Maintain vendor risk documentation and audit evidence. * Draft, review, and maintain information ... Proven ability to manage multiple priorities with strong attention to detail * Excellent ...
Maintain vendor risk documentation and audit evidence. * Draft, review, and maintain information ... Proven ability to manage multiple priorities with strong attention to detail * Excellent ...
Maintain vendor risk documentation and audit evidence. * Draft, review, and maintain information ... Proven ability to manage multiple priorities with strong attention to detail * Excellent ...
Maintain vendor risk documentation and audit evidence. * Draft, review, and maintain information ... Proven ability to manage multiple priorities with strong attention to detail * Excellent ...
Senior GRC Analyst
Westerville, OH · On-site
$92K - $121K/yr
Maintain and improve vendor risk management * Support CMMC compliance and audits * Help design and implement a data governance program * Manage security policies, standards, and updates * Partner ...
Senior GRC Analyst
Westerville, OH · On-site
$92K - $121K/yr
Maintain and improve vendor risk management * Support CMMC compliance and audits * Help design and implement a data governance program * Manage security policies, standards, and updates * Partner ...
Be Seen First
Senior Risk Management Analyst
Warren, OH · On-site
$52K - $65K/yr
Perform primary functions of Vendor Management Program including classifying vendors, performing due diligence and risk assessments on vendors, maintaining and monitoring vendor contracts and due ...
Quick apply
Be Seen First
Senior Risk Management Analyst
Warren, OH · On-site
$52K - $65K/yr
Perform primary functions of Vendor Management Program including classifying vendors, performing due diligence and risk assessments on vendors, maintaining and monitoring vendor contracts and due ...
Perform primary functions of Vendor Management Program including classifying vendors, performing due diligence and risk assessments on vendors, maintaining and monitoring vendor contracts and due ...
Perform primary functions of Vendor Management Program including classifying vendors, performing due diligence and risk assessments on vendors, maintaining and monitoring vendor contracts and due ...
Senior GRC Analyst
Westerville, OH · On-site
$92K - $121K/yr
Maintain and improve vendor risk management * Support CMMC compliance and audits * Help design and implement a data governance program * Manage security policies, standards, and updates * Partner ...
Senior GRC Analyst
Westerville, OH · On-site
$92K - $121K/yr
Maintain and improve vendor risk management * Support CMMC compliance and audits * Help design and implement a data governance program * Manage security policies, standards, and updates * Partner ...
Legal Operations Analyst
Cincinnati, OH · On-site
$35 - $40/hr
Manage the third-party vendor inventory and vendor lifecycle within OneTrust * Conduct vendor risk assessments and track remediation activities * Coordinate outreach to vendors for Data Protection ...
Legal Operations Analyst
Cincinnati, OH · On-site
$35 - $40/hr
Manage the third-party vendor inventory and vendor lifecycle within OneTrust * Conduct vendor risk assessments and track remediation activities * Coordinate outreach to vendors for Data Protection ...
Risk Management Professional - Insurance Risk
$99K - $137K/yr
Manage external broker partnerships and insurance vendors, holding partners accountable for top-tier service delivery and cutting-edge market intelligence. * Optimize the company's Total Cost of Risk ...
Risk Management Professional - Insurance Risk
$99K - $137K/yr
Manage external broker partnerships and insurance vendors, holding partners accountable for top-tier service delivery and cutting-edge market intelligence. * Optimize the company's Total Cost of Risk ...
Job Title: AI Risk Management Administrator Location: Marysville, OH, 43040 (On-site) JOB ... Support third-party and vendor AI risk reviews, including due diligence and ongoing monitoring ...
Job Title: AI Risk Management Administrator Location: Marysville, OH, 43040 (On-site) JOB ... Support third-party and vendor AI risk reviews, including due diligence and ongoing monitoring ...
001903 - Information Security Analyst
Columbus, OH · On-site
$75K - $100K/yr
Apply established risk management, governance, and compliance processes across business operations and technology initiatives. * Support all phases of the vendor risk lifecycle, including due ...
001903 - Information Security Analyst
Columbus, OH · On-site
$75K - $100K/yr
Apply established risk management, governance, and compliance processes across business operations and technology initiatives. * Support all phases of the vendor risk lifecycle, including due ...
Support and enhance the Third-Party Risk Management (TPRM) program, including conducting vendor risk assessments, reviewing security documentation, leveraging tools such as Viso Trust, and partnering ...
Support and enhance the Third-Party Risk Management (TPRM) program, including conducting vendor risk assessments, reviewing security documentation, leveraging tools such as Viso Trust, and partnering ...
Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle. * Familiarity with cloud security risk ...
Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle. * Familiarity with cloud security risk ...
Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle. * Familiarity with cloud security risk ...
Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle. * Familiarity with cloud security risk ...
Technology Risk and Controls Lead - Portfolio of Applications
Columbus, OH · On-site
$142K - $200K/yr
Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle. * Familiarity with cloud security risk ...
Technology Risk and Controls Lead - Portfolio of Applications
Columbus, OH · On-site
$142K - $200K/yr
Proficiency in third-party and vendor risk management, including due diligence, ongoing monitoring, and control assessments across the vendor lifecycle. * Familiarity with cloud security risk ...
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Assists management by overseeing day to day operations for risk adjustment programs including both prospective and retrospective, claims, vendor quality, and audits. * Develops metrics, policies, and ...
Assists management by overseeing day to day operations for risk adjustment programs including both prospective and retrospective, claims, vendor quality, and audits. * Develops metrics, policies, and ...
Assists management by overseeing day to day operations for risk adjustment programs including both prospective and retrospective, claims, vendor quality, and audits. * Develops metrics, policies, and ...
Assists management by overseeing day to day operations for risk adjustment programs including both prospective and retrospective, claims, vendor quality, and audits. * Develops metrics, policies, and ...
Vendor Risk Management information
See Ohio salary details
$41.4K - $52.1K
8% of jobs
$52.1K - $62.8K
14% of jobs
$67.7K is the 25th percentile. Wages below this are outliers.
$62.8K - $73.5K
6% of jobs
$73.5K - $84.2K
8% of jobs
$84.2K - $94.9K
11% of jobs
The median wage is $97.2K / yr.
$94.9K - $105.7K
13% of jobs
$105.7K - $116.4K
11% of jobs
$119.6K is the 75th percentile. Wages above this are outliers.
$116.4K - $127.1K
15% of jobs
$127.1K - $137.8K
8% of jobs
$137.8K - $148.5K
4% of jobs
$148.5K - $159.2K
2% of jobs
$41.4K
$98.6K
$159.2K
How much do vendor risk management jobs pay per year?
What is the highest paying risk management job?
Do risk managers make good money?
What are the key skills and qualifications needed to thrive in the Vendor Risk Management position, and why are they important?
To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.
How much does a Risk Manager get paid?
What is a Vendor Risk Management job?
A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.
What is a vendor Risk Manager?
What are some common challenges faced in a Vendor Risk Management role?
Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

Owens Corning rating
8.0
Based on 98 frontline employees who took The Breakroom Quiz
133rd of 519 rated manufacturers
Job description
The IT Security Lead - Risk Management is a critical member of the Owens Corning Global Information Services (GIS) Security team. This role supports the Governance, Risk, and Compliance (GRC) function by executing cybersecurity governance activities, performing risk assessments, maintaining security policies and standards, supporting audits, and enabling compliance across the enterprise.
This role has global responsibility for identifying, analyzing, documenting, and communicating cybersecurity risks and control gaps in support of the cybersecurity risk framework. Strong analytical skills are required to assess complex environments, identify emerging risks and inconsistencies, and translate findings into clear, actionable guidance for risk owners and leadership.
The IT Security Lead - Risk Management also supports cybersecurity compliance activities across projects, programs, facilities, and business functions. This role manages information security communications, including policies, standards, and related requirements, ensuring updates are documented, approved, and communicated in alignment with governance expectations.
Success in this role requires comfort operating in a fast-paced environment, managing multiple priorities, and adjusting to changing business needs. Curiosity, integrity, honesty, and strong attention to detail are essential, particularly when working with regulatory requirements, audit evidence, risk documentation, and enterprise reporting.
Reports to: IT Security Leader - Governance, Risk and Compliance
Span of Control:Individual Contributor
JOB RESPONSIBILITIES
Knowing Our Businesses and their Strategies
- Maintain strong awareness of evolving security standards, regulatory requirements, and industry best practices, and assess their impact on organizational risk posture and compliance obligations.
- Enable effective governance and audit readiness for Business Continuity and Disaster Recovery (BCP/DR) controls, aligned with information security, incident response, and compliance requirements.
- Identify opportunities to align security and compliance initiatives with strategic business programs (e.g., digital transformation, AI adoption, operational resilience), ensuring security is embedded as a business enabler rather than a constraint.
- Provide governance support for AI and machine-learning capabilities by maintaining and evolving security, governance, and responsible-AI policies aligned to enterprise objectives; executing AI security and risk assessments to identify control gaps and emerging risks; coordinating with Legal, Privacy, and business stakeholders to ensure alignment with regulatory, ethical, and compliance expectations; and continuously monitoring regulatory developments, industry trends, and emerging risks to inform and strengthen governance practices.
Executing Strategy
- Support enterprise cybersecurity governance and compliance efforts, including development and maintenance of information security policies, standards, procedures, and ISO 27001 ISMS documentation.
- Perform compliance and assurance activities, including internal control reviews and external audit coordination.
- Perform information security risk assessments in accordance with the cybersecurity risk framework.
- Identify control gaps, weaknesses, and emerging risks, document findings clearly and consistently.
- Support risk owners with analysis, impact statements, and documentation.
- Track and report risk remediation activities and status.
- Execute third-party security assessments aligned with vendor risk management processes.
- Document vendor risks, control gaps, and remediation actions.
- Maintain vendor risk documentation and audit evidence.
- Draft, review, and maintain information security policies, standards, procedures, and guidelines.
- Ensure policies align with ISO 27001, regulatory requirements, and internal governance standards.
- Perform ongoing control testing and monitoring activities.
- Track audit findings, remediation activities, and evidence closure.
Influencing in the Function
- Collaborate with cross-functional partners to support security and compliance requirements.
- Partner with Internal Controls, Internal Audit, and external auditors to provide evidence, documentation, and subject matter expertise.
- Engage with application and system owners to assess control effectiveness and document risk posture.
- Communicate findings clearly, distinguishing between required controls and best-practice recommendations.
- Prepare accurate, well-articulated reports on ISMS status, assessment results, and compliance metrics.
- Support documentation, publication, and communication of approved policy and control changes.
- Promote a culture of accountability, transparency, and continuous improvement within information security.
Developing Talent
- Support security awareness activities related to policy understanding and adherence.
- Mentor and coach team members to build information security knowledge, risk awareness, and governance capabilities.
- Share knowledge with a broader audience through training sessions, forums, and cross-functional engagements on information security topics.
- Proactively communicate security expectations, emerging risks, and best practices to drive awareness and adoption across the organization.
- Identify opportunities to improve documentation quality, assessment consistency, and governance processes while enabling team learning and growth.
JOB REQUIREMENTS
MINIMUM QUALIFICATIONS
- Bachelor's degree in computer science, Information Systems, Information Technology; equivalent experience may be considered in lieu of a degree
- 5+ years of information security experience
- 3+ years supporting governance, risk, and compliance functions
KNOWLEDGE, SKILLS AND ABILITIES
- Strong understanding of project and operational execution in complex environments, with a hands-on, delivery-focused approach
- Strong knowledge of security controls, data classification, regulatory requirements, and privacy standards, including working knowledge of ISO 27001
- Excellent analytical, documentation, and problem-solving skills, with the ability to translate risks into clear, actionable controls and audit evidence
- Proven ability to build trust and work effectively across a highly matrixed, global organization, engaging stakeholders with varying levels of technical expertise
- Proven ability to manage multiple priorities with strong attention to detail
- Excellent communication, organizational, and interpersonal skills Self-starter with curiosity and a continuous improvement mindset
- Service-oriented professional with high personal standards and accountability
- Working knowledge of AI governance, responsible AI principles, and emerging regulatory considerations, with the ability to translate evolving risks into practical security and compliance frameworks
- Experience supporting business continuity, disaster recovery, or operational resilience initiatives from a security or compliance perspective
- Demonstrated ability to distinguish between mandatory security requirements and best practices, and clearly articulate that distinction
- Ability to travel up to 10%, domestically
#LI-JP1
#LI-HYBRID
About Owens Corning
Owens Corning is a branded building products leader with three complementary market-leading businesses providing roofing, insulation, and doors primarily for residential markets in North America and Europe. The company operates with an integrated go-to-market strategy and a unique set of OC Advantages™ - including its iconic brand, unparalleled commercial strength, leading technology, and winning cost position - to help customers win and grow in the market. Owens Corning is committed to helping build better and achieve more through winning partnerships, leading performance, and engaging people. Founded in 1938 and headquartered in Toledo, Ohio, Owens Corning is listed on the New York Stock Exchange (NYSE: OC). For more information, visit www.owenscorning.com.
Owens Corning is an equal opportunity employer. Except in limited circumstances such as formal apprenticeship programs, Owens Corning does not employ anyone under the age of 18.
What Owens Corning employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About OWENS CORNING
Sourced by ZipRecruiter
Owens Corning (OC) develops, manufactures and markets insulation, roofing, and fiberglass composites. Global in scope and human in scale, the company's market-leading businesses use their deep expertise in materials, manufacturing and building science to develop products and systems that save energy and improve comfort in commercial and residential buildings. Through its glass reinforcements business, the company makes thousands of products lighter, stronger and more durable. Ultimately, Owens Corning people and products make the world a better place. Based in Toledo, Ohio, Owens Corning posted 2017 sales of $6.4 billion and employs 19,000 people in 37 countries. It has been a Fortune 500® company for 64 consecutive years. For more information, please visit www.owenscorning.com. A career at Owens Corning offers the ability to enhance your expertise and achieve your personal and professional aspirations. Through it all, we'll empower you with an environment that encourages open communication and big ideas, competitive pay for your performance, comprehensive benefits, and more opportunities to make your impact.
Industry
Construction materials wholesalers
Company size
10,000+ Employees
Headquarters location
Toledo, OH, US