Report onsystemic control gaps, concentration risk, and emerging third-party risk themes across the vendor population. * Escalatematerialthird-party risk issues and control deficiencies ...
Report onsystemic control gaps, concentration risk, and emerging third-party risk themes across the vendor population. * Escalatematerialthird-party risk issues and control deficiencies ...
Manage Third-Party and Vendor Risk: Evaluate technology vendors and third-party service providers for cybersecurity compliance and risk posture across all applicable frameworks. Review vendor ...
Manage Third-Party and Vendor Risk: Evaluate technology vendors and third-party service providers for cybersecurity compliance and risk posture across all applicable frameworks. Review vendor ...
Manage Third-Party and Vendor Risk: Evaluate technology vendors and third-party service providers for cybersecurity compliance and risk posture across all applicable frameworks. Review vendor ...
Manage Third-Party and Vendor Risk: Evaluate technology vendors and third-party service providers for cybersecurity compliance and risk posture across all applicable frameworks. Review vendor ...
Manage Third-Party and Vendor Risk: Evaluate technology vendors and third-party service providers for cybersecurity compliance and risk posture across all applicable frameworks. Review vendor ...
Manage Third-Party and Vendor Risk: Evaluate technology vendors and third-party service providers for cybersecurity compliance and risk posture across all applicable frameworks. Review vendor ...
Vendor Auditor
Hanover, MD · On-site
This position manages the day-to-day oversight of the organization's highest-risk vendor population by evaluating claims accuracy, monitoring vendor performance, identifying operational risks, and ...
Vendor Auditor
Hanover, MD · On-site
This position manages the day-to-day oversight of the organization's highest-risk vendor population by evaluating claims accuracy, monitoring vendor performance, identifying operational risks, and ...
$111K - $111K/yr
Identifyopportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
$111K - $111K/yr
Identifyopportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
Identifyopportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
Identifyopportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
Dir., Technical Operations & Infrastructure
Silver Spring, MD · On-site
$150K - $188K/yr
... vendor oversight, and operational governance. As a member of the IT leadership team, this leader translates IT strategy into measurable service performance, risk reduction, and high-quality employee ...
Quick apply
Dir., Technical Operations & Infrastructure
Silver Spring, MD · On-site
$150K - $188K/yr
... vendor oversight, and operational governance. As a member of the IT leadership team, this leader translates IT strategy into measurable service performance, risk reduction, and high-quality employee ...
$150 - $210/hr
... vendor oversight, and operational governance. You will translate IT strategy into measurable service performance, risk reduction, and a high-quality employee technology experience as a member of the ...
New
$150 - $210/hr
... vendor oversight, and operational governance. You will translate IT strategy into measurable service performance, risk reduction, and a high-quality employee technology experience as a member of the ...
New
Director of Risk Management
Towson, MD · On-site
$106K - $175K/yr
Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage organizational risk exposures. 2. Litigation Management Assistance * Support litigation and claims ...
Director of Risk Management
Towson, MD · On-site
$106K - $175K/yr
Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage organizational risk exposures. 2. Litigation Management Assistance * Support litigation and claims ...
... , vendor risk management, contract negotiation, and technology-specific compliance requirements (e.g., data privacy, cybersecurity standards, software licensing, AI ). This role offers the ...
... , vendor risk management, contract negotiation, and technology-specific compliance requirements (e.g., data privacy, cybersecurity standards, software licensing, AI ). This role offers the ...
... vendor risk management, contract negotiation, and technology-specific compliance requirements(e.g., data privacy, cybersecurity standards, software licensing, AI ). This role offers the opportunity ...
... vendor risk management, contract negotiation, and technology-specific compliance requirements(e.g., data privacy, cybersecurity standards, software licensing, AI ). This role offers the opportunity ...
Director of Risk Management
Towson, MD · On-site
$51.18 - $84.34/hr
Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage organizational risk exposures. 2. Litigation Management Assistance * Support litigation and claims ...
Director of Risk Management
Towson, MD · On-site
$51.18 - $84.34/hr
Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage organizational risk exposures. 2. Litigation Management Assistance * Support litigation and claims ...
Director of Risk Management
Towson, MD · On-site
$106.46 - $175.42/hr
Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage organizational risk exposures. Litigation Management Assistance * Support litigation and claims ...
New
Director of Risk Management
Towson, MD · On-site
$106.46 - $175.42/hr
Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage organizational risk exposures. Litigation Management Assistance * Support litigation and claims ...
New
$111K - $111K/yr
Identify opportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
$111K - $111K/yr
Identify opportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
Model Risk Control Specialist
Baltimore, MD · On-site
$70K - $125K/yr
... vendors, including design of challenger models or compensating controls as needed > Perform and/or ... Risk Management, and Internal Audit D. Part 2: Scope of Role - What you'll bring: > Ability to ...
Model Risk Control Specialist
Baltimore, MD · On-site
$70K - $125K/yr
... vendors, including design of challenger models or compensating controls as needed > Perform and/or ... Risk Management, and Internal Audit D. Part 2: Scope of Role - What you'll bring: > Ability to ...
Senior Manager, Program Management and Governance - Revenue Technology
California, MD · On-site
$111K - $111K/yr
Identify opportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
Senior Manager, Program Management and Governance - Revenue Technology
California, MD · On-site
$111K - $111K/yr
Identify opportunities for license optimization, consolidation, cost avoidance, and vendor risk mitigation. Demand Intake & Portfolio Governance * Own the single-backlog intake framework, triaging ...
Model Risk Control Specialist
Baltimore, MD · On-site
$70K - $125K/yr
... vendors, including design of challenger models or compensating controls as needed > Perform and/or ... Risk Management, and Internal Audit D. Part 2: Scope of Role - What you'll bring: > Ability to ...
Model Risk Control Specialist
Baltimore, MD · On-site
$70K - $125K/yr
... vendors, including design of challenger models or compensating controls as needed > Perform and/or ... Risk Management, and Internal Audit D. Part 2: Scope of Role - What you'll bring: > Ability to ...
Manager of Workplace Safety & Risk Management
$76K - $95K/yr
Risk Management Campus Location: Arnold/Main Campus Salary Range: $76,448-$95,560 Work Mode: This ... Select vendor for these services based on proper hazardous waste hauling regulations. This includes ...
Manager of Workplace Safety & Risk Management
$76K - $95K/yr
Risk Management Campus Location: Arnold/Main Campus Salary Range: $76,448-$95,560 Work Mode: This ... Select vendor for these services based on proper hazardous waste hauling regulations. This includes ...
Guide responsible AI adoption, including governance, acceptable use, data privacy, vendor risk, and practical implementation Client-Facing Technology Partnership * Partner with business and project ...
Guide responsible AI adoption, including governance, acceptable use, data privacy, vendor risk, and practical implementation Client-Facing Technology Partnership * Partner with business and project ...
Vendor Risk information
What is the difference between Vendor Risk vs Vendor Compliance?
| Aspect | Vendor Risk | Vendor Compliance |
|---|---|---|
| Focus | Identifying and mitigating risks associated with vendors | Ensuring vendors meet regulatory and contractual requirements |
| Certifications | Risk management certifications (e.g., CRISC, FAIR) | Compliance certifications (e.g., ISO 27001, SOC 2) |
| Work Environment | Risk assessment teams, procurement, security departments | Legal, compliance, audit teams |
| Industry Usage | Financial, healthcare, technology sectors | Financial services, healthcare, regulated industries |
Vendor Risk and Vendor Compliance roles often overlap but serve different purposes. Vendor Risk focuses on identifying and mitigating potential risks posed by vendors, while Vendor Compliance ensures vendors adhere to legal and contractual standards. Both are essential for managing vendor relationships effectively and maintaining organizational security and compliance.

Full-time
Re-posted yesterday
T. Rowe Price rating
9.1
Based on 21 frontline employees who took The Breakroom Quiz
Job description
Role Summary
TheDirector- ThirdParty Risk Management is aSecond Line of Defense (2LoD)leadership role responsible for thestrategic development, oversight, and ongoing maturation of the firm'sThirdPartyRisk Management (TPRM) program. Reporting to the Head of Privacy & TPRM, this role is regarded as asubject matter expert in third-party riskand plays a key role in shaping the firm's risk strategy, governance framework, and operating model following the implementation of anoutsourced TPRMcapability.
TheDirectorprovides independent oversight, crediblechallenge, and assurance over first-line and outsourced TPRM activities, while building a sustainable, regulator-ready 2LoD function aligned with the firm's risk appetite and regulatory expectations.
Responsibilities
TPRM Strategy & Program Leadership:
Serve as the firm'ssubject matter experton third-party risk management.
Contribute to the development and execution of the firm'sTPRM strategy, roadmap, and target-state operating model.
Lead the build-out and continuous improvement of a 2LoD TPRM functionfollowing outsourcing of due diligence and periodic reviews.
Define and maintain TPRM policies, standards, risk methodologies, and oversight frameworks aligned with regulatory expectations and industry best practices.
Ensure alignment of the TPRM program with enterprise risk appetite and governance structures.
Lead assessment of emergingthird partyrisks and technologies, including AI, andintegratefindings into TPRM strategy, governance, and executive reporting.
Oversight of Outsourced & First-Line TPRM Activities:
Provide independent oversight and effectivechallengeofoutsourced TPRM service providers, including due diligence execution and ongoing monitoring.
Oversight of monitoring activities related toSLAs, KPIs, quality assurance standards, and performance metrics for outsourced partners.
Report onsystemic control gaps, concentration risk, and emerging third-party risk themes across the vendor population.
Escalatematerialthird-party risk issues and control deficiencies throughappropriate governanceand risk committees.
Risk Governance, Reporting & Regulatory Readiness:
Design and deliver executive and board-level reporting on third-party risk, including trends, emerging risks, and risk appetite breaches.
Lead TPRM-related regulatory exams, internal audits, and management assurance activities.
Ensure TPRM documentation, evidence, and reporting areaudit-and exam-ready.
Partner with Enterprise Risk, Compliance, Legal, Information Security, Procurement, and Technology while maintaining 2LoD independence.
Leadership & Capability Development:
Provide leadership, guidance, and technical mentorship to TPRM risk analysts and managers.
Establish clear roles, responsibilities, and RACI alignment across 1LoD, 2LoD, and outsourced providers.
Drive adoption of data-driven, AI-enabled reporting and analytics to enhance risk insight and oversight efficiency.
Promote a strong risk culture and consistent application of third-party risk standards across the firm.
Qualifications
Required:
Bachelor's degree in Risk Management, Information Systems, Finance, Business, Law, ora relatedfield.10+ years of experience inthird-party risk management, operational risk, or compliance, withsignificant experiencein a2LoD capacitywithin financial services or asset management(or other industry subject to equivalent regulatory scrutiny).
Demonstrated experiencedesigning, implementing, or maturing a TPRM program, including oversight of outsourced or co-sourced models.
Deep understanding of regulatory expectations for third-party risk (e.g., SEC, FINRA, global regulators).
Proven ability tooperateas a trusted expert and strategic advisor to senior leadership.
Required Certifications (at least one): Certified Third Party Risk Professional (CTPRP), Certified in Risk and Information Systems Control (CRISC), Certified Information Systems Auditor (CISA)
Preferred:
Advanced degree (MBA, JD, or equivalent).
Experience supporting global or complex vendor ecosystems.
Additionalcertifications:
ISO 27001 Lead Implementer or Auditor
PMP or equivalent program management certification
ExperienceleveragingAI, automation, or advanced analytics in TPRM oversight(e.g., Microsoft Co-Pilot, ChatGPT Enterprise).
Tools & Technology (Preferred)
Extensive experience with TPRM and GRC platforms (e.g., ServiceNow, Coupa).
Strong executive-level reporting and data visualization skills (e.g., Power BI).
Experience implementing metrics, KRIs, and dashboards aligned to risk appetite.
Key Competencies
Recognizedexpertisein third-party risk management.
Strategic mindset with hands-on oversight capability.
Strong executive presence and ability to provide crediblechallenge.
Excellent written and verbal communication skills.
Ability to lead through influence in a matrixed, regulated environment.
FINRA Requirements
FINRA licenses are not required and will not be supported for this role.
Work Flexibility
This role is eligible for hybrid work, with up to one day per week from home.
What T. Rowe Price employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About T. Rowe Price
Sourced by ZipRecruiter
Industry
Funds, trusts and financial programs
Company size
5,001 - 10,000 Employees
Headquarters location
Baltimore, MD, US
Year founded
1937