Senior Manager, Third Party Risk Management

Jobtailor

Sterling (VA)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Senior Third-Party Risk Manager to own and enhance the TPRM program across vendor lifecycle. You will define policy, perform due diligence, and align with CISO and GRC leadership to manage risk posture.

The role requires deep knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS, and hands-on experience with TPRM platforms, audits, and security ratings; leadership of a risk team is essential to drive improvements.

Qualifications

  • 8+ years in information security, IT risk, or GRC.
  • 4+ years focused on third-party/vendor risk management.
  • 2+ years of direct people leadership.
  • Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS.
  • Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports).
  • Hands-on experience with TPRM/GRC platforms and continuous monitoring/security-rating tools.
  • Bachelor’s degree in a related field or equivalent professional experience.

Responsibilities

  • Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program
  • Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology
  • Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership
  • Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding
  • Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination
  • Operationalize inherent-risk tiering to scope assessment depth and cadence
  • Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments
  • Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk
  • Establish and lead risk reviews for third-party AI/GenAI tooling
  • Coordinate third-party incident response with SOC/IR
  • Manage the third-party risk register and findings inventory
  • Develop a standardized library of contractual security requirements
  • Define and report outcome-driven metrics and KRIs

Skills

Info security
GRC
Vendor risk mgmt
Leadership
NIST CSF
ISO 27001
SOC 2
PCI DSS

Education

Bachelor's degree

Tools

TPRM platforms
Security rating tools

Job description

Responsibilities
  • Own strategy, design, and continuous improvement of the Third-Party/Vendor Risk Management (TPRM) program
  • Define and maintain TPRM policy, standards, procedures, and risk-tiering methodology
  • Establish third-party risk appetite and tolerance thresholds with CISO and GRC leadership
  • Embed risk gates within sourcing, onboarding, contracting, renewal, and offboarding
  • Lead the full vendor risk lifecycle: intake, inherent-risk classification, due diligence, residual-risk determination
  • Operationalize inherent-risk tiering to scope assessment depth and cadence
  • Direct security, privacy, and resilience assessments using methodologies such as SIG/Shared Assessments
  • Evaluate fourth-party/Nth-party dependencies, vendor concentration, and systemic risk
  • Establish and lead risk reviews for third-party AI/GenAI tooling
  • Coordinate third-party incident response with SOC/IR
  • Manage the third-party risk register and findings inventory
  • Develop a standardized library of contractual security requirements
  • Define and report outcome-driven metrics and KRIs
Requirements
  • 8+ years in information security, IT risk, or GRC
  • 4+ years focused on third-party/vendor risk management
  • 2+ years of direct people leadership managing analysts or a risk team
  • Strong working knowledge of NIST CSF 2.0, ISO 27001, SOC 2, PCI DSS
  • Experience reviewing assurance artifacts (SOC 2 Type II, ISO certifications, penetration test reports)
  • Hands‑on experience with TPRM/GRC platforms and continuous monitoring/security‑rating tools
  • Experience partnering with Procurement and Legal on vendor contracting and security/privacy termsBachelor’s degree in a related field or equivalent professional experience
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Third Party Risk Management Lead
Third Party Risk Management Lead

Jobtailor • Foster City (CA)

On-site
USD 150,000 - 230,000
Senior Consultant, Third Party Issue Management - Third Party Risk Management
Senior Consultant, Third Party Issue Management - Third Party Risk Management

Northern Trust • Tempe (AZ)

On-site
USD 100,000 - 130,000
401k and pension
Health and welfare benefits
Paid time off
+3
Head of Third-Party Risk Management
Head of Third-Party Risk Management

Getevolved • Memphis (TN)

On-site
USD 120,000 - 180,000
Senior - Third-Party Cybersecurity & Risk Management
Senior - Third-Party Cybersecurity & Risk Management

TechDigital Group • Mount Laurel Township (NJ)

On-site
USD 90,000 - 120,000
Third Party Risk Manager
Third Party Risk Manager

Crowe • New York (NY)

On-site
USD 104,000 - 214,000
Third Party Risk Officer
Third Party Risk Officer

Getevolved • Memphis (TN)

On-site
USD 120,000 - 180,000
Senior Manager, Third-Party Risk & Vendor Security
Senior Manager, Third-Party Risk & Vendor Security

Jobtailor • Sterling (VA)

On-site
USD 140,000 - 190,000
Director, Third-Party Risk Management – Technical Information Security Lead
Director, Third-Party Risk Management – Technical Information Security Lead

Jobtailor • New York (NY)

On-site
USD 180,000 - 240,000
Information Security Vendor Management Analyst
Information Security Vendor Management Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000
Third Party Risk Analyst
Third Party Risk Analyst

Addison Group • Chicago (IL)

On-site
USD 70,000 - 90,000