1

Tprm Jobs in California (NOW HIRING)

CA ยท On-site

You will also serve as the primary authority for Third-Party Risk Management (TPRM) architectural reviews, ensuring proposed technology investments are evaluated through sound architectural ...

next page

Showing results 1-20

Tprm information

See California salary details

$5

$55

$86

How much do tprm jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for tprm in California is $55.46, according to ZipRecruiter salary data. Most workers in this role earn between $48.17 and $68.32 per hour, depending on experience, location, and employer.

What is a TPRM?

A TPRM (Third-Party Risk Management) job involves assessing, monitoring, and mitigating risks associated with an organization's third-party vendors, suppliers, or service providers. Professionals in TPRM evaluate vendor security, compliance, and operational stability to ensure they align with company policies and regulatory requirements. They often collaborate with internal stakeholders and external partners to conduct risk assessments, manage due diligence processes, and implement risk mitigation strategies. This role is critical in industries like finance, healthcare, and technology, where third-party relationships can significantly impact business operations and regulatory compliance.

What are the key skills and qualifications needed to thrive in the TPRM position, and why are they important?

To excel as a Third Party Risk Manager (TPRM), you need strong analytical skills, knowledge of risk management principles, and experience in vendor management or compliance frameworks. Familiarity with risk assessment tools, governance, risk and compliance (GRC) platforms, and relevant certifications such as CTPRP or CRISC is highly valued. Exceptional communication, stakeholder management, and critical thinking are standout soft skills that facilitate collaborative risk mitigation. These skills are essential for ensuring third-party relationships are assessed and managed responsibly to protect organizational interests.

What are typical challenges faced by a Third Party Risk Manager (TPRM) on a daily basis?

Third Party Risk Managers often navigate the complexities of assessing and monitoring multiple vendors across various departments, each with their own processes and risk profiles. Challenges include gathering sufficient due diligence documentation, staying updated on evolving regulations, and ensuring that vendors meet compliance and security standards. The role frequently collaborates with procurement, legal, IT, and business units to address concerns and remediate potential risks. Successfully managing these challenges requires strong organizational skills, attention to detail, and the ability to communicate requirements effectively both internally and externally.

What are the most commonly searched types of Tprm jobs in California? The most popular types of Tprm jobs in California are:
What cities in California are hiring for Tprm jobs? Cities in California with the most Tprm job openings:
Infographic showing various Tprm job openings in California as of August 2026, with employment types broken down into 82% Full Time, and 18% Contract. Highlights an 78% In-person, and 22% Remote job distribution, with an average salary of $115,358 per year, or $55.5 per hour.

GRC TPRM Assessment and Remediation SME

Tata Consultancy Service Limited

Sunnyvale, CA โ€ข On-site

$80K - $140K/yr

Full-time

Re-posted 2 days ago


Job description

We are seeking an experienced Third-Party Risk Management (TPRM) Assessment and Remediation Subject Matter Expert to manage the end-to-end lifecycle of supplier/vendor cybersecurity risk assessments and remediation from inventory governance through assessment coordination, escalation management, and executive reporting in a fully remote, client-facing environment. This role serves as the process authority for vendor risk assessments, findings management, and cross-functional remediation, requiring precise, proactive communication to maintain trust with high-visibility stakeholders.
Key Responsibilities
1. Supplier Inventory Management
โ€ข Maintain the Supplier Inventory (GRC platform, e.g., SupplierNinja) as the single source of truth for assessment status.
โ€ข Tier/filter suppliers requiring reassessment vs. new assessment per program criteria.
โ€ข Maintain accurate Direct Responsible Individual (DRI) records in the GRC tool (e.g., OneTrust).
2. Assessment Execution
โ€ข Evaluate suppliers against standard frameworks (SIG, CAIQ, NIST CSF, ISO 27001, SOC 2) and validate evidence (audit reports, certifications, pen test results).
โ€ข Confirm DRI ownership and obtain kick-off acknowledgement before initiating assessments.
โ€ข Log and track assessment tasks in a workflow tool (e.g., Wrike), including acknowledgement evidence.
โ€ข Confirm onsite-assessed suppliers have current-year coverage (e.g., in AirTable).
โ€ข Participate in recurring findings-review meetings (e.g., CSFA), advising on policy and evidence standards.
3. Remediation Management
โ€ข Own Corrective Action Plans (CAPs) end-to-end: define SLAs, track progress, drive closure with vendors and business owners.
โ€ข Coordinate with Legal, Procurement, and InfoSec on remediation timelines and compensating controls.
4. Stakeholder Communication & Escalation
โ€ข Run a structured outreach cadence with DRIs (kick-off 3 follow-ups 3 escalations to management).
โ€ข Track response/non-response rates for every outreach cycle.
โ€ข Escalate unresolved/high-risk findings to client leadership and track to closure.
5. Weekly Reporting
Deliver a standing weekly metrics report to leadership: outreach volume, response rates, follow-up/escalation status, suppliers approved for (re)assessment, and overall assessment/remediation coverage.
Required Qualifications
โ€ข 5+ years in cybersecurity, TPRM, GRC operations, or supplier risk coordination.
โ€ข Working knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ.
โ€ข Hands-on experience with GRC/TPRM tools (OneTrust, Archer, ServiceNow GRC, SupplierNinja, or similar).
โ€ข Proven ownership of high-volume, multi-step communication workflows with strict tracking/documentation.
โ€ข Excellent written communication for remote, client-facing engagement.
โ€ข Experience operating in distributed/remote teams.
Preferred Qualifications
โ€ข Certification: CTPRP, CRISC, CISA, or CISSP.
โ€ข Experience with Wrike, AirTable, Jira, or similar tracking tools.
โ€ข Prior experience in regulated industries (financial services, healthcare, insurance).
โ€ข Track record producing leadership-facing weekly reporting.
Location : Sunnyvale, CA/Austin, TX
Salary Range : $80,000-$140,000 a year
#LI-AS3