Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions. * Establishing a ...
Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions. * Establishing a ...
You set the defense architecture across fraud vendors, card processors, and banking partners ... Own the fraud risk strategy and the end-to-end defense architecture across the payments stack ...
Quick apply
You set the defense architecture across fraud vendors, card processors, and banking partners ... Own the fraud risk strategy and the end-to-end defense architecture across the payments stack ...
Senior/Staff TPM, Security Risk
New York, NY · On-site
$152K - $241K/yr
Own the third-party/vendor security risk management program , streamlining review workflows to support business velocity while ensuring robust security oversight of partners and vendors. * Drive ...
Senior/Staff TPM, Security Risk
New York, NY · On-site
$152K - $241K/yr
Own the third-party/vendor security risk management program , streamlining review workflows to support business velocity while ensuring robust security oversight of partners and vendors. * Drive ...
Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team ...
Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team ...
Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team ...
Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team ...
Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team ...
Maintaining the vendor risk register and tracking dashboards - keeping records accurate and current, and preparing status updates on in-progress reviews, escalations, and remediation actions for team ...
Oversee the vendor risk management program, including third-party due diligence, risk tiering, and escalation of critical findings * Lead reviews of vendor and client security questionnaires (DDQs ...
Oversee the vendor risk management program, including third-party due diligence, risk tiering, and escalation of critical findings * Lead reviews of vendor and client security questionnaires (DDQs ...
Vendor Risk ManagementResponsible for vendor due diligence, ongoing oversight, and risk mitigation activities to ensure providers deliver services in line with firm expectations and governance ...
New
Vendor Risk ManagementResponsible for vendor due diligence, ongoing oversight, and risk mitigation activities to ensure providers deliver services in line with firm expectations and governance ...
New
Senior Director of Claims and Vendor Management
Manhattan, NY · On-site
$159.19 - $199.01/hr
Establish and manage a robust vendor governance framework, including vendor risk assessment, due diligence, contract negotiation, and performance management. * Oversee implementation / project ...
New
Senior Director of Claims and Vendor Management
Manhattan, NY · On-site
$159.19 - $199.01/hr
Establish and manage a robust vendor governance framework, including vendor risk assessment, due diligence, contract negotiation, and performance management. * Oversee implementation / project ...
New
Senior TPRM Security Lead
Manhattan, NY · On-site
Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality. * Build a robust and ...
Senior TPRM Security Lead
Manhattan, NY · On-site
Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due diligence according to inherent risk, data sensitivity, and business criticality. * Build a robust and ...
... Risk Management and Process Improvement Evaluate and renegotiate vendor MSAs to meet current market standards for key terms such SLAs and payment terms Monitor day-to-day vendor risk management ...
... Risk Management and Process Improvement Evaluate and renegotiate vendor MSAs to meet current market standards for key terms such SLAs and payment terms Monitor day-to-day vendor risk management ...
... Risk Management and Process Improvement Evaluate and renegotiate vendor MSAs to meet current market standards for key terms such SLAs and payment terms Monitor day-to-day vendor risk management ...
... Risk Management and Process Improvement Evaluate and renegotiate vendor MSAs to meet current market standards for key terms such SLAs and payment terms Monitor day-to-day vendor risk management ...
Vendor AI detection across the full vendor portfolio * FactSheet review, validation, and updates ... AI risk posture * Cyber and technology risk posture * Ensure consistent and transparent reporting ...
Vendor AI detection across the full vendor portfolio * FactSheet review, validation, and updates ... AI risk posture * Cyber and technology risk posture * Ensure consistent and transparent reporting ...
Head of Security & Risk
New York, NY · On-site +1
... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ... audit-ready at all times. * Establish the Information Security Operations Framework : Design and ...
Head of Security & Risk
New York, NY · On-site +1
... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ... audit-ready at all times. * Establish the Information Security Operations Framework : Design and ...
... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ... audit-ready at all times. * Establish the Information Security Operations Framework : Design and ...
Quick apply
... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ... audit-ready at all times. * Establish the Information Security Operations Framework : Design and ...
IT Risk & Compliance Analyst
Manhattan, NY · On-site
$126K - $157K/yr
Develop and coordinates vendor risk management frameworks, policies and processes within a broader enterprise, operational and IT risk management model. * Compile metrics for reporting threats, risks ...
IT Risk & Compliance Analyst
Manhattan, NY · On-site
$126K - $157K/yr
Develop and coordinates vendor risk management frameworks, policies and processes within a broader enterprise, operational and IT risk management model. * Compile metrics for reporting threats, risks ...
Audit Manager - Third Party Risk
Manhattan, NY · On-site
$89K - $150K/yr
Our assurance and risk professionals have diverse backgrounds including internal controls, consumer ... Understanding of risks associated with third-party relationships across the vendor lifecycle ...
Audit Manager - Third Party Risk
Manhattan, NY · On-site
$89K - $150K/yr
Our assurance and risk professionals have diverse backgrounds including internal controls, consumer ... Understanding of risks associated with third-party relationships across the vendor lifecycle ...
Perform and document risk-based vendor assessments in alignment with internal procedures and global regulatory expectations. Maintain vendor qualification status and support periodic vendor risk ...
Perform and document risk-based vendor assessments in alignment with internal procedures and global regulatory expectations. Maintain vendor qualification status and support periodic vendor risk ...
M0 Labs - Head of Security & Risk
New York, NY · On-site +1
$117K - $153K/yr
... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ... audit-ready at all times. * Establish the Information Security Operations Framework : Design and ...
M0 Labs - Head of Security & Risk
New York, NY · On-site +1
$117K - $153K/yr
... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ... audit-ready at all times. * Establish the Information Security Operations Framework : Design and ...
Perform and document risk-based vendor assessments in alignment with internal procedures and global regulatory expectations. Maintain vendor qualification status and support periodic vendor risk ...
Perform and document risk-based vendor assessments in alignment with internal procedures and global regulatory expectations. Maintain vendor qualification status and support periodic vendor risk ...
Vendor Risk information
See Montclair, NJ salary details
$19.66 is the 25th percentile. Wages below this are outliers.
$14.70 - $20.22
28% of jobs
The median wage is $23.52 / hr.
$20.22 - $25.74
37% of jobs
$25.74 - $31.27
6% of jobs
$34.72 is the 75th percentile. Wages above this are outliers.
$31.27 - $36.79
6% of jobs
$36.79 - $42.31
12% of jobs
$42.31 - $47.83
0% of jobs
$47.83 - $53.36
0% of jobs
$53.36 - $58.88
8% of jobs
$58.88 - $64.40
0% of jobs
$64.40 - $69.92
0% of jobs
$69.92 - $75.45
2% of jobs
$14
$30
$75
How much do vendor risk jobs pay per hour?
What is the difference between Vendor Risk vs Vendor Compliance?
| Aspect | Vendor Risk | Vendor Compliance |
|---|---|---|
| Focus | Identifying and mitigating risks associated with vendors | Ensuring vendors meet regulatory and contractual requirements |
| Certifications | Risk management certifications (e.g., CRISC, FAIR) | Compliance certifications (e.g., ISO 27001, SOC 2) |
| Work Environment | Risk assessment teams, procurement, security departments | Legal, compliance, audit teams |
| Industry Usage | Financial, healthcare, technology sectors | Financial services, healthcare, regulated industries |
Vendor Risk and Vendor Compliance roles often overlap but serve different purposes. Vendor Risk focuses on identifying and mitigating potential risks posed by vendors, while Vendor Compliance ensures vendors adhere to legal and contractual standards. Both are essential for managing vendor relationships effectively and maintaining organizational security and compliance.

Full-time
Re-posted 18 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
45th of 150 rated financial services
Job description
The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll doThe Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
- Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
- Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
- Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
- Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
- Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.
A successful candidate would possess these skills:
- Strong communicator with the ability to tailor messages for technical and non-technical audiences.
- Collaborative relationship builder who works effectively across functions and levels to drive alignment.
- Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams.
- Confident facilitator who influences without authority and helps move issues to resolution.
The Team
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
Preferred:
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.
At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.
Recruiting for this role ends on May 31, 2027
Work you'll doThe Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.
Responsibilities include:
- Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
- Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
- Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
- Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
- Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
- Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.
A successful candidate would possess these skills:
- Strong communicator with the ability to tailor messages for technical and non-technical audiences.
- Collaborative relationship builder who works effectively across functions and levels to drive alignment.
- Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams.
- Confident facilitator who influences without authority and helps move issues to resolution.
The Team
Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients.
Qualifications
Required:
- Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
- Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
- 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
- Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
- Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
- Limited immigration sponsorship may be available.
- Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
- One of the following active accreditations obtained:
- Licensed CPA in state of practice/primary office if eligible to sit for the CPA
- If not CPA eligible:
- Licensed Attorney
- Enrolled Agent
- CBAP - Certified Business Analysis Professional
- Certified in Risk and Information System Controls (CRISC)
- Microsoft Azure
- Project Management Professional (PMP)
Preferred:
- Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes.
- Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences.
- Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels.
- Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs.
- Experience supporting business process improvement, transformation, or technology-enabled change initiatives.
- Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.