRP or CISA are commonly required. Strong analytical thinking, communication, and negotiation skills help professionals build effective relationships and convey risk findings. These skills are critical for identifying, mitigating, and managing risks associated with third-party vendors, ultimately protecting organizational interests and ensuring regulatory compliance.

What are some common challenges faced in third party vendor risk management roles, and how can they be addressed?

Professionals in Third Party Vendor Risk Management often encounter challenges such as evaluating vendor risk with limited visibility, ensuring timely compliance documentation, and coordinating risk assessments across multiple departments. To address these, effective communication skills and the ability to build strong relationships with both vendors and internal stakeholders are essential. Utilizing centralized risk management tools and staying updated on regulatory requirements can help streamline processes and reduce oversight gaps, making the role both impactful and dynamic.

What is the difference between Third Party Vendor Risk Management vs Vendor Compliance Specialist?

AspectThird Party Vendor Risk ManagementVendor Compliance Specialist
Primary FocusAssessing and mitigating risks associated with third-party vendorsEnsuring vendors comply with legal, regulatory, and internal standards
CertificationsCertifications like CRISC, CTPRP, or vendor risk management coursesCertifications such as CCEP, CCEP-I, or compliance-specific credentials
Work EnvironmentRisk management teams within finance, IT, or procurement departmentsCompliance departments or legal teams within organizations
Industry UsageCommon in finance, healthcare, and technology sectorsPrevalent across regulated industries like finance, healthcare, and manufacturing

While both roles focus on vendor-related activities, Third Party Vendor Risk Management emphasizes assessing and mitigating risks posed by vendors, whereas Vendor Compliance Specialists concentrate on ensuring vendors adhere to applicable standards and regulations. Both roles are essential for maintaining organizational integrity and reducing operational risks.

What is third-party vendor risk management?

Third-party vendor risk management is the process of identifying, assessing, and mitigating risks associated with external vendors or suppliers that provide goods or services to an organization. It involves evaluating vendor security, compliance, and performance to protect the organization from potential disruptions, data breaches, or regulatory issues. Professionals in this field often use risk assessment tools and may hold certifications like Certified Third Party Risk Professional (CTPRP).
More about Third Party Vendor Risk Management jobs

What cities are hiring for Third Party Vendor Risk Management jobs?

Cities with the most Third Party Vendor Risk Management job openings:

What states have the most Third Party Vendor Risk Management jobs?

States with the most job openings for Third Party Vendor Risk Management jobs include:

What job categories do people searching Third Party Vendor Risk Management jobs look for?

The top searched job categories for Third Party Vendor Risk Management jobs are:

Infographic showing various Third Party Vendor Risk Management job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 82% Full Time, 15% Part Time, and 2% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $103,704 per year, or $49.9 per hour.

Senior Information Security Risk Analyst (3rd Party Vendor Risk)

Atlanta, GA • Hybrid

Full-time

Re-posted 13 days ago


Key responsibilities

  • Perform third-party vendor risk assessments using WBD processes and tools to evaluate information security risks.

  • Review vendor controls, identify deficiencies, and communicate findings and recommendations to the business and security management.

  • Review contracts to ensure appropriate data security terms are included and provide comments or alternatives as needed.


Job description

Welcome to Warner Bros. Discovery... the stuff dreams are made of.

Who We Are...

When we say, "the stuff dreams are made of," we're not just referring to the world of wizards, dragons and superheroes, or even to the wonders of Planet Earth. Behind WBD's vast portfolio of iconic content and beloved brands, are the storytellers bringing our characters to life, the creators bringing them to your living rooms and the dreamers creating what's next...

From brilliant creatives, to technology trailblazers, across the globe, WBD offers career defining opportunities, thoughtfully curated benefits, and the tools to explore and grow into your best selves. Here you are supported, here you are celebrated, here you can thrive.

*Must work a hybrid schedule (3 days onsite) out of our Atlanta office.*

THE JOB:
The Senior Information Security Risk Analyst will support the assessment of information security risks across all of Warner Bros. Discovery's (WBD's) third party suppliers/vendors. This role requires the ability to understand and assess information security risks posed by third parties and clearly communicate those risks to the business. It will apply global IT industry best practices to ensure WBD uses third party information security risk management to foster business-enabling insights.

RISK ASSESSMENTS:

  • Use WBD processes and tools to perform 3rd party vendor risk assessments, for new and existing vendors
  • Work with business to understand the "what" and "how" of services provided by vendor to assess level of risk and scope of assessment
  • Perform timely assessments of Vendor controls to identify, document, and communicate key deficiencies to the business and Information Security management
  • Report on assessment outcomes, risk level and associated recommendations to remediate issues
  • Perform 2nd-level peer reviews of assessment outputs, prior to reports being finalized, to drive consistency and completeness of findings based on risk of engagement
  • Assist with follow-up on documentation requests for initial and periodic assessments

FINDINGS MANAGEMENT:

  • Monitor corrective action plans against agreed upon timelines
  • Review of remediation evidence for closure of findings

CONTRACT REVIEWS:

  • Review contracts to ensure appropriate data security terms are included
  • Provide comment and acceptable alternatives to vendor contract revisions, in alignment with defined guidance
  • Escalate provision changes, as needed

OTHER:

  • Assist with contract intake to ensure pipeline of assessments is managed in a timely and efficient manner
  • Provide periodic status updates
  • Maintain accurate and complete data within the identified system of record
  • Contribute to the team's continuous improvement efforts by identifying opportunities and helping to implement them

THE ESSENTIALS:

  • BS/BA degree required
  • 3-5 years' experience in information security, with at least one (1) year experience in third party risk management
  • Knowledge of IP network infrastructure (firewalls, intrusion detection/prevention), access control, data encryption and physical security; Cloud security knowledge a plus
  • Excellent communication skills, including the ability to communicate effectively in English, both written and verbal
  • Ability to present complex topics in clear, non-technical language
  • Ability to work collaboratively within team and across business and technology functions
  • Detail-oriented individual with critical thinking, analytical, and problem-solving skills
  • Demonstrated ability to be proactive and take ownership of and solve problems
  • Active learner - able to enhance personal, professional, and business growth through new knowledge and experiences
  • Ability to handle multiple assignments concurrently within an iterative environment

THE NICE TO HAVES:

  • One or more of the following certifications: CISSP, CRISC, CISA
  • 2+ years of prior experience in a related field (media, entertainment, business development or streaming services industry experience a plus)
  • Familiarity with streaming and similar products/services
  • Experience working in a national or global company

How We Get Things Done...

This last bit is probably the most important! Here at WBD, our guiding principles are the core values by which we operate and are central to how we get things done. You can find them at www.wbd.com/guiding-principles/ along with some insights from the team on what they mean and how they show up in their day to day. We hope they resonate with you and look forward to discussing them during your interview.

Championing Inclusion at WBD

Warner Bros. Discovery embraces the opportunity to build a workforce that reflects a wide array of perspectives, backgrounds and experiences. Being an equal opportunity employer means that we take seriously our responsibility to consider qualified candidates on the basis of merit, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity or expression, age, mental or physical disability, and genetic information, marital status, citizenship status, military status, protected veteran status or any other category protected by law.

If you're a qualified candidate with a disability and you require adjustments or accommodations during the job application and/or recruitment process, please visit our accessibility page for instructions to submit your request.