1

Vendor Risk Management Jobs in California (NOW HIRING)

Drive workflow optimization and automation within ServiceNow Vendor Risk Management * Review and advise on vendor agreements * Enhance vendor risk processes, including risk tiering, assessments, and ...

GRC Risk Management Analyst

San Jose, CA · On-site

$68 - $72/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and ...

GRC Risk Management Analyst

San Jose, CA · On-site

$68.97 - $72.80/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and ...

Conduct and oversee risk reviews for contracts, vendor agreements, and new business initiatives ... Oversee coordination of risk management efforts related to physical security, safety, and ...

Director, Risk Management

San Diego, CA · On-site

$169.48 - $203.38/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Director of Risk Management provides strategic leadership and operational oversight for risk ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Director, Risk Management

San Diego, CA · On-site

$169.48 - $203.38/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Director of Risk Management provides strategic leadership and operational oversight for risk ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Director, Risk Management

San Diego, CA

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Director of Risk Management provides strategic leadership and operational oversight for risk ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Director, Risk Management

San Diego, CA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Director of Risk Management provides strategic leadership and operational oversight for risk ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Director, Risk Management

San Diego, CA · On-site

$169.48 - $203.38/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

The Director of Risk Management provides strategic leadership and operational oversight for risk ... and vendor agreements, equipment leases, joint ventures, and professional service agreements.

Showing results 21-40

Vendor Risk Management information

See California salary details

$42.9K

$102.3K

$165.3K

How much do vendor risk management jobs pay per year?

As of Aug 15, 2026, the average yearly pay for vendor risk management in California is $102,346.00, according to ZipRecruiter salary data. Most workers in this role earn between $71,600.00 and $130,300.00 per year, depending on experience, location, and employer.

How to do vendor risk management?

Vendor risk management involves identifying, assessing, and mitigating risks associated with third-party vendors to ensure they meet security, compliance, and performance standards. It typically includes conducting due diligence, evaluating vendor controls, and monitoring ongoing performance using tools like risk assessment frameworks and vendor management software. Strong communication and documentation are essential for effective oversight.

What are the key skills and qualifications needed to thrive in vendor risk management?

To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.

What does a vendor risk management do?

A vendor risk management professional assesses and monitors the risks associated with third-party vendors to ensure compliance, security, and operational integrity. They evaluate vendor security practices, contractual obligations, and potential vulnerabilities, often using risk assessment tools and frameworks to mitigate potential threats to the organization.

What is vendor risk management?

A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.

What are some common challenges faced in vendor risk management?

Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

What are the most commonly searched types of Vendor Risk Management jobs in California?

The most popular types of Vendor Risk Management jobs in California are:

What are popular job titles related to Vendor Risk Management jobs in California?

For Vendor Risk Management jobs in California, the most frequently searched job titles are:

What job categories do people searching Vendor Risk Management jobs in California look for?

The top searched job categories for Vendor Risk Management jobs in California are:

What cities in California are hiring for Vendor Risk Management jobs?

Cities in California with the most Vendor Risk Management job openings:

Infographic showing various Vendor Risk Management job openings in California as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 2% Temporary, and 2% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $102,346 per year, or $49.2 per hour.

Manager, IT Risk Operations

Wsgr

Palo Alto, CA

$147K - $198K/yr

Full-time

Re-posted 5 days ago


Job description

Wilson Sonsini is the premier legal advisor to technology, life sciences, and other growth enterprises worldwide. We represent companies at every stage of development, from entrepreneurial start-ups to multibillion-dollar global corporations, as well as the venture firms, private equity firms, and investment banks that finance and advise them. The firm has approximately 1,100 attorneys in 17 offices: 13 in the U.S., two in China, and two in Europe. Our broad spectrum of practices and entrepreneurial spirit allow exceptional opportunities for professional achievement and career growth.

Essential Duties and Responsibilities:

This high-impact position in the Governance, Risk & Compliance function sits at the center of the firm's technology, security, and operational ecosystem.Managing a small team, you willwork closely with senior leaders across IT, Security Engineering, General Counsel, and firm leadership to shape how risk is understood, measured, and managed.

The role can be 100% remote or hybrid-in person if located near a physical office.

Strengthen IT Governance & Controls

  • Lead the development of executive-level reporting on IT risk, compliance posture, and operational performance
  • Build and evolve KPI/KRI dashboards that provide real-time visibility into risk trends and control effectiveness
  • Translate complex IT and security data into meaningful insights for decision making
  • Ensure adherence to IT policies, standards, and leading frameworks (e.g., NIST, ISO 27001)
  • Own and evolve the firm's IT risk register and Risk & Control Self-Assessment (RCSA) program
  • Identifyemerging and systemic risks across IT, security, privacy, and operational processes

Incident Governance & Investigations

  • Partner with General Counsel, Security, and IT to lead internal investigations

Own ITSM Governance & ServiceNow Analytics

  • Oversee governance and reporting across the IT Service Management (ITSM) ecosystem
  • Analyze incident, change, and problem management data toidentifytrends and improvement opportunities
  • Drive workflow optimization and automation within ServiceNow

Vendor Risk Management

  • Review and advise on vendor agreements
  • Enhance vendor risk processes, including risk tiering, assessments, and monitoring
  • Identifyopportunities to streamline processes, enhance reporting, and improve governance
  • Introduce data-driven approaches to risk management and operational oversight
  • Perform related duties as assigned or directed by supervisor
  • Maintain compliance with all firm policies and procedures

Education and/or Work Experience Requirements:

  • Bachelor's degree preferred
  • Seven years of experience in ITrisk,securitycompliance,technologyaudit, or ITgovernancepreferred
  • Experienceoperatingin complex, regulated environments (e.g., law firms, financial services, consulting)preferred
  • Proven ability to lead reporting, analytics, and governance initiatives
  • Familiarity with ServiceNow and ITSM reporting including understanding of incident, change, and problem management lifecycles
  • Experience with security and collaboration platforms such as Microsoft 365,Purviewand email security tools
  • Working knowledge of frameworks such as the NIST Cybersecurity Framework, ISO/IEC 27001and SOC 2
  • Strong understanding of control design, risk registers, RCSA programs, and audit response
  • Basic understanding of privacy regulations
  • CISA, CISSP, CRISC,CTPRMand/or ITILpreferred
The primary location for this job posting is in Palo Alto, but other locations may be listed. The actual base pay offered will depend upon a variety of factors, including but not limited to the selected candidate's qualifications, years of relevant experience, level of education, professional certifications and licenses, and work location. The anticipated pay range for this position is as follows:Palo Alto, New York, San Francisco: $163,200 - $220,800 per year. Austin, Boston, Boulder, Century City, Los Angeles, Salt Lake City, San Diego, Seattle: $147,050 - $198,950 per year.

The compensation for this position may include a discretionary year-end merit bonus based on performance. We offer a highly competitive salary and benefits package.

Benefits information can be found here. Equal Opportunity Employer (EOE).