IT Third-Party Risk Manager

bankerstoolbox

Raleigh (NC)

Hybrid

USD 110,000 - 150,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Health benefits with HSA
Flexible PTO
401(k) plan with company match
Bonus structure

Job summary

Abrigo is seeking an IT Third-Party Risk Manager to lead the Third-Party Risk Management Program. The role oversees risk operations, audit readiness, governance, and continuous improvement, reporting to the VP IT Risk & Assurance within the CISO organization.

Remote-first, based in Raleigh with quarterly onsite engagements. You will coordinate vendor onboarding, review security documentation, maintain records, and develop risk metrics while collaborating with Information Security, Technology,

Qualifications

  • 4+ years of IT risk assessment and/or IT audit experience.
  • Ability to read and interpret audit reports (SOC 1, SOC 2) and security assessments.
  • Strong written and verbal communication across management levels.
  • Familiarity with information security standards and laws (NIST/FFIEC/GLBA).

Responsibilities

  • Lead operational administration of the Third-Party Risk Management Program.
  • Coordinate vendor onboarding, risk reviews, due diligence, and reassessments.
  • Review vendor security docs (SOC reports, policies, risk assessments) and determine actions.
  • Maintain vendor records and supporting documentation in governance platforms.
  • Monitor schedules, risk treatment, contracts, and remediation efforts.
  • Assist in metrics, dashboards, and reporting on risk and audits.
  • Research new technologies to improve risk assessment processes.
  • Act as SME on risk threats and mitigations.
  • Update policies, training materials, and playbooks; support continuous improvement.
  • Assist with customer assurance materials and security responses for third-party activities.
  • Support audit cycles with evidence collection and issue management.
  • Occasional travel for team events and engagements.

Skills

IT risk assessment
IT audit
Communication
Documentation & reporting
Regulatory compliance knowledge

Education

CRVPM
TPCRA
CISA
CRISC

Job description

We provide technology that community financial institutions use to manage risk and drive growth. Our solutions automate key processes - from anti-money laundering to fraud detection to CECL readiness to lending workflows - empowering our customers by addressing their Enterprise Risk Management needs.

Abrigo is seeking an IT Third-Party Risk Manager to lead the Third-Party Risk Management Program. The role is responsible for overseeing third-party risk management operations, including audit readiness efforts, security governance processes, customer assurance support, and continuous improvement initiatives.

The IT Third-Party Risk Manager serves as a key liaison between Information Security, Technology, Finance, Legal, Product, and business stakeholders to ensure IT risk management activities are executed consistently, documented appropriately, and aligned with regulatory, contractual, and organizational requirements. This position reports to the VP IT Risk & Assurance and is part of Abrigo's CISO organization. This is a remote first role primarily based in Raleigh, NC with quarterly onsite team engagements and periodic onsite visits during external audit fieldwork.

What You'll Do:
  • Lead operational administration of Abrigo's Third-Party Risk Management Program.
  • Coordinate vendor onboarding, inherent and residual risk reviews, due diligence collection, and annual reassessments.
  • Review vendor security documentation including SOC reports, security questionnaires, policies, certifications, and risk assessments and determine appropriate actions required based upon the review.
  • Maintain vendor records, ownership assignments, and supporting documentation within approved governance platforms.
  • Monitor vendor review schedules, risk treatment activities, contract obligations, and remediation commitments.
  • Assist in developing metrics, dashboards, and reporting related to risk, compliance, vendor governance, and audit activities.
  • Research new and developing technologies and standards to help contribute to the continuous improvement of the risk assessment process.
  • Act as a subject matter expert in understanding why certain risks are a threat to the company and how compensating or mitigating processes affect that risk.
  • Maintain and enhance policies, training materials, and operational playbooks.
  • Promote continuous improvement through automation, process optimization, and effective use of technology.
  • Assist with maintenance of customer assurance materials, trust documentation, and standardized security responses, with a focus on third-party activities.
  • Support audit cycles through collection of evidence requests, testing coordination, issue management, and audit response activities.
  • Other duties as assigned.
  • Occasional travel required for team events to support engagement, relationship-building, and key decision-making.
What You'll Need:
  • 4+ years of IT risk assessment and/or IT audit experience to include reading and interpreting the results of audit reports (SOC 1, SOC 2, etc.), security assessments (penetration tests, vulnerability scans, etc.), and continuity exercises (disaster recovery, security incident, etc.)
  • Bachelor's degree in Information Systems, Risk Management, Business Administration, Accounting, or a related field.
  • Working knowledge of information security standards and laws (e.g., NIST, FFIEC, GLBA, etc.), and commonly used concepts, practices and procedures within the information security and privacy field.
  • Experience supporting IT risk management, information security, internal audit, compliance, or third-party risk management programs.
  • Excellent communication skills and be able to write, speak and present to all levels of management.
  • Strong organizational ethic to manage a large volume of competing tasks effectively.
  • Professional certification, such as CRVPM, TPCRA, CISA, or CRISC, are preferred.
What You'll Get:
  • Market competitive total rewards package
  • To be part of the Heart & SOUL of a winning company with an inspiring mission
  • The opportunity to Make Big Things Happen
  • Competitive salary and bonus structure along with full health benefits with an HSA option
  • Flexible PTO and bank holidays
  • 401(k) plan and company match

We are an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, age, genetic trait, sexual orientation, national origin, disability status, or any other characteristic protected by law. Abrigo is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at Careers@abrigo.com with the subject line accommodation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Third Party Risk Manager
IT Third Party Risk Manager

Abrigo • Raleigh (NC)

On-site
USD 110,000 - 160,000
Health benefits (HSA)
Flexible PTO
401(k) plan with company match
+1
Remote IT Third-Party Risk Lead | Compliance & Audit
Remote IT Third-Party Risk Lead | Compliance & Audit

Abrigo • Raleigh (NC)

On-site
USD 110,000 - 160,000
Health benefits (HSA)
Flexible PTO
401(k) plan with company match
+1
Remote IT Third-Party Risk Manager
Remote IT Third-Party Risk Manager

Abrigo • Raleigh (NC)

On-site
USD 120,000 - 150,000
Health benefits with HSA
Flexible PTO and bank holidays
401(k) plan with company match
+1
Strategic IT Third-Party Risk Lead - Remote
Strategic IT Third-Party Risk Lead - Remote

bankerstoolbox • Raleigh (NC)

Hybrid
USD 110,000 - 150,000
Health benefits with HSA
Flexible PTO
401(k) plan with company match
+1
Senior Contracts Manager
Senior Contracts Manager

Abrigo • United States

Hybrid
USD 80,000 - 120,000
Market competitive total rewards package
Full health benefits with HSA option
Flexible PTO and bank holidays
+2
IT Third Party Risk Lead – $125-145K plus Bonus
IT Third Party Risk Lead – $125-145K plus Bonus

ACCsurance, LLC • Town of Texas (WI)

On-site
USD 125,000 - 145,000
401k match and contribution
Student loan forgiveness
Home-buyers assistance
+1
Vendor Risk Manager
Vendor Risk Manager

Skill • Westlake (TX)

On-site
USD 49,593 - 56,481
Health insurance
Security Third Party Risk Management Lead
Security Third Party Risk Management Lead

Cloudflare • Austin (TX)

On-site
USD 150,000 - 190,000
Cybersecurity and Third-Party Risk Manager
Cybersecurity and Third-Party Risk Manager

Lord Abbett • Jersey City (NJ)

On-site
USD 95,000 - 110,000
Cybersecurity and Third-Party Risk Manager
Cybersecurity and Third-Party Risk Manager

Lord, Abbett & Co. LLC • Jersey City (NJ)

On-site
USD 95,000 - 110,000