The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and ... Experience in negotiating and managing vendor contracts (buy-side) for third-party software ...
The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and ... Experience in negotiating and managing vendor contracts (buy-side) for third-party software ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
In this role, you will apply your expertise in IT governance, risk management, and compliance to ... Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
In this role, you will apply your expertise in IT governance, risk management, and compliance to ... Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ...
In this role, you will apply your expertise in IT governance, risk management, and compliance to ... Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ...
In this role, you will apply your expertise in IT governance, risk management, and compliance to ... Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ...
Coordinate and manage third-party vendor risk governance activities, including vendor SOC and Enhanced Information Risk Review * Lead AI Clearinghouse operations and strategic initiatives, including ...
Coordinate and manage third-party vendor risk governance activities, including vendor SOC and Enhanced Information Risk Review * Lead AI Clearinghouse operations and strategic initiatives, including ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
In this role, you will apply your expertise in IT governance, risk management, and compliance to ... Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ...
Quick apply
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
In this role, you will apply your expertise in IT governance, risk management, and compliance to ... Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment ...
Global Cybersecurity Director - Risk & Compliance
Washington, DC · On-site
Medical
Dental
Vision
Retirement
PTO
Lead cybersecurity review of federal contracts, RFPs, client opportunities, software approvals, cloud service reviews, and third-party vendor risk management to support secure technology adoption.
Global Cybersecurity Director - Risk & Compliance
Washington, DC · On-site
Medical
Dental
Vision
Retirement
PTO
Lead cybersecurity review of federal contracts, RFPs, client opportunities, software approvals, cloud service reviews, and third-party vendor risk management to support secure technology adoption.
Senior Associate, Claims & Risk Management
Falls Church, VA · On-site
$77K - $112K/yr
Medical
Dental
Vision
Retirement
This position reports to Senior Manager, Claims & Risk Management in the Insurance & Risk ... Participate in interviews with prospective attorneys and vendors; update and maintain list of ...
Senior Associate, Claims & Risk Management
Falls Church, VA · On-site
$77K - $112K/yr
Medical
Dental
Vision
Retirement
This position reports to Senior Manager, Claims & Risk Management in the Insurance & Risk ... Participate in interviews with prospective attorneys and vendors; update and maintain list of ...
Senior Associate, Claims & Risk Management
Falls Church, VA · On-site
$77K - $112K/yr
Medical
Dental
Vision
Retirement
This position reports to Senior Manager, Claims & Risk Management in the Insurance & Risk ... vendors; update and maintain list of approved attorneys and vendors Insurance Claims Program ...
Senior Associate, Claims & Risk Management
Falls Church, VA · On-site
$77K - $112K/yr
Medical
Dental
Vision
Retirement
This position reports to Senior Manager, Claims & Risk Management in the Insurance & Risk ... vendors; update and maintain list of approved attorneys and vendors Insurance Claims Program ...
Senior Associate, Claims & Risk Management
Falls Church, VA · On-site
$77K - $112K/yr
Medical
Dental
Vision
Retirement
This position reports to Senior Manager, Claims & Risk Management in the Insurance & Risk ... Participate in interviews with prospective attorneys and vendors; update and maintain list of ...
Senior Associate, Claims & Risk Management
Falls Church, VA · On-site
$77K - $112K/yr
Medical
Dental
Vision
Retirement
This position reports to Senior Manager, Claims & Risk Management in the Insurance & Risk ... Participate in interviews with prospective attorneys and vendors; update and maintain list of ...
ICBA PAYMENTS - SPECIALIST, RISK OPERATIONS
Washington, DC · On-site
$55K - $75K/yr
Retirement
The Specialist, Risk Operations is responsible for managing the operations lifecycle of bank customer and vendor contracts/agreements, maintaining accurate operational and risk-related records, and ...
ICBA PAYMENTS - SPECIALIST, RISK OPERATIONS
Washington, DC · On-site
$55K - $75K/yr
Retirement
The Specialist, Risk Operations is responsible for managing the operations lifecycle of bank customer and vendor contracts/agreements, maintaining accurate operational and risk-related records, and ...
ICBA PAYMENTS - SPECIALIST, RISK OPERATIONS
Washington, DC · Hybrid
$55K - $75K/yr
Retirement
The Specialist, Risk Operations is responsible for managing the operations lifecycle of bank customer and vendor contracts/agreements, maintaining accurate operational and risk-related records, and ...
ICBA PAYMENTS - SPECIALIST, RISK OPERATIONS
Washington, DC · Hybrid
$55K - $75K/yr
Retirement
The Specialist, Risk Operations is responsible for managing the operations lifecycle of bank customer and vendor contracts/agreements, maintaining accurate operational and risk-related records, and ...
Senior Vendor Program Analyst
$131K - $131K/yr
... management with Enterprise third parties to ensure compliance across Legal, IT, and Risk teams ... It fills a need for ownership and representation on enterprise vendors that have no sole business ...
Senior Vendor Program Analyst
$131K - $131K/yr
... management with Enterprise third parties to ensure compliance across Legal, IT, and Risk teams ... It fills a need for ownership and representation on enterprise vendors that have no sole business ...
Risk and Insurance Manager - Real Estate/Multi-Family Property Management
Gaithersburg, MD · On-site
$100 - $120/hr
Medical
PTO
Review contracts, RFPs, bids, and vendor agreements to ensure appropriate insurance and risk ... Manager), or CSP (Certified Safety Professional) are preferred. Legal or paralegal experience is a ...
New
Risk and Insurance Manager - Real Estate/Multi-Family Property Management
Gaithersburg, MD · On-site
$100 - $120/hr
Medical
PTO
Review contracts, RFPs, bids, and vendor agreements to ensure appropriate insurance and risk ... Manager), or CSP (Certified Safety Professional) are preferred. Legal or paralegal experience is a ...
New
Manage the end-to-end CTRPP operational lifecycle, including vendor inherent risk rating, due diligence assessments and ongoing monitoring. * Serve as the primary escalation point for complex risk ...
Manage the end-to-end CTRPP operational lifecycle, including vendor inherent risk rating, due diligence assessments and ongoing monitoring. * Serve as the primary escalation point for complex risk ...
Manage the end-to-end CTRPP operational lifecycle, including vendor inherent risk rating, due diligence assessments and ongoing monitoring. * Serve as the primary escalation point for complex risk ...
Manage the end-to-end CTRPP operational lifecycle, including vendor inherent risk rating, due diligence assessments and ongoing monitoring. * Serve as the primary escalation point for complex risk ...
Integrate, oversee, manage and deliver the annual operational risk work program for the WBG ... external vendors, suppliers, and third parties who provide critical services or products ...
New
Integrate, oversee, manage and deliver the annual operational risk work program for the WBG ... external vendors, suppliers, and third parties who provide critical services or products ...
New
... audit findings, vendor risk, and resilience needs, then connecting those priorities to RSM ... Forecast and manage the cyber and risk consulting pipeline, including opportunity sizing ...
... audit findings, vendor risk, and resilience needs, then connecting those priorities to RSM ... Forecast and manage the cyber and risk consulting pipeline, including opportunity sizing ...
Senior Contract Analyst
Rockville, MD · Hybrid
$89K - $118K/yr
Medical
Life
Retirement
PTO
The Senior Contract Analyst serves as a key partner within the Risk Management Division, providing expertise throughout the contract lifecycle, including contract review, negotiation support, vendor ...
Senior Contract Analyst
Rockville, MD · Hybrid
$89K - $118K/yr
Medical
Life
Retirement
PTO
The Senior Contract Analyst serves as a key partner within the Risk Management Division, providing expertise throughout the contract lifecycle, including contract review, negotiation support, vendor ...
Senior Contract Analyst
Rockville, MD · Hybrid
$89K - $118K/yr
Medical
Life
Retirement
PTO
The Senior Contract Analyst serves as a key partner within the Risk Management Division, providing expertise throughout the contract lifecycle, including contract review, negotiation support, vendor ...
Senior Contract Analyst
Rockville, MD · Hybrid
$89K - $118K/yr
Medical
Life
Retirement
PTO
The Senior Contract Analyst serves as a key partner within the Risk Management Division, providing expertise throughout the contract lifecycle, including contract review, negotiation support, vendor ...
Procurement Manager
Washington, DC · On-site
$130K - $160K/yr
Implement audit and automation controls. 6. Partner with Risk Management on Vendor Risk & Third-Party Management * Collaborate with TPRM to support vendor due diligence across financial, operational ...
Quick apply
Procurement Manager
Washington, DC · On-site
$130K - $160K/yr
Implement audit and automation controls. 6. Partner with Risk Management on Vendor Risk & Third-Party Management * Collaborate with TPRM to support vendor due diligence across financial, operational ...
Vendor Risk Manager information
See Washington, DC salary details
$58.1K - $70.3K
4% of jobs
$70.3K - $82.4K
6% of jobs
$82.4K - $94.6K
11% of jobs
$99.1K is the 25th percentile. Wages below this are outliers.
$94.6K - $106.7K
11% of jobs
The median wage is $116.4K / yr.
$106.7K - $118.9K
23% of jobs
$118.9K - $131K
13% of jobs
$139.1K is the 75th percentile. Wages above this are outliers.
$131K - $143.2K
12% of jobs
$143.2K - $155.4K
8% of jobs
$155.4K - $167.5K
6% of jobs
$167.5K - $179.7K
4% of jobs
$179.7K - $191.8K
2% of jobs
$58.1K
$125.9K
$191.8K
How much do vendor risk manager jobs pay per year?
What is a vendor risk manager?
What are the key skills and qualifications needed to thrive as a vendor risk manager?
How does a vendor risk manager typically collaborate with other departments within an organization?
What is the difference between Vendor Risk Manager vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Manager | Vendor Compliance Analyst |
|---|---|---|
| Certifications | Certified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA) | Certified Compliance & Ethics Professional (CCEP), Certified Regulatory Compliance Manager (CRCM) |
| Work Environment | Risk management teams, procurement, legal departments | Compliance departments, audit teams, legal units |
| Industry Usage | Finance, healthcare, technology, retail | Finance, healthcare, manufacturing, technology |
| Primary Focus | Identifying, assessing, and mitigating vendor risks | Ensuring vendor adherence to compliance standards and policies |
The Vendor Risk Manager focuses on evaluating and mitigating risks associated with vendors, while the Vendor Compliance Analyst concentrates on ensuring vendors meet regulatory and internal compliance standards. Both roles are essential in managing vendor relationships but differ in their core responsibilities and focus areas.

Full-time
Posted 27 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
44th of 150 rated financial services
Job description
The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex business to improve financial performance and protect the firm's assets and reputation.
Work you'll do
Deloitte's Cyber QRM team is seeking a Quality & Risk Manager who will be responsible for supporting Cyber quality and risk management activities across the Cyber Offering Portfolio and Market Offerings. Candidates must have extensive experience in delivering and/or contracting for consulting services and related agreements.
Recruiting for this role ends on 08/28/2026.
Key job responsibilities include:
Guidance and Support to Senior Business Leaders within the Firm
- Serves as liaison between firm leadership and the Office of General Counsel and others (National Risk, National Office of Independence, etc.).
- Is responsible for advising practice leadership on potential quality and risk management issues within the Cyber Offering Portfolio that includes Cyber Strategy & Transformation, Cyber Defense & Resilience, Digital Trust & Privacy, Enterprise Security, and Cyber Operate services.
- Provides guidance to engagement leaders and teams on risk mitigation strategies, contract formation, contract terms, and contract management for Cyber services.
- Facilitates internal compliance with contract terms, risk management policies and procedures, and management directives for Cyber services.
- Comfortable in facilitating risk management training to business leaders / business teams when called upon to do so for Cyber services.
Proposals for Cyber Services
- Performs proposal reviews for Cyber opportunities.
- Consults with firm Partners, Principals, Managing Directors, and engagement teams on Requests for Proposals (RFPs), Teaming Agreements, and Non-Disclosure Agreements.
- Conducts Risk Consultations as needed.
- Helps interpret contract requirements and obligations and provides guidance to engagement teams.
- Facilitates early coordination with Office of General Counsel on RFPs where applicable.
Contract Negotiation for Cyber Services
- Involved in the negotiation of professional services contracts with a primary focus on reducing and mitigating delivery and contractual risks associated with the services being provided.
- Facilitates the coordination of Office of General Counsel, the business, and clients (where applicable) on contract negotiations.
- Professional services contracts include Master Services Agreements, Managed Services Agreements, Subscription License Agreements, Statements of Work, Engagement Letters, Change Orders, Subcontractor Agreements, Teaming Agreements, Non-Disclosure Agreements, independence consultations, and other similar or related agreements.
Contract Management for Cyber Services
- Reviews services contracts (in particular Statements of Work, Engagement Letters, and Change Orders) and provides revisions oriented to mitigating and containing risk aligned with Deloitte policies and procedures and management guidance.
- Available to consult and help interpret requirements of the contract as aligned to the Cyber services as well as associated Master Services Agreements and Managed Services Agreements, where applicable.
- Analyzes and assesses potential impacts associated with contract delivery risks aligned to the Cyber services.
- Where applicable, assists business leadership with contract template development and review to help expedite future risk reviews.
- Provides guidance to reduce in flight project risks, adjusts contract requirements to accommodate changing project circumstances, and manages stakeholder expectations to contractual obligations and agreed upon performance standards.
A successful candidate will possess these skills:
- Significant experience in negotiating various consulting agreements as identified above.
- Significant experience in advising business teams on developing agreements and contracts
- Significant experience evaluating and assessing Cyber engagements across the Cyber Market Offerings
- Experience in negotiating and managing vendor contracts (buy-side) for third-party software providers, including reseller agreements
- Understanding of the different types of sensitive data (PII, PHI, etc.), the associated risk profile of handling each type of data, and the appropriate risk mitigation strategies to be employed
- Ability to evaluate risks associated with large professional service engagements
- Experience advising engagement teams on risk matters
- Experience in Request for Proposal analysis, including contract terms and conditions
- Experience and ability to work directly with senior level individuals (internally and externally)
- Strong oral and written communication skills
- Ability to work autonomously and handle a fast paced, multi-task environment
- Experience structuring and negotiating license agreements for a software business
Qualifications
Required:
- Experience: 15+ years of Client Service delivery, direct contract negotiation, and/or relevant management experience
- Education: BBA/BA/BS in related field
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Education: Master's Degree is desirable
The wage range for this roletakes into accountthe wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $155,600-$306,800.
You may also be eligible toparticipatein a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends onvarious factors, including, without limitation, individual and organizational performance.
Qualifications:The Team: The mission of Quality and Risk Management (QRM) is to manage the risk in our growing and increasingly complex business to improve financial performance and protect the firm's assets and reputation.
Work you'll do
Deloitte's Cyber QRM team is seeking a Quality & Risk Manager who will be responsible for supporting Cyber quality and risk management activities across the Cyber Offering Portfolio and Market Offerings. Candidates must have extensive experience in delivering and/or contracting for consulting services and related agreements.
Recruiting for this role ends on 08/28/2026.
Key job responsibilities include:
Guidance and Support to Senior Business Leaders within the Firm
- Serves as liaison between firm leadership and the Office of General Counsel and others (National Risk, National Office of Independence, etc.).
- Is responsible for advising practice leadership on potential quality and risk management issues within the Cyber Offering Portfolio that includes Cyber Strategy & Transformation, Cyber Defense & Resilience, Digital Trust & Privacy, Enterprise Security, and Cyber Operate services.
- Provides guidance to engagement leaders and teams on risk mitigation strategies, contract formation, contract terms, and contract management for Cyber services.
- Facilitates internal compliance with contract terms, risk management policies and procedures, and management directives for Cyber services.
- Comfortable in facilitating risk management training to business leaders / business teams when called upon to do so for Cyber services.
Proposals for Cyber Services
- Performs proposal reviews for Cyber opportunities.
- Consults with firm Partners, Principals, Managing Directors, and engagement teams on Requests for Proposals (RFPs), Teaming Agreements, and Non-Disclosure Agreements.
- Conducts Risk Consultations as needed.
- Helps interpret contract requirements and obligations and provides guidance to engagement teams.
- Facilitates early coordination with Office of General Counsel on RFPs where applicable.
Contract Negotiation for Cyber Services
- Involved in the negotiation of professional services contracts with a primary focus on reducing and mitigating delivery and contractual risks associated with the services being provided.
- Facilitates the coordination of Office of General Counsel, the business, and clients (where applicable) on contract negotiations.
- Professional services contracts include Master Services Agreements, Managed Services Agreements, Subscription License Agreements, Statements of Work, Engagement Letters, Change Orders, Subcontractor Agreements, Teaming Agreements, Non-Disclosure Agreements, independence consultations, and other similar or related agreements.
Contract Management for Cyber Services
- Reviews services contracts (in particular Statements of Work, Engagement Letters, and Change Orders) and provides revisions oriented to mitigating and containing risk aligned with Deloitte policies and procedures and management guidance.
- Available to consult and help interpret requirements of the contract as aligned to the Cyber services as well as associated Master Services Agreements and Managed Services Agreements, where applicable.
- Analyzes and assesses potential impacts associated with contract delivery risks aligned to the Cyber services.
- Where applicable, assists business leadership with contract template development and review to help expedite future risk reviews.
- Provides guidance to reduce in flight project risks, adjusts contract requirements to accommodate changing project circumstances, and manages stakeholder expectations to contractual obligations and agreed upon performance standards.
A successful candidate will possess these skills:
- Significant experience in negotiating various consulting agreements as identified above.
- Significant experience in advising business teams on developing agreements and contracts
- Significant experience evaluating and assessing Cyber engagements across the Cyber Market Offerings
- Experience in negotiating and managing vendor contracts (buy-side) for third-party software providers, including reseller agreements
- Understanding of the different types of sensitive data (PII, PHI, etc.), the associated risk profile of handling each type of data, and the appropriate risk mitigation strategies to be employed
- Ability to evaluate risks associated with large professional service engagements
- Experience advising engagement teams on risk matters
- Experience in Request for Proposal analysis, including contract terms and conditions
- Experience and ability to work directly with senior level individuals (internally and externally)
- Strong oral and written communication skills
- Ability to work autonomously and handle a fast paced, multi-task environment
- Experience structuring and negotiating license agreements for a software business
Qualifications
Required:
- Experience: 15+ years of Client Service delivery, direct contract negotiation, and/or relevant management experience
- Education: BBA/BA/BS in related field
- Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Preferred:
- Education: Master's Degree is desirable
The wage range for this roletakes into accountthe wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $155,600-$306,800.
You may also be eligible toparticipatein a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends onvarious factors, including, without limitation, individual and organizational performance.
Education:Bachelor's DegreeEmployment Type:About Deloitte
Sourced by ZipRecruiter
Industry
Finance and insurance and business management consulting
Company size
10,000+ Employees
Headquarters location
Orlando, FL, US