GRC CareersConnecting Talent and Trust. Post a Job Log in

JobsMassachusettsBostonDirector, Third Party Risk Management – Quality Assurance & Governance

Director, Third Party Risk Management – Quality Assurance & Governance

Manulife
Third-Party RiskHybridFull-timeBoston, MA

Manulife is hiring for the role of Director, Third Party Risk Management – Quality Assurance & Governance, Boston, MA (Hybrid). This is a Third-Party Risk role in the governance, risk, and compliance field. Review the full details below and apply directly with Manulife.

Organization: ManulifeLocation: Boston, MAWorkplace: HybridFocus: Third-Party RiskPosted: Jul 30, 2026
Manulife is hiring for this Third-Party Risk role in Boston, one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See other GRC roles in Boston →

Leads Quality Assurance and governance oversight across vendor security management, vendor governance, and sourcing. Owns procurement-related RCSAs, Key Risk Indicators, and issue remediation tracking. Acts as primary point of contact for financial regulators and internal audit on third-party risk controls.

Location and market context

This role is based in Boston on-site. Local candidates benefit from being close to Manulife's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About third-party risk roles

Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Roles like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.

How to position yourself for this third-party risk role

Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how Manulife would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.