Third Party Risk Management Lead

Jobtailor

Foster City (CA)

On-site

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking an experienced Vendor Risk Manager in the United States (California) to lead substantive third‑party risk assessments. You will independently evaluate real risk from vendors and AI providers, review security reports, and work with Legal on DPAs and subprocessor terms.

The role requires deep GRC expertise, cross‑functional collaboration, and the ability to build scalable vendor review processes while maintaining risk registers. Prior AI/ML vendor experience is a plus.

Qualifications

  • 8+ years in third‑party/vendor risk management or related GRC role.
  • Ability to independently assess vendor risk beyond questionnaires.
  • Fluency reading SOC 2, ISO certificates, pen test summaries, architecture docs.
  • Experience reviewing or redlining security and data‑handling contracts with Legal.
  • Knowledge of GDPR/CCPA as they relate to vendors and subprocessors.
  • Strong cross‑functional collaboration with Legal, Engineering, Product, and Sales.
  • Bonus: experience with foundation model or AI/ML vendors.

Responsibilities

  • Run substantive third‑party/vendor risk management, independently evaluating real risk.
  • Review SOC 2 reports, pen tests, and architecture docs to form an independent view.
  • Partner with Legal on vendor and AI contract terms, including DPAs and subprocessor agreements.
  • Review contracts for non‑standard security language and recommend redlines.
  • Maintain vendor and AI/model risk registers and feed findings to the master risk register.
  • Enable sales by maturing the customer trust program.
  • Build capability for continuous monitoring of the vendor ecosystem.

Skills

Vendor risk management
Security risk assessment
GRC processes
Cross-functional collaboration
Independent risk assessment
Contract language review

Job description

Responsibilities
  • Run substantive third‑party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses
  • Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers
  • Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI‑specific provisions
  • Review contracts for non‑standard security language when flagged by Legal or deal desk, and recommend redlines
  • Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register
  • Enable sales through maturing the customer trust program
  • Build the capability for continuous monitoring of vendor ecosystem
Requirements
  • 8+ years in third‑party/vendor risk management, security risk, or a related GRC role
  • Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation
  • Experience reviewing or redlining security and data‑handling contract language, ideally in partnership with a legal team
  • Working knowledge of data privacy fundamentals (GDPR, CCPA) as they relate to vendor and subprocessor relationships
  • Strong cross‑functional collaboration skills — this role touches Legal, Engineering, Product, and Sales regularly
  • Experience building repeatable, scalable vendor review processes rather than inheriting an existing one
  • Bonus Qualifications include direct experience assessing foundation model providers or AI/ML vendors specifically
Core Competencies

Expertise in third‑party risk management, including independent vendor risk assessment and contract review, with a strong understanding of data privacy regulations and the ability to collaborate across multiple functions. Proven capability in building scalable vendor review processes and maintaining comprehensive risk registers.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Manager, Third Party Risk Management
Senior Manager, Third Party Risk Management

Jobtailor • Sterling (VA)

On-site
USD 140,000 - 190,000
Director, 3rd Party Security Risk
Director, 3rd Party Security Risk

HealthEquity • United States

On-site
USD 180,000 - 260,000
Independent TPRM Lead: Vendor & AI Risk Strategy
Independent TPRM Lead: Vendor & AI Risk Strategy

Jobtailor • Foster City (CA)

On-site
USD 150,000 - 230,000
Third Party Risk Analyst
Third Party Risk Analyst

Addison Group • Chicago (IL)

On-site
USD 70,000 - 90,000
Third Party Risk Management and Customer Trust Lead
Third Party Risk Management and Customer Trust Lead

Replit • United States

On-site
USD 180,000 - 230,000
Competitive Salary
Equity
401(k) with 4% match (US)
+12
Third Party Risk Management and Customer Trust Lead
Third Party Risk Management and Customer Trust Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 230,000
Competitive Salary & Equity
401(k) with 4% match
Health, Dental, Vision, Life Insurance
+8
Third-Party Risk Analyst
Third-Party Risk Analyst

OpenRouter • New York (NY)

On-site
USD 140,000 - 190,000
Third-Party Cyber Risk Specialist
Third-Party Cyber Risk Specialist

Jobtailor • Illinois

On-site
USD 85,000 - 110,000
Information Security Vendor Management Analyst
Information Security Vendor Management Analyst

Centreville Bank • West Warwick (RI)

On-site
USD 75,000 - 100,000
(On-site) Information Security Vendor Management Analyst
(On-site) Information Security Vendor Management Analyst

Centreville Bank • Warwick (RI)

On-site
USD 70,000 - 90,000