Third-Party / Vendor Risk Management * Own and manage the third-party risk management (TPRM)/vendor risk program lifecycle, including vendor onboarding, inherent risk assessments, due diligence, risk ...
Third-Party / Vendor Risk Management * Own and manage the third-party risk management (TPRM)/vendor risk program lifecycle, including vendor onboarding, inherent risk assessments, due diligence, risk ...
Security GRC Operations Specialist (TPRM & Risk Management)
Houston, TX · On-site
$53.33 - $63.33/hr
Conduct end-to-end Third-Party Risk Management (TPRM) evaluations and monitor third-party vendor risk profiles. * Manage daily GRC operational processes, tracking risk findings, control gaps, and ...
Security GRC Operations Specialist (TPRM & Risk Management)
Houston, TX · On-site
$53.33 - $63.33/hr
Conduct end-to-end Third-Party Risk Management (TPRM) evaluations and monitor third-party vendor risk profiles. * Manage daily GRC operational processes, tracking risk findings, control gaps, and ...
Business Continuity Vendor Manager
Bremerton, WA · On-site
$91K - $110K/yr
Third-Party / Vendor Risk Management * Own and manage the third-party risk management (TPRM)/vendor risk program lifecycle, including vendor onboarding, inherent risk assessments, due diligence, risk ...
Business Continuity Vendor Manager
Bremerton, WA · On-site
$91K - $110K/yr
Third-Party / Vendor Risk Management * Own and manage the third-party risk management (TPRM)/vendor risk program lifecycle, including vendor onboarding, inherent risk assessments, due diligence, risk ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
... Risk Management (TPRM) Program ... This role ensures that risks associated with third-party vendors, service providers, and FinTech ...
... Risk Management (TPRM) Program ... This role ensures that risks associated with third-party vendors, service providers, and FinTech ...
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...
Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the Senior Enterprise Risk Manager, you will play a hands-on role in executing risk assessments ...
Ensure compliance with internal policies, regulatory requirements, and third-party risk management standards. * Partner with business units and vendors to develop and implement risk mitigation ...
Ensure compliance with internal policies, regulatory requirements, and third-party risk management standards. * Partner with business units and vendors to develop and implement risk mitigation ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
You will independently lead complex third-party risk assessments, influence vendor security and compliance strategies across the organization, shape how the team scales its risk management ...
Reporting to the Director Risk Management, the Senior Vendor Risk Analyst is responsible for assessing third-party risk exposure and supporting the organization's vendor risk management program. This ...
Reporting to the Director Risk Management, the Senior Vendor Risk Analyst is responsible for assessing third-party risk exposure and supporting the organization's vendor risk management program. This ...
BlackRock's third parties include fund operations providers, technology vendors, index and market ... Lead Third-Party Risk Management for Americas region. Framework enhancements * Develop a testing ...
BlackRock's third parties include fund operations providers, technology vendors, index and market ... Lead Third-Party Risk Management for Americas region. Framework enhancements * Develop a testing ...
Third Party Risk Manager
Columbus, OH · On-site
$67K - $81K/yr
Develop, implement and continuously improve the organization's third-party risk management strategy, policy and procedures ensuring effective oversight of vendor relationships. * Lead the development ...
Third Party Risk Manager
Columbus, OH · On-site
$67K - $81K/yr
Develop, implement and continuously improve the organization's third-party risk management strategy, policy and procedures ensuring effective oversight of vendor relationships. * Lead the development ...
Third Party Risk Manager
Columbus, OH · On-site
$67K - $81K/yr
Develop, implement and continuously improve the organization's third-party risk management strategy, policy and procedures ensuring effective oversight of vendor relationships. * Lead the development ...
Third Party Risk Manager
Columbus, OH · On-site
$67K - $81K/yr
Develop, implement and continuously improve the organization's third-party risk management strategy, policy and procedures ensuring effective oversight of vendor relationships. * Lead the development ...
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site
$200K - $225K/yr
Define and manage data gathering, preparation, and execution of third-party risk and onboarding assessments for new vendors and technologies, and guide regular risk reviews for high and critical ...
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site
$200K - $225K/yr
Define and manage data gathering, preparation, and execution of third-party risk and onboarding assessments for new vendors and technologies, and guide regular risk reviews for high and critical ...
BlackRock's third parties include fund operations providers, technology vendors, index and market ... Lead Third-Party Risk Management for Americas region. Framework enhancements * Develop a testing ...
BlackRock's third parties include fund operations providers, technology vendors, index and market ... Lead Third-Party Risk Management for Americas region. Framework enhancements * Develop a testing ...
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site +1
$200K - $225K/yr
Define and manage data gathering, preparation, and execution of third-party risk and onboarding assessments for new vendors and technologies, and guide regular risk reviews for high and critical ...
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site +1
$200K - $225K/yr
Define and manage data gathering, preparation, and execution of third-party risk and onboarding assessments for new vendors and technologies, and guide regular risk reviews for high and critical ...
Advisor - Third-Party Risk Management (TPRM) At CGS CyberDefense, we're more than a cybersecurity ... Support third-party cybersecurity risk assessments and vendor due diligence engagements across ...
Advisor - Third-Party Risk Management (TPRM) At CGS CyberDefense, we're more than a cybersecurity ... Support third-party cybersecurity risk assessments and vendor due diligence engagements across ...
Vendor Risk Management ... Coordinate Third Party Risk Management (TPRM) activities, including risk assessments, control ...
Vendor Risk Management ... Coordinate Third Party Risk Management (TPRM) activities, including risk assessments, control ...
Vendor Risk Management ... Coordinate Third Party Risk Management (TPRM) activities, including risk assessments, control ...
Vendor Risk Management ... Coordinate Third Party Risk Management (TPRM) activities, including risk assessments, control ...
Vendor Risk Management ... Coordinate Third Party Risk Management (TPRM) activities, including risk assessments, control ...
Vendor Risk Management ... Coordinate Third Party Risk Management (TPRM) activities, including risk assessments, control ...
Third Party Vendor Risk Management information
See salary details
$43.5K - $54.8K
8% of jobs
$54.8K - $66K
14% of jobs
$71.2K is the 25th percentile. Wages below this are outliers.
$66K - $77.3K
6% of jobs
$77.3K - $88.6K
8% of jobs
$88.6K - $99.9K
11% of jobs
The median wage is $102.2K / yr.
$99.9K - $111.1K
13% of jobs
$111.1K - $122.4K
11% of jobs
$125.8K is the 75th percentile. Wages above this are outliers.
$122.4K - $133.7K
15% of jobs
$133.7K - $145K
8% of jobs
$145K - $156.2K
4% of jobs
$156.2K - $167.5K
2% of jobs
$43.5K
$103.7K
$167.5K
How much do third party vendor risk management jobs pay per year?
What are the key skills and qualifications needed to thrive in third party vendor risk management?
What are some common challenges faced in third party vendor risk management roles, and how can they be addressed?
What is the difference between Third Party Vendor Risk Management vs Vendor Compliance Specialist?
| Aspect | Third Party Vendor Risk Management | Vendor Compliance Specialist |
|---|---|---|
| Primary Focus | Assessing and mitigating risks associated with third-party vendors | Ensuring vendors comply with legal, regulatory, and internal standards |
| Certifications | Certifications like CRISC, CTPRP, or vendor risk management courses | Certifications such as CCEP, CCEP-I, or compliance-specific credentials |
| Work Environment | Risk management teams within finance, IT, or procurement departments | Compliance departments or legal teams within organizations |
| Industry Usage | Common in finance, healthcare, and technology sectors | Prevalent across regulated industries like finance, healthcare, and manufacturing |
While both roles focus on vendor-related activities, Third Party Vendor Risk Management emphasizes assessing and mitigating risks posed by vendors, whereas Vendor Compliance Specialists concentrate on ensuring vendors adhere to applicable standards and regulations. Both roles are essential for maintaining organizational integrity and reducing operational risks.
What is third-party vendor risk management?
What cities are hiring for Third Party Vendor Risk Management jobs?
Cities with the most Third Party Vendor Risk Management job openings:
What states have the most Third Party Vendor Risk Management jobs?
States with the most job openings for Third Party Vendor Risk Management jobs include:
What job categories do people searching Third Party Vendor Risk Management jobs look for?
The top searched job categories for Third Party Vendor Risk Management jobs are:

Business Continuity Vendor Manager
Bremerton, WA • Hybrid
Full-time
Posted 29 days ago
Kitsap Credit Union rating
8.7
Based on 5 frontline employees who took The Breakroom Quiz
Job description
About Us
Kitsap Credit Union is a not-for-profit, member-owned financial cooperative with more than 300 employees and 14 branches throughout Western Washington. We have a passion for making a positive difference. As a $2 + billion-asset credit union, we are deeply committed to our members’ financial wellbeing and the prosperity and quality of life in the communities we serve. We are proud to be led by individuals with the experience and skills to drive our organization towards our goals for strategic growth and operational excellence. Our KCU Cares Foundation program focuses on providing resources and support for those struggling with homelessness or hunger and improving the financial well-being of the people in our communities. And beyond monetary efforts, we have provided thousands of hours in staff volunteerism and in-kind support.
At Kitsap Credit Union, our success is built on trust-based relationships and personalized service. We understand our employees are key to our success. They provide the personalized service to our members and contribute to the communities where we live. We are committed to providing a supportive, mission-driven, and inclusive culture where employees can grow their careers. To learn more, visit kitsapcu.org.
About the Role
The Business Continuity & Vendor Risk Manager is responsible for the leadership, administration, and continuous improvement of Kitsap Credit Union's Business Continuity Management and Third-Party/Vendor Risk Management programs. Serving as the primary subject matter expert for operational resilience and third-party risk, this position ensures critical business functions, external service provider relationships, and third-party engagements are identified, assessed, monitored, tested, and governed in alignment with regulatory expectations, internal policies, and KCU's risk appetite. As an individual contributor, the role provides enterprise-wide leadership through program ownership, governance, risk oversight, reporting, and cross-functional collaboration. The position partners closely with business owners, Information Security, Information Technology, Compliance, Internal Audit, and executive leadership to strengthen organizational resilience, enhance third-party risk management practices, reduce operational risk exposure, and support audit and examination readiness.
Quick Facts
Reports to: VP, Risk Management
Employment Type: Full-time, salaried, exempt
Salary Range: $91,536.68 - $110,285.16 depending on experience
Bonus Target: 9%
Working Hours: Monday - Friday 8:00 AM - 5:00 PM / Hybrid - 2 days in office
Grade: 12BC
Industry: Banking
PRINCIPAL ACCOUNTABILITIES
Business Continuity Management & Operational Resilience
- Own and manage the credit union’s Business Continuity Management (BCM) program framework, including business impact analysis, continuity planning, recovery strategy documentation, plan maintenance, testing, exercises, and issue tracking.
- Organization wide leadership of departmental continuity plans are current, actionable, and aligned to critical business processes, recovery objectives, dependencies, and member-impact considerations.
- Lead enterprise-level tabletop exercises, scenario testing, and post-exercise reviews; document results, lessons learned, and remediation activities through closure.
- Partnering cross functionally identifying critical operations, internal and external dependencies, recovery gaps, and opportunities to strengthen continuity capabilities across the organization.
- Collaborate with IT, Information Security, Operations, Facilities, and other stakeholders on disaster recovery dependencies, incident response coordination, and continuity-related communications.
Third-Party / Vendor Risk Management
- Own and manage the third-party risk management (TPRM)/vendor risk program lifecycle, including vendor onboarding, inherent risk assessments, due diligence, risk tiering, ongoing monitoring, contract review, issue escalation, and periodic reassessments.
- Provide risk-based oversight of critical and high-risk vendors, including review of financial, operational, information security, business continuity, compliance, privacy, and service performance considerations.
- Partner with business owners to clarify vendor ownership, monitoring expectations, documentation requirements, risk acceptance needs, and accountability for identified gaps or remediation plans.
- Monitor vendor performance, control issues, incidents, emerging risks, and relationship changes that may affect KCU’s risk exposure or continuity posture.
- Coordinate with Compliance, Information Security, Finance, and business stakeholders to support contract risk review and ensure key risk considerations are addressed before or during vendor engagement.
Governance, Reporting & Regulatory Readiness
- Develop and maintain program documentation, standards, procedures, templates, calendars, dashboards, and evidence repositories to support consistent execution and examiner-ready documentation.
- Prepare periodic reporting for the VP of Risk Management , Enterprise Risk Management Committee, executive leadership, and other governance forums regarding BCM and TPRM status, key risks, testing results, issues, exceptions, and remediation progress.
- Maintain awareness of applicable NCUA, FFIEC, and related regulatory guidance impacting business continuity, operational resilience, third-party risk management, and external service provider oversight.
- Key role in internal audits, external audits, regulatory examinations, and management requests by providing documentation, analysis, responses, and corrective action tracking related to BCM and TPRM.
- Escalate material vendor, continuity, operational resilience, or compliance concerns to the VP of Risk Management and appropriate governance channels in a timely and well-documented manner.
Program Maturity & Process Improvement
- Evaluate program maturity and recommend enhancements to strengthen efficiency, consistency, reporting, risk visibility, ownership, and alignment with KCU’s enterprise risk management framework.
- Identify opportunities to reduce reliance on outsourced support by building internal expertise, standardizing workflows, improving tools/templates, and clarifying first-line business owner responsibilities.
- Provide training, guidance, and consultative support to business units on continuity planning, vendor risk expectations, risk assessments, documentation requirements, and issue remediation.
- Support broader ERM initiatives as needed, including risk assessments, key risk indicators, risk appetite monitoring, policy governance, project risk review, and operational risk reporting.
REQUIRED SKILLS AND ABILITIES
- Advanced knowledge of business continuity, operational resilience, vendor management, third-party risk, and risk governance concepts within a regulated financial institution environment.
- Ability to independently manage complex risk programs, balance strategic and operational priorities, and drive cross-functional execution without direct supervisory authority.
- Strong analytical, critical thinking, documentation, and problem-solving skills, with the ability to assess risk, identify gaps, and recommend practical remediation actions.
- Strong written and verbal communication skills, including the ability to prepare executive-level summaries, governance reporting, issue documentation, and business-owner guidance.
- Ability to interpret regulatory expectations and translate them into sustainable program practices, documentation standards, and monitoring routines.
- High degree of judgment, discretion, accountability, and attention to detail when handling sensitive vendor, continuity, risk, audit, and examination information.
- Proficiency with Microsoft Office Suite and ability to work with vendor management, GRC, reporting, document management, or workflow tools.
- Demonstrates a high level of engagement and active collaboration, contributing to a positive team environment and modeling KCU’s core values.
REQUIRED Qualifications and Education
- 5 plus years in risk management.
- Experience with NCUA, FFIEC, GLBA, privacy, cybersecurity, operational resilience, disaster recovery, or third-party risk regulatory expectations.
- Experience managing or improving a vendor management, TPRM, business continuity, operational resilience, or GRC program.
- Professional certification such as CBCP, MBCP, CRVPM, CTPRP, CTPRA, CRISC, CERP, PMP, or similar risk, continuity, vendor management, or governance credential.
Preferred Qualifications and Education
- Credit union or community financial institution experience preferred.
- Experience owning full cycle of vendor management program.
SUPERVISORY STATUS
This position does not supervise others.
Working conditions
This position will be required to work in an office environment with moderate noise levels, and, with or without reasonable accommodation is required:
- Must be able to remain in a stationary position for a minimum of 75% of the time
- Constantly operates a computer and other office productivity machines
- The person in this position frequently communicates with peers, supervisors, vendors and employees to exchange accurate information and answer questions
- Works in an indoor office environment but expected to attend meetings in buildings that require travel in outdoor weather conditions
EQUAL EMPLOYMENT OPPORTUNITY/AFFIRMATIVE ACTION STATEMENT
Kitsap Credit Union is firmly committed to equality of opportunity for all employees and applicants for employment in accordance with applicable Equal Employment Opportunity/Affirmative Action laws, directives, and legislation.
This job description is intended to describe the general nature and level of work being performed by employees in this position. It is not intended to be an exhaustive list of all responsibilities, duties, and skills required for this position; other duties outside of normal responsibilities may be performed as necessary to meet the needs of the organization. Nothing in this position description restricts management’ right to assign or reassign duties and responsibilities to this job at any time.
We believe in the power of belonging – it’s in our DNA as a not-for-profit, member-owned cooperative. Our un-bank-like structure ensures that we remain all about people: our members, our employees, and the people in the communities where we live and work. We work hard to provide a collaborative and inclusive environment where you can grow and excel in your career.
We are dedicated to serving our members by providing personalized experiences, convenient access, and highly competitive products and services. But it goes much deeper than that. For more than 86 years, we have been relentless about making a positive difference in our communities. We understand that when our members and communities succeed, we all succeed, and that success can’t happen without great employees.
****** Employment is contingent upon satisfactory background check. Kitsap Credit Union is an Equal Opportunity Employer. All qualified applicants for employment will receive consideration without regard to sex, marital status, race, color, religion, national origin, age, veteran status, disability, genetic information, or any other protected status. ******
#IND
What Kitsap Credit Union employees say
Pay
Hours and flexibility
Workplace
Get the full story on Breakroom
About Kitsap Credit Union
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
201 - 500 Employees
Headquarters location
Bremerton, WA, US
Year founded
1934