1

Vendor Risk Manager Jobs in Houston, TX (NOW HIRING)

Knowledge of vendor risk management practices and compliance frameworks Our Benefits: At Frost, we care about your health, your family, and your future and strive to have our benefits reflect that.

... patch management governance, IAM hygiene, security monitoring, SaaS and integration security, cyberinsurance and vendor risk reporting, secure SDLC practices, PCI DSS support, and SOC 2 Type 2 ...

Director of Risk Management Department: Risk Management Location: Houston or Dallas (Hybrid ... vendors, and operational leaders to ensure effective communication, timely claim progression, and ...

Showing results 21-40

Vendor Risk Manager information

See Houston, TX salary details

$49.2K

$106.5K

$162.3K

How much do vendor risk manager jobs pay per year?

As of Aug 9, 2026, the average yearly pay for vendor risk manager in Houston, TX is $106,483.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,900.00 and $123,100.00 per year, depending on experience, location, and employer.

What is the difference between Vendor Risk Manager vs Vendor Compliance Analyst?

AspectVendor Risk ManagerVendor Compliance Analyst
CertificationsCertified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA)Certified Compliance & Ethics Professional (CCEP), Certified Regulatory Compliance Manager (CRCM)
Work EnvironmentRisk management teams, procurement, legal departmentsCompliance departments, audit teams, legal units
Industry UsageFinance, healthcare, technology, retailFinance, healthcare, manufacturing, technology
Primary FocusIdentifying, assessing, and mitigating vendor risksEnsuring vendor adherence to compliance standards and policies

The Vendor Risk Manager focuses on evaluating and mitigating risks associated with vendors, while the Vendor Compliance Analyst concentrates on ensuring vendors meet regulatory and internal compliance standards. Both roles are essential in managing vendor relationships but differ in their core responsibilities and focus areas.

How does a vendor risk manager typically collaborate with other departments within an organization?

A Vendor Risk Manager works closely with departments like procurement, legal, IT, and compliance to ensure that vendors meet the organization's security and regulatory standards. This collaboration often involves reviewing contracts, assessing potential risks, and implementing mitigation strategies. Regular communication with stakeholders is essential to keep everyone informed about vendor performance and risk status, making cross-functional teamwork a key aspect of the role. Effective collaboration helps streamline risk assessments and supports informed decision-making across the business.

What are the key skills and qualifications needed to thrive as a vendor risk manager?

To thrive as a Vendor Risk Manager, you need expertise in risk assessment, third-party management, and compliance, often backed by a degree in business, finance, or a related field. Familiarity with risk management platforms, contract management tools, and certifications like Certified Third Party Risk Professional (CTPRP) are highly valuable. Strong analytical thinking, negotiation, and clear communication skills help you collaborate with vendors and internal stakeholders effectively. These skills ensure organizations can identify, mitigate, and manage risks arising from third-party relationships, safeguarding business continuity and compliance.

What is a vendor risk manager?

Vendor Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with third-party vendors that provide goods or services to an organization. They evaluate vendors’ security, compliance, and operational practices to ensure they meet the company’s standards and regulatory requirements. These managers implement frameworks to monitor vendor performance, manage contracts, and respond to potential risks or incidents. Their role is crucial in protecting the organization from financial, reputational, and regulatory harm that can arise from third-party relationships.
What cities near Houston, TX are hiring for Vendor Risk Manager jobs? Cities near Houston, TX with the most Vendor Risk Manager job openings:
Infographic showing various Vendor Risk Manager job openings in Houston, TX as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $106,483 per year, or $51.2 per hour.

QRM - Senior Risk Manager, Cyber (Senior Manager) - C_MAT

Deloitte

Houston, TX

Full-time

Posted 18 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

45th of 150 rated financial services


Job description

The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex business to improve financial performance and protect the firm's assets and reputation.

Work you'll do

Deloitte's Cyber QRM team is seeking a Quality & Risk Manager who will be responsible for supporting Cyber quality and risk management activities across the Cyber Offering Portfolio and Market Offerings. Candidates must have extensive experience in delivering and/or contracting for consulting services and related agreements.

Recruiting for this role ends on 08/28/2026.

Key job responsibilities include:

Guidance and Support to Senior Business Leaders within the Firm

  • Serves as liaison between firm leadership and the Office of General Counsel and others (National Risk, National Office of Independence, etc.).
  • Is responsible for advising practice leadership on potential quality and risk management issues within the Cyber Offering Portfolio that includes Cyber Strategy & Transformation, Cyber Defense & Resilience, Digital Trust & Privacy, Enterprise Security, and Cyber Operate services.
  • Provides guidance to engagement leaders and teams on risk mitigation strategies, contract formation, contract terms, and contract management for Cyber services.
  • Facilitates internal compliance with contract terms, risk management policies and procedures, and management directives for Cyber services.
  • Comfortable in facilitating risk management training to business leaders / business teams when called upon to do so for Cyber services.

Proposals for Cyber Services

  • Performs proposal reviews for Cyber opportunities.
  • Consults with firm Partners, Principals, Managing Directors, and engagement teams on Requests for Proposals (RFPs), Teaming Agreements, and Non-Disclosure Agreements.
  • Conducts Risk Consultations as needed.
  • Helps interpret contract requirements and obligations and provides guidance to engagement teams.
  • Facilitates early coordination with Office of General Counsel on RFPs where applicable.

Contract Negotiation for Cyber Services

  • Involved in the negotiation of professional services contracts with a primary focus on reducing and mitigating delivery and contractual risks associated with the services being provided.
  • Facilitates the coordination of Office of General Counsel, the business, and clients (where applicable) on contract negotiations.
  • Professional services contracts include Master Services Agreements, Managed Services Agreements, Subscription License Agreements, Statements of Work, Engagement Letters, Change Orders, Subcontractor Agreements, Teaming Agreements, Non-Disclosure Agreements, independence consultations, and other similar or related agreements.

Contract Management for Cyber Services

  • Reviews services contracts (in particular Statements of Work, Engagement Letters, and Change Orders) and provides revisions oriented to mitigating and containing risk aligned with Deloitte policies and procedures and management guidance.
  • Available to consult and help interpret requirements of the contract as aligned to the Cyber services as well as associated Master Services Agreements and Managed Services Agreements, where applicable.
  • Analyzes and assesses potential impacts associated with contract delivery risks aligned to the Cyber services.
  • Where applicable, assists business leadership with contract template development and review to help expedite future risk reviews.
  • Provides guidance to reduce in flight project risks, adjusts contract requirements to accommodate changing project circumstances, and manages stakeholder expectations to contractual obligations and agreed upon performance standards.

A successful candidate will possess these skills:

  • Significant experience in negotiating various consulting agreements as identified above.
  • Significant experience in advising business teams on developing agreements and contracts
  • Significant experience evaluating and assessing Cyber engagements across the Cyber Market Offerings
  • Experience in negotiating and managing vendor contracts (buy-side) for third-party software providers, including reseller agreements
  • Understanding of the different types of sensitive data (PII, PHI, etc.), the associated risk profile of handling each type of data, and the appropriate risk mitigation strategies to be employed
  • Ability to evaluate risks associated with large professional service engagements 
  • Experience advising engagement teams on risk matters
  • Experience in Request for Proposal analysis, including contract terms and conditions
  • Experience and ability to work directly with senior level individuals (internally and externally)
  • Strong oral and written communication skills 
  • Ability to work autonomously and handle a fast paced, multi-task environment 
  • Experience structuring and negotiating license agreements for a software business

Qualifications

Required:

  • Experience: 15+ years of Client Service delivery, direct contract negotiation, and/or relevant management experience 
  • Education: BBA/BA/BS in related field
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Education: Master's Degree is desirable

The wage range for this roletakes into accountthe wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $155,600-306,800. 

You may also be eligible toparticipatein a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends onvarious factors, including, without limitation, individual and organizational performance. 

Qualifications:

The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex business to improve financial performance and protect the firm's assets and reputation.

Work you'll do

Deloitte's Cyber QRM team is seeking a Quality & Risk Manager who will be responsible for supporting Cyber quality and risk management activities across the Cyber Offering Portfolio and Market Offerings. Candidates must have extensive experience in delivering and/or contracting for consulting services and related agreements.

Recruiting for this role ends on 08/28/2026.

Key job responsibilities include:

Guidance and Support to Senior Business Leaders within the Firm

  • Serves as liaison between firm leadership and the Office of General Counsel and others (National Risk, National Office of Independence, etc.).
  • Is responsible for advising practice leadership on potential quality and risk management issues within the Cyber Offering Portfolio that includes Cyber Strategy & Transformation, Cyber Defense & Resilience, Digital Trust & Privacy, Enterprise Security, and Cyber Operate services.
  • Provides guidance to engagement leaders and teams on risk mitigation strategies, contract formation, contract terms, and contract management for Cyber services.
  • Facilitates internal compliance with contract terms, risk management policies and procedures, and management directives for Cyber services.
  • Comfortable in facilitating risk management training to business leaders / business teams when called upon to do so for Cyber services.

Proposals for Cyber Services

  • Performs proposal reviews for Cyber opportunities.
  • Consults with firm Partners, Principals, Managing Directors, and engagement teams on Requests for Proposals (RFPs), Teaming Agreements, and Non-Disclosure Agreements.
  • Conducts Risk Consultations as needed.
  • Helps interpret contract requirements and obligations and provides guidance to engagement teams.
  • Facilitates early coordination with Office of General Counsel on RFPs where applicable.

Contract Negotiation for Cyber Services

  • Involved in the negotiation of professional services contracts with a primary focus on reducing and mitigating delivery and contractual risks associated with the services being provided.
  • Facilitates the coordination of Office of General Counsel, the business, and clients (where applicable) on contract negotiations.
  • Professional services contracts include Master Services Agreements, Managed Services Agreements, Subscription License Agreements, Statements of Work, Engagement Letters, Change Orders, Subcontractor Agreements, Teaming Agreements, Non-Disclosure Agreements, independence consultations, and other similar or related agreements.

Contract Management for Cyber Services

  • Reviews services contracts (in particular Statements of Work, Engagement Letters, and Change Orders) and provides revisions oriented to mitigating and containing risk aligned with Deloitte policies and procedures and management guidance.
  • Available to consult and help interpret requirements of the contract as aligned to the Cyber services as well as associated Master Services Agreements and Managed Services Agreements, where applicable.
  • Analyzes and assesses potential impacts associated with contract delivery risks aligned to the Cyber services.
  • Where applicable, assists business leadership with contract template development and review to help expedite future risk reviews.
  • Provides guidance to reduce in flight project risks, adjusts contract requirements to accommodate changing project circumstances, and manages stakeholder expectations to contractual obligations and agreed upon performance standards.

A successful candidate will possess these skills:

  • Significant experience in negotiating various consulting agreements as identified above.
  • Significant experience in advising business teams on developing agreements and contracts
  • Significant experience evaluating and assessing Cyber engagements across the Cyber Market Offerings
  • Experience in negotiating and managing vendor contracts (buy-side) for third-party software providers, including reseller agreements
  • Understanding of the different types of sensitive data (PII, PHI, etc.), the associated risk profile of handling each type of data, and the appropriate risk mitigation strategies to be employed
  • Ability to evaluate risks associated with large professional service engagements 
  • Experience advising engagement teams on risk matters
  • Experience in Request for Proposal analysis, including contract terms and conditions
  • Experience and ability to work directly with senior level individuals (internally and externally)
  • Strong oral and written communication skills 
  • Ability to work autonomously and handle a fast paced, multi-task environment 
  • Experience structuring and negotiating license agreements for a software business

Qualifications

Required:

  • Experience: 15+ years of Client Service delivery, direct contract negotiation, and/or relevant management experience 
  • Education: BBA/BA/BS in related field
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Preferred:

  • Education: Master's Degree is desirable

The wage range for this roletakes into accountthe wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $155,600-306,800. 

You may also be eligible toparticipatein a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends onvarious factors, including, without limitation, individual and organizational performance. 

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom