1

Vendor Risk Manager Jobs in Boston, MA (NOW HIRING)

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

Contribute to vendor and third-party risk management, ensuring Reco's supply chain meets our own ... security bar. Identity and Access Management * Partner with IT and Engineering to maintain role ...

Security Engineer (Boston HQ)

Boston, MA · On-site

$80K - $110K/yr

Reporting to the Director of Information Security & Risk Management, you will be a core member of a ... Conduct vendor and third-party risk assessments using the firm's third-party assessment tool.

Security Engineer (Boston HQ)

Boston, MA · On-site

$80K - $110K/yr

Reporting to the Director of Information Security & Risk Management, you will be a core member of a ... Conduct vendor and third-party risk assessments using the firm's third-party assessment tool.

Showing results 41-60

Vendor Risk Manager information

See Boston, MA salary details

$54.3K

$117.6K

$179.2K

How much do vendor risk manager jobs pay per year?

As of Aug 11, 2026, the average yearly pay for vendor risk manager in Boston, MA is $117,578.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,900.00 and $136,000.00 per year, depending on experience, location, and employer.

What is the difference between Vendor Risk Manager vs Vendor Compliance Analyst?

AspectVendor Risk ManagerVendor Compliance Analyst
CertificationsCertified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA)Certified Compliance & Ethics Professional (CCEP), Certified Regulatory Compliance Manager (CRCM)
Work EnvironmentRisk management teams, procurement, legal departmentsCompliance departments, audit teams, legal units
Industry UsageFinance, healthcare, technology, retailFinance, healthcare, manufacturing, technology
Primary FocusIdentifying, assessing, and mitigating vendor risksEnsuring vendor adherence to compliance standards and policies

The Vendor Risk Manager focuses on evaluating and mitigating risks associated with vendors, while the Vendor Compliance Analyst concentrates on ensuring vendors meet regulatory and internal compliance standards. Both roles are essential in managing vendor relationships but differ in their core responsibilities and focus areas.

How does a vendor risk manager typically collaborate with other departments within an organization?

A Vendor Risk Manager works closely with departments like procurement, legal, IT, and compliance to ensure that vendors meet the organization's security and regulatory standards. This collaboration often involves reviewing contracts, assessing potential risks, and implementing mitigation strategies. Regular communication with stakeholders is essential to keep everyone informed about vendor performance and risk status, making cross-functional teamwork a key aspect of the role. Effective collaboration helps streamline risk assessments and supports informed decision-making across the business.

What are the key skills and qualifications needed to thrive as a vendor risk manager?

To thrive as a Vendor Risk Manager, you need expertise in risk assessment, third-party management, and compliance, often backed by a degree in business, finance, or a related field. Familiarity with risk management platforms, contract management tools, and certifications like Certified Third Party Risk Professional (CTPRP) are highly valuable. Strong analytical thinking, negotiation, and clear communication skills help you collaborate with vendors and internal stakeholders effectively. These skills ensure organizations can identify, mitigate, and manage risks arising from third-party relationships, safeguarding business continuity and compliance.

What is a vendor risk manager?

Vendor Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with third-party vendors that provide goods or services to an organization. They evaluate vendors’ security, compliance, and operational practices to ensure they meet the company’s standards and regulatory requirements. These managers implement frameworks to monitor vendor performance, manage contracts, and respond to potential risks or incidents. Their role is crucial in protecting the organization from financial, reputational, and regulatory harm that can arise from third-party relationships.
What cities near Boston, MA are hiring for Vendor Risk Manager jobs? Cities near Boston, MA with the most Vendor Risk Manager job openings:
Infographic showing various Vendor Risk Manager job openings in Boston, MA as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 13% Part Time, and 2% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $117,578 per year, or $56.5 per hour.

Customer Trust Lead

Emburse

Boston, MA • On-site

Full-time

Re-posted 18 days ago


Job description

Who We Are:
At Emburse, you'll not just imagine the future - you'll build it. As a leader in travel and expense solutions, we are creating a future where technology drives business value and inspires extraordinary results. Our AI-powered platform helps organizations modernize financial operations, increase visibility, and optimize spend across the enterprise.
Join our team as the internal authority on security and compliance representation - and the organization's credible, knowledgeable face to enterprise buyers, procurement teams, and third-party risk functions.
The Customer Trust Lead is a specialized individual contributor responsible for managing Emburse's customer-facing security and compliance due diligence function, supporting the full breadth of Emburse's customer-facing organization - including all Customer Success Managers, Extended Services, Client Sales and Installations teams - and serving as a critical enabler of the renewal cycle. The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products.
Emburse is an industry leader specializing in Financial SaaS software including Expense and Accounts Payable (AP) Reporting and Management.
What You'll Do:
  • Own end-to-end response for all inbound security questionnaires, DDQs, and vendor risk assessments across new business, renewals, Extended Services engagements, and Installations - supporting the full customer-facing organization via RFPIO
  • Maintain and continuously improve a high-quality content library in RFPIO and SafeBase that reflects current, accurate, and approved Emburse positions across all 14 products
  • Triage all inbound requests to confirm scope, route non-security requests appropriately with documented rationale, and manage response SLAs with proactive communication; escalate blockers including unanswerable questions and policy gaps
  • Serve as the internal subject matter expert on Emburse's security and compliance posture across frameworks including SOC 2, ISO 27001, NIST 800-171, CSA CAIQ, GDPR, CCPA, and others required by the customer base, in direct liaison with the CISO and DPO
  • Translate complex technical and compliance concepts into clear, accurate, customer-facing language calibrated to the audience, staying current on Emburse's certifications, audit outcomes, policy changes, and product-level control updates across all products
  • Partner with Security, Legal, and Product teams to validate responses, identify gaps, and ensure nothing is overstated or misrepresented
  • Co-manage and maintain Emburse's SafeBase Trust Center as the primary self-service destination for customer security inquiries, keeping content current and aligned with the RFPIO content library
  • Drive SafeBase adoption among customers and CSMs to reduce inbound DDQ volume for requests that can be self-served, and identify content gaps based on recurring questionnaire themes
  • Enforce intake governance: maintain and apply routing guides, SLA tiers, and scope definitions; document and track reason codes for out-of-scope requests, declined engagements, and escalations
  • Maintain accurate records of all engagements for pipeline visibility and capacity planning, and contribute to policies governing non-standard intake methods, including customer requests for portal-based vendor risk platform access

What We're Looking For:
  • 5+ years in information security compliance, vendor risk, customer trust, or a closely related function
  • Demonstrated working knowledge of SOC 2, ISO 27001, NIST 800-53, SCCs, SIG, CSA CAIQ, GDPR, and CCPA
  • Experience managing high-volume security questionnaire or DDQ workflows, ideally in a SaaS environment
  • Exceptional written communication skills - precise, defensible, and audience-aware
  • Proficiency with RFPIO or a comparable questionnaire automation platform
  • Strong organization skills and ability to manage a large concurrent workload independently
  • Experience administering or contributing to a Trust Center platform (SafeBase, Vanta, Drata, OneTrust, Whistic, or similar) is preferred, but not required
  • Familiarity with public sector or regulated industry requirements (FedRAMP, StateRAMP, CMMC) is preferred, but not required
  • Background in T&E, fintech, or multi-product SaaS is preferred, but not required

Why Emburse?
Finance is changing-and at Emburse, we're leading the way. Our AI-powered solutions help organizations eliminate inefficiencies, gain real-time visibility, and optimize spend-so they can focus on what's next, not what's slowing them down.
  • A Company with Momentum - We serve 12M+ users across 120 countries, helping businesses modernize their finance operations.
  • A Team That Innovates - Work alongside some of the brightest minds in finance, tech, and AI to solve real-world challenges.
  • A Culture That Empowers - Competitive pay, flexible work, and an inclusive, collaborative environment that supports your success.
  • A Career That Matters - Your work here drives efficiency, innovation, and smarter financial decision-making for businesses everywhere.

$78,600 - $95,000 a year
Shape your future & find what's next at Emburse.
Emburse provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Emburse complies with applicable state and local laws governing nondiscrimination in employment in every location where the company has facilities. This policy applies to all terms and conditions of employment.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.