1

Vendor Risk Management Jobs in Portland, OR (NOW HIRING)

... management, workflow, and communication platforms. * Conduct risk-based reviews and analysis of proposed projects, vendors, and issue remediation efforts, and provide recommendations for ...

... vendors), risk management, financial management, procurement, and logistical coordination. Project Managers are involved with subcontractor/ vendor management, and coordinate activities with ...

next page

Showing results 1-20

Vendor Risk Management information

See Portland, OR salary details

$46.1K

$110K

$177.6K

How much do vendor risk management jobs pay per year?

As of Aug 22, 2026, the average yearly pay for vendor risk management in Portland, OR is $109,979.00, according to ZipRecruiter salary data. Most workers in this role earn between $76,900.00 and $140,000.00 per year, depending on experience, location, and employer.

What is vendor risk management?

A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.

What are some common challenges faced in vendor risk management?

Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

What are the key skills and qualifications needed to thrive in vendor risk management?

To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.

How to do vendor risk management?

Vendor risk management involves identifying, assessing, and mitigating risks associated with third-party vendors to ensure they meet security, compliance, and performance standards. It typically includes conducting due diligence, evaluating vendor controls, and monitoring ongoing performance using tools like risk assessment frameworks and audits. Strong communication and documentation are essential for effective management.

What does a vendor risk management do?

A vendor risk management professional assesses and monitors the risks associated with third-party vendors to ensure compliance, security, and operational integrity. They evaluate vendor security practices, contractual obligations, and potential vulnerabilities, often using risk assessment tools and frameworks to mitigate potential threats to the organization.

What are the most commonly searched types of Vendor Risk Management jobs in Portland, OR?

The most popular types of Vendor Risk Management jobs in Portland, OR are:

What are popular job titles related to Vendor Risk Management jobs in Portland, OR?

For Vendor Risk Management jobs in Portland, OR, the most frequently searched job titles are:

What job categories do people searching Vendor Risk Management jobs in Portland, OR look for?

The top searched job categories for Vendor Risk Management jobs in Portland, OR are:

What cities near Portland, OR are hiring for Vendor Risk Management jobs?

Cities near Portland, OR with the most Vendor Risk Management job openings:

Infographic showing various Vendor Risk Management job openings in Portland, OR as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 14% Part Time, and 3% Contract. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $109,979 per year, or $52.9 per hour.

Third-Party Risk Management Program Officer

Heritage Bank NW

Hillsboro, OR • On-site

$100.88 - $151.33/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

Third-Party Risk Management Program Officer

Heritage Bank is seeking a Third-Party Risk Management Program Officer to join the Risk and Compliance team. The officer will design, execute, and continuously improve the bank’s third‑party risk management program across the full vendor lifecycle, from onboarding through offboarding.

The role operates within the Second Line of Defense (2LoD) and provides governance and oversight to ensure operational alignment of the bank’s third‑party risk management processes across Information Security, Legal, Procurement, Business Units, and Internal Audit.

Key responsibilities include ensuring third‑party risks—cybersecurity, operational, compliance, reputational, and concentration risks—are appropriately identified, assessed, and monitored in alignment with regulatory expectations.

Geographic locations:

  • Tacoma, WA
  • Seattle, WA
  • Spokane, WA
  • Portland, OR

Base Salary Range: $100,884.00 - $126,105.00 - $151,326.00 annual

The Role at a Glance
  • Leads and manages the Third-Party Risk Management (TPRM) Program, including development and continuous refinement of policies, procedures, risk tiering, segmentation models, risk rating methodologies, and vendor lifecycle control checkpoints.
  • Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks.
  • Oversees execution of inherent risk assessments, due diligence reviews, and control assessments across all third‑party risk domains (cybersecurity, privacy, operational resilience, etc.).
  • Ensures appropriate engagement of cross‑functional subject matter experts and that roles and responsibilities are clearly defined within established processes.
  • Defines and maintains program tools, templates, escalation protocols, and residual risk acceptance processes.
  • Integrates and aligns TPRM program with related programs (Vendor Management, procurement, Business Continuity Planning, Information Security Risk Assessments, Cloud Governance, AI/Model Risk).
  • Establishes and tracks key risk indicators (KRIs).
  • Provides executive‑level reporting on third‑party risk posture, program maturity, and systemic exposures (e.g., concentration risk, critical service dependency).
  • Monitors and escalates open risk issues, overdue assessments, and policy exceptions.
  • Serves as the primary contact for regulatory exams and internal/external audits related to third‑party risk.
  • Performs continuous monitoring of Critical and High risk third parties.
  • Maintains audit‑ready documentation, evidence of program execution, and continuous improvement roadmap.
  • Monitors regulatory changes (OCC Bulletins, FFIEC updates, DORA, NYDFS, etc.) and updates program controls to align with evolving requirements.
Core Skills and Qualifications
  • Bachelor’s degree in Business, Risk Management, Information Security or related field preferred.
  • 5+ years of recent experience in vendor risk management, third‑party oversight, or enterprise risk program role within a financial services environment required.
  • Proven experience leading the development, implementation, and ongoing management of an enterprise‑scale third‑party risk management program.
  • Professional certifications such as CISA, CRISC, or equivalent preferred.
  • Equivalent combination of education, training, certifications, and/or relevant work experience may be considered.
  • Exceptional service orientation for internal and external customers, with ability to build and maintain positive, professional relationships across all levels of management and functional areas.
  • Highly effective listening, verbal, written, and telephone etiquette with strong questioning, negotiation, and presentation skills.
  • Strategic approach to program design, problem solving, and decision‑making with ability to focus on key issues under time pressure.
  • Risk‑based mindset with strong analytical and critical thinking skills; ability to independently assess risk decisions and challenge assumptions.
  • Comprehensive knowledge of regulatory frameworks (FFIEC, GLBA, PCI‑DSS, SOX, HIPAA, etc.) and standards (NIST CSF, ISO 27001, COBIT, COSO, vendor risk management frameworks).
  • Strong knowledge of information security assessment, auditing practices, and ability to evaluate technical and business controls using established frameworks.
  • Knowledge of statutory banking compliance regulations issued by FDIC, FinCEN, Federal Reserve Board, and privacy laws (GLBA, SOX).
  • Excellent project management, planning, organization, time management, and follow‑up skills, with a strong sense of urgency and ability to execute quickly and efficiently.
  • Unquestionable integrity in handling sensitive and confidential information.
  • Proficient use of MS Office (Word, Excel, Outlook) and ability to learn new technologies quickly.
  • Proficient use of third‑party risk management software (e.g., UpGuard, Tandem, Gartner).
Work Environment / Conditions
  • Climate controlled office environment.
  • Work involves concentrating on tasks amid occasional distractions and frequent employee/customer contacts and interruptions.
Physical Demands / Effort
  • Constant use of computer screens, reading reports, and sitting throughout the day.
  • Operating a computer keyboard, multi‑line telephone, photocopier, scanner, and fax machine requiring dexterity of hands and fingers.
  • Typically sitting at a desk or table; occasional standing, stooping, bending, walking, climbing, kneeling or crouching to file materials.
  • Occasional lifting up to 20 lbs. (files, boxes, etc.).

At Heritage Bank, you’ll enjoy a total rewards package that includes a base salary based on role, experience, and skill set, along with an exceptional benefits package—medical, dental, vision, life insurance, 401(k), community volunteer time—and generous time‑off policy. Full‑time team members receive a minimum of ten paid vacation days annually (pro‑rated from start date and/or hours worked) and eight hours of paid sick leave per month, along with eleven paid holidays each calendar year and an annual float day.

Heritage Bank is an Equal Opportunity Employer

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other basis protected by applicable law.

Job applicants have certain legal rights. Please click for information regarding these rights.

If you need assistance completing the online application, please email HBRecruiting@HeritageBankNW.com.

Salary Range Disclaimer

The base salary range represents Heritage Bank’s current salary range for the position. Actual salaries will vary depending on qualifications, experience, and job performance. The range listed is one component of the total compensation package for full‑time and part‑time employees. Depending on position, other total compensation rewards may include monthly, quarterly, or annual incentive and/or bonuses.

#J-18808-Ljbffr