1

Vendor Risk Manager Jobs in North Carolina (NOW HIRING)

The Risk Advisor also supports and helps drive our client's third-party risk management (TPRM) program, contributing to vendor risk assessments, escalations, and remediation across the vendor ...

The Third Party Risk Manager position will be primarily responsible for managing and leading the ... Experience working with or assessing third-party vendors and service providers * IT or ...

Compliance & Risk Management Ensure adherence to JLL and client sourcing policies, contracting ... vendor relationships. Conduct PDS Post Project Reviews to identify lessons learned and ...

next page

Showing results 1-20

Vendor Risk Manager information

See North Carolina salary details

$46.8K

$101.4K

$154.5K

How much do vendor risk manager jobs pay per year?

As of Aug 23, 2026, the average yearly pay for vendor risk manager in North Carolina is $101,382.00, according to ZipRecruiter salary data. Most workers in this role earn between $81,800.00 and $117,200.00 per year, depending on experience, location, and employer.

What is a vendor risk manager?

Vendor Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with third-party vendors that provide goods or services to an organization. They evaluate vendors’ security, compliance, and operational practices to ensure they meet the company’s standards and regulatory requirements. These managers implement frameworks to monitor vendor performance, manage contracts, and respond to potential risks or incidents. Their role is crucial in protecting the organization from financial, reputational, and regulatory harm that can arise from third-party relationships.

What are the key skills and qualifications needed to thrive as a vendor risk manager?

To thrive as a Vendor Risk Manager, you need expertise in risk assessment, third-party management, and compliance, often backed by a degree in business, finance, or a related field. Familiarity with risk management platforms, contract management tools, and certifications like Certified Third Party Risk Professional (CTPRP) are highly valuable. Strong analytical thinking, negotiation, and clear communication skills help you collaborate with vendors and internal stakeholders effectively. These skills ensure organizations can identify, mitigate, and manage risks arising from third-party relationships, safeguarding business continuity and compliance.

How does a vendor risk manager typically collaborate with other departments within an organization?

A Vendor Risk Manager works closely with departments like procurement, legal, IT, and compliance to ensure that vendors meet the organization's security and regulatory standards. This collaboration often involves reviewing contracts, assessing potential risks, and implementing mitigation strategies. Regular communication with stakeholders is essential to keep everyone informed about vendor performance and risk status, making cross-functional teamwork a key aspect of the role. Effective collaboration helps streamline risk assessments and supports informed decision-making across the business.

What is the difference between Vendor Risk Manager vs Vendor Compliance Analyst?

AspectVendor Risk ManagerVendor Compliance Analyst
CertificationsCertified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA)Certified Compliance & Ethics Professional (CCEP), Certified Regulatory Compliance Manager (CRCM)
Work EnvironmentRisk management teams, procurement, legal departmentsCompliance departments, audit teams, legal units
Industry UsageFinance, healthcare, technology, retailFinance, healthcare, manufacturing, technology
Primary FocusIdentifying, assessing, and mitigating vendor risksEnsuring vendor adherence to compliance standards and policies

The Vendor Risk Manager focuses on evaluating and mitigating risks associated with vendors, while the Vendor Compliance Analyst concentrates on ensuring vendors meet regulatory and internal compliance standards. Both roles are essential in managing vendor relationships but differ in their core responsibilities and focus areas.

What cities in North Carolina are hiring for Vendor Risk Manager jobs?

Cities in North Carolina with the most Vendor Risk Manager job openings:

Infographic showing various Vendor Risk Manager job openings in North Carolina as of August 2026, with employment types broken down into 83% Full Time, 9% Part Time, 7% Temporary, and 1% Contract. Highlights an 81% Physical, 2% Hybrid, and 17% Remote job distribution, with an average salary of $101,382 per year, or $48.7 per hour.

Full-time

Posted 25 days ago


Job description

Job Description Risk Advisor Hybrid, 3-days onsite (NYC or Charlotte office) Contract role Our client's Technology Governance, Risk & Compliance (GRC) organization is seeking a Risk Advisor to advise leadership on risk posture and tradeoffs and to lead enterprise risk assessments and treatment decisions across their business and technology functions. The Risk Advisor also supports and helps drive our client's third-party risk management (TPRM) program, contributing to vendor risk assessments, escalations, and remediation across the vendor lifecycle. Responsibilities: Advise leadership on enterprise risk posture, tradeoffs, and risk acceptance, with clear recommendations.

Identify systemic and emerging risks and influence prioritization and investment decisions. Lead risk assessments and gap assessments across business processes and technologies, from initiation through treatment planning. Own escalation of material risks, with recommendations for treatment or acceptance.

Maintain the enterprise risk register, keeping risks and response plans current. Track remediation and follow up to closure and SLA adherence. Integrate risk data into recurring reporting and metrics for leadership and risk-focused governance forums.

Support and help drive the third-party risk management program, contributing to vendor risk assessments across onboarding, reassessment, and renewal. Advise business owners and procurement on third-party risk decisions, and support escalation and remediation tracking for vendor risks. Contribute to TPRM process improvements and program maturity.

Requirements: Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, Business Administration, or a related discipline. (Equivalent experience may be considered in lieu of formal education) 7+ years in risk management, including risk leadership or advisory experience. Advanced understanding of enterprise risk management, with experience advising leadership on risk posture, tradeoffs, and acceptance.

Demonstrated experience with third-party/vendor risk assessments across the vendor lifecycle, and the ability to support and help drive a TPRM program. Strong executive communication skills, including clear risk documentation and reporting to leadership and governance forums. Working knowledge of security and risk frameworks such as NIST CSF, NIST 800-53, PCI-DSS, HIPAA, or SOC 2, applied to enterprise and third-party risk.

Familiarity with GRC and vendor risk platforms such as TruOps, Prevalent, OneTrust, ProcessUnity, or ServiceNow. Strong stakeholder management, with the ability to influence risk decisions without centralized authority. Identify opportunities to improve risk management scalability through analytics, automation, and AI.

(Preferred) CRISC, CISA, or PMI-RMP; CTPRP, CTPRA, CISM, or CISSP a plus. Experience building or maturing a third-party risk management program. Experience operating in federated, matrixed, or multi-business enterprise environments.

Familiarity with AI governance or emerging technology risk Experience supporting risk-focused governance forums or steering committees.