Vendor Risk Management * Oversee the Third-Party/Vendor Risk Management program, ensuring appropriate due diligence, risk assessment, and ongoing monitoring. * Ensure compliance with regulatory ...
Vendor Risk Management * Oversee the Third-Party/Vendor Risk Management program, ensuring appropriate due diligence, risk assessment, and ongoing monitoring. * Ensure compliance with regulatory ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Manager, Risk Management
Tustin, CA ยท On-site
... Vendor) and controls within business units are identified and documented and recommendations of enhancement to improve the effectiveness of risk management efforts across the organization are ...
Manager, Risk Management
Tustin, CA ยท On-site
... Vendor) and controls within business units are identified and documented and recommendations of enhancement to improve the effectiveness of risk management efforts across the organization are ...
Risk Management Analyst
Irvine, CA ยท On-site
Field vendor calls, evaluate relevance to the department, and deliver clear summaries and ... Provide backup coverage and continuity support for the Risk Management Manager Position ...
Quick apply
Risk Management Analyst
Irvine, CA ยท On-site
Field vendor calls, evaluate relevance to the department, and deliver clear summaries and ... Provide backup coverage and continuity support for the Risk Management Manager Position ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Implement third-party risk management processes, including vendor risk assessments, contract reviews, and ongoing monitoring * Create risk treatment plans and track remediation activities across the ...
Risk Management Analyst
Irvine, CA ยท On-site
Field vendor calls, evaluate relevance to the department, and deliver clear summaries and ... Provide backup coverage and continuity support for the Risk Management Manager Position ...
Risk Management Analyst
Irvine, CA ยท On-site
Field vendor calls, evaluate relevance to the department, and deliver clear summaries and ... Provide backup coverage and continuity support for the Risk Management Manager Position ...
Familiarity with marketplace lending, fintech partnerships, and/or vendor risk management frameworks Work Location San Francisco The above locations are eligible offices for this role. The locations ...
Familiarity with marketplace lending, fintech partnerships, and/or vendor risk management frameworks Work Location San Francisco The above locations are eligible offices for this role. The locations ...
Familiarity with marketplace lending, fintech partnerships, and/or vendor risk management frameworks Work Location San Francisco The above locations are eligible offices for this role.The locations ...
Familiarity with marketplace lending, fintech partnerships, and/or vendor risk management frameworks Work Location San Francisco The above locations are eligible offices for this role.The locations ...
S. risk and insurance programs, providing strategic oversight and operational management across all ... from vendors, contractors, and partners. * Track and manage insurance-covered expenses and ...
S. risk and insurance programs, providing strategic oversight and operational management across all ... from vendors, contractors, and partners. * Track and manage insurance-covered expenses and ...
Raley's Risk Management Analyst
West Sacramento, CA ยท On-site
$71K/yr
You will partner closely with the Director, Risk Management to evaluate insurance programs, vendor performance, and risk trends, and serve as a technical resource to internal leaders, third-party ...
Raley's Risk Management Analyst
West Sacramento, CA ยท On-site
$71K/yr
You will partner closely with the Director, Risk Management to evaluate insurance programs, vendor performance, and risk trends, and serve as a technical resource to internal leaders, third-party ...
Risk Manager
Los Angeles, CA ยท On-site
$155K - $175K/yr
Contractor & Risk Transfer Management * Establish and enforce insurance requirements for contractors, consultants, and vendors. * Review contracts, indemnification provisions, and certificates of ...
Risk Manager
Los Angeles, CA ยท On-site
$155K - $175K/yr
Contractor & Risk Transfer Management * Establish and enforce insurance requirements for contractors, consultants, and vendors. * Review contracts, indemnification provisions, and certificates of ...
S. risk and insurance programs, providing strategic oversight and operational management across all ... from vendors, contractors, and partners. * Track and manage insurance-covered expenses and ...
S. risk and insurance programs, providing strategic oversight and operational management across all ... from vendors, contractors, and partners. * Track and manage insurance-covered expenses and ...
Risk Management Coordinator - City of Bessemer
San Juan Capistrano, CA ยท On-site
$56K - $87K/yr
Risk Management Coordinators are responsible for ensuring that the operations of the city's Risk ... Experience reviewing contracts from third-party vendors for accuracy and completeness in order to ...
Risk Management Coordinator - City of Bessemer
San Juan Capistrano, CA ยท On-site
$56K - $87K/yr
Risk Management Coordinators are responsible for ensuring that the operations of the city's Risk ... Experience reviewing contracts from third-party vendors for accuracy and completeness in order to ...
You will partner closely with the Director, Risk Management to evaluate insurance programs, vendor performance, and risk trends, and serve as a technical resource to internal leaders, third-party ...
You will partner closely with the Director, Risk Management to evaluate insurance programs, vendor performance, and risk trends, and serve as a technical resource to internal leaders, third-party ...
We are seeking a Vendor Security Contractor with strong experience in third-party / vendor risk management and network security to support our Information Risk Questionnaire (IRQ) process and secure ...
Quick apply
We are seeking a Vendor Security Contractor with strong experience in third-party / vendor risk management and network security to support our Information Risk Questionnaire (IRQ) process and secure ...
Senior Analyst, Information Security Governance, Risk, & Compliance
Commerce, CA ยท On-site
$121K - $152K/yr
Additionally, this person will also be responsible for leading vulnerability management efforts, and vendor and risk management programs, including leading the risk-based change management program ...
Senior Analyst, Information Security Governance, Risk, & Compliance
Commerce, CA ยท On-site
$121K - $152K/yr
Additionally, this person will also be responsible for leading vulnerability management efforts, and vendor and risk management programs, including leading the risk-based change management program ...
Additionally, this person will also be responsible for leading vulnerability management efforts, and vendor and risk management programs, including leading the risk-based change management program ...
Additionally, this person will also be responsible for leading vulnerability management efforts, and vendor and risk management programs, including leading the risk-based change management program ...
Vendor Security Manager
San Francisco, CA ยท On-site
What You'll Do Program Ownership & Security Risk Management Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program ...
Vendor Security Manager
San Francisco, CA ยท On-site
What You'll Do Program Ownership & Security Risk Management Be the interface between Security and Sierra teams on everything vendor security related, drive risk conversations, and keep the program ...
Associate GRC Security Analyst
$80K - $105K/yr
Experience with or exposure to vendor risk assessment processes and third-party risk management * Strong attention to detail with the ability to organize and manage documentation and evidence across ...
Associate GRC Security Analyst
$80K - $105K/yr
Experience with or exposure to vendor risk assessment processes and third-party risk management * Strong attention to detail with the ability to organize and manage documentation and evidence across ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor ... Escalate material risks, control deficiencies, and vendor issues through established governance and ...
The Third Party Risk Management (TPRM) Capability Lead is a senior individual contributor ... Escalate material risks, control deficiencies, and vendor issues through established governance and ...
Vendor Risk Management information
See California salary details
$42.9K - $54.1K
8% of jobs
$54.1K - $65.2K
14% of jobs
$70.3K is the 25th percentile. Wages below this are outliers.
$65.2K - $76.3K
6% of jobs
$76.3K - $87.4K
8% of jobs
$87.4K - $98.6K
11% of jobs
The median wage is $100.9K / yr.
$98.6K - $109.7K
13% of jobs
$109.7K - $120.8K
11% of jobs
$124.2K is the 75th percentile. Wages above this are outliers.
$120.8K - $131.9K
15% of jobs
$131.9K - $143.1K
8% of jobs
$143.1K - $154.2K
4% of jobs
$154.2K - $165.3K
2% of jobs
$42.9K
$102.3K
$165.3K
How much do vendor risk management jobs pay per year?
What is the highest paying risk management job?
Do risk managers make good money?
What are the key skills and qualifications needed to thrive in the Vendor Risk Management position, and why are they important?
To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.
How much does a Risk Manager get paid?
What is a Vendor Risk Management job?
A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.
What is a vendor Risk Manager?
What are some common challenges faced in a Vendor Risk Management role?
Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

VP, Head of Enterprise Risk Management (ERM)
SF Fire Credit UnionSan Francisco, CA โข On-site, Remote
Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 16 days ago
Job description
In 1951 SF Fire Credit Union first opened its doors from a modest 10' x 15' office space in 17 Engine. It was from those humble beginnings-where everyone pitched in to help one another in their community-that the organization forged its way of business forever. Today, the San Francisco-based credit union has grown to $1.7B in assets and a membership that extends from the regional firefighters we trace our roots back to throughout our many neighbors in San Francisco, San Mateo and Marin Counties. Our members benefit from the ideas and principles that have shaped us: Shared trust, continuous innovation of products and services, competitive rates, and excellent member service. These qualities foster a true sense of member-ownership and strengthen the credit union's bond with the people for whom this credit union was created.
What we stand for...
There are a few things we look for those we hire at SF Fire Credit Union, regardless of role or team.
First, do they align with our values?
Be Personal - Walk the Member/Employee Path
Be a Leader - Empower, Collaborate, Own
Be Outside the Box - Innovate, Educate, Engage
Be Real - Integrity and Transparency Matter
Be the Connection - Serve our Community
Second, will they thrive in a culture like ours, where we default to trust, embrace feedback, and desire to innovate? Finally, do they share our vision to help empower members to accomplish their dreams and build lasting financial security in whatever way is most relevant to their role?
What it feels like...
Most days it feels more like going to work with a big family. Whether it's a pot luck lunch, baking birthday cakes for colleagues in the kitchen, or after-hours get together, we're here to do a great job and have a good time while doing it! We value a good sense of humor, are motivated by a higher purpose, and always bring an "in-this-together" attitude. While we're driven to do great work, we also value real work/life balance.
Is This the Career for You?
The Vice President, Head of Enterprise Risk Management (ERM) is a senior leadership role responsible for designing, implementing, and continuously maturing the Credit Union's enterprise risk management framework. This role provides strategic oversight across all risk disciplines, including ERM, Compliance, Business Continuity Planning (BCP), and Vendor Risk Management.
The VP will lead the organization's efforts to identify, assess, monitor, and mitigate risks across all NCUA risk categories, while ensuring alignment with regulatory expectations, industry best practices, and organizational strategy. A critical component of this role is strong expertise in technology and IT-related risks, including cybersecurity, data governance, and IT compliance.
What You'll Be Doing
Enterprise Risk Management Leadership
- Lead the development, implementation, and ongoing enhancement of a formal Enterprise Risk Management (ERM) framework aligned with regulatory expectations and industry standards (e.g., COSO ERM Framework).
- Establish a holistic risk management approach that integrates risk awareness into strategic planning and operational decision-making.
- Provide enterprise-wide oversight of risk identification, assessment, mitigation, and monitoring activities.
- Maintain oversight across all seven NCUA risk categories, including Credit Risk, Interest Rate Risk, Liquidity Risk, Operational Risk, Compliance Risk, Strategic Risk, and Reputation Risk.
- Ensure risks are effectively assessed, documented, and managed across all business units.
- Design and oversee the Enterprise Risk Assessment program to identify emerging and top organizational risks.
- Lead the implementation and ongoing enhancement of Risk and Control Self-Assessments (RCSA) across the organization.
- Ensure consistency, quality, and reliability of risk assessments across business lines.
- Partner with business leaders to strengthen control environments and risk mitigation strategies.
- Develop, refine, and maintain the organization's Risk Appetite Framework, ensuring alignment with strategic objectives and board expectations.
- Establish and monitor KRIs and thresholds to proactively manage risk exposure.
- Provide actionable insights and early warning signals to executive leadership.
- Deliver comprehensive, timely, and insightful risk reporting to executive management.
- Establish strong risk governance structures, including policies, committees, and escalation protocols.
- Ensure transparency and clarity regarding risk exposure, trends, and emerging risks.
- Oversee the Compliance function, ensuring adherence to applicable laws, regulations, and regulatory guidance.
- Maintain strong regulatory relationships and support regulatory examinations and audits.
- Ensure integration of compliance risk into the broader ERM framework.
- Provide executive oversight of Business Continuity and Disaster Recovery programs.
- Ensure organizational resilience through robust continuity planning, testing, and response capabilities.
- Oversee crisis management frameworks and incident response coordination.
- Oversee the Third-Party/Vendor Risk Management program, ensuring appropriate due diligence, risk assessment, and ongoing monitoring.
- Ensure compliance with regulatory expectations related to third-party risk management.
- Evaluate concentration risk, critical vendor dependencies, and operational resilience risks.
- Serve as a key leader overseeing technology-related risks, including Cybersecurity Risk, Information Security, Data Privacy & Governance, and Cloud & Third-Party Technology Risks.
- Partner with IT and Information Security leadership to ensure robust risk identification and mitigation practices.
- Ensure compliance with relevant regulatory guidance and frameworks (e.g., FFIEC guidance, NCUA expectations).
- Translate complex technical risks into clear business and executive-level insights.
- Lead, mentor, and develop a multi-functional risk team spanning ERM, Compliance, Business Continuity Planning (BCP), and Vendor Risk Management.
- Foster a strong risk culture across the organization through training, communication, and leadership.
- Serve as a trusted advisor to executive leadership on all risk-related matters.
- Collaborate cross-functionally with Finance, IT, Internal Audit, and business units.
What We Look For In You
- Bachelor's degree required; advanced degree preferred (e.g., MS in Risk Management or related field).
- 12-15+ years of progressive experience in risk management, compliance, or related fields within financial services (credit union or banking experience strongly preferred).
- 10-15 years of experience in senior leadership roles.
- Deep knowledge of enterprise risk management frameworks (e.g., COSO ERM).
- Strong understanding of NCUA regulations and supervisory expectations.
- Demonstrated expertise in Risk Appetite Frameworks & KRIs, RCSA Programs & Enterprise Risk Assessments, and Risk Governance & Reporting.
- Strategic thinker with strong execution capabilities.
- Exceptional communication and relationship management skills.
- Proven ability to build and mature risk programs within a dynamic environment.
- Strong analytical, problem-solving, and decision-making capabilities.
- High integrity and sound judgment.
- The physical demands described here are representative of those required to successfully perform the essential functions of this role. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.
- While performing the duties of this role, the employee is regularly required to sit for extended periods of time, use hands to handle objects and operate a computer, and communicate verbally and hear effectively.
- Specific vision abilities required include close vision and the ability to adjust focus.
Note: This job description is non-contractual and is not intended to be an exhaustive list of responsibilities. Duties and responsibilities may be modified or updated at any time.
Salary
This compensation range takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At SFFCU, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for the San Francisco Market is an annual salary of $156,000 to $234,000.
OUR BENEFITS
We have a competitive compensation and benefits package, but the true reward of working for SF Fire Credit Union goes beyond what you'll see on a pay-stub. We genuinely care our employees and we strive to invest in their professional and personal growth. We're a relatively small organization at about 200 employees, so you can see the impact of your efforts and the value your contributions bring to our members and fellow employees.
- 401(k) and Employer Match
- Health, Vision, Dental and Life Insurance
- Annual Incentive/Bonus Program
- Tuition Reimbursement Program
- 11 Paid Holidays + Competitive PTO package
- Home & Consumer Loan Program (Discounted Rates)
- Professional development and training programs
- On-demand personal coaching resource
- Wellness Program (Discounted Gym Membership)
"Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records."
About SF Fire Credit Union
Sourced by ZipRecruiter
Industry
Finance and insurance
Company size
51 - 200 Employees
Headquarters location
San Francisco, CA, US
Year founded
1951