GRC Careers: AI Governance, Risk and Compliance JobsConnecting Talent and Trust. Post a Job Log in

JobsWestportVendor Risk Manager

Vendor Risk Manager

DFO Referrals
RiskOn-siteFull-timeWestport, CT$ 175,000 -$ 26

DFO Referrals is hiring for the job of Vendor Risk Manager, Westport, CT (On-site). This is a Risk job in the governance, risk, and compliance field, with a posted range of $ 175,000 -$ 26. Review the full details below and apply directly with DFO Referrals.

Organization: DFO ReferralsLocation: Westport, CTWorkplace: On-siteFocus: RiskSalary: $ 175,000 -$ 26Posted: Sep 19, 2026
DFO Referrals is hiring for this Risk job in Westport, one of the metros GRC Careers tracks for governance, risk, and compliance hiring.

strong;ObjectId;ClassId;Properties;Default;2;true;Default;1;Calibri;Calibri;Calibri;Calibri;0;24;240;0;0;1;5;1;1;Calibri;1 Vendor Risk Manager / ​:0:0

Dalio Family Office /:0:0

Dalio Family Office Overview /:0:240:0

The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures investments and philanthropic efforts under Dalio Philanthropies which includes OceanX Dalio Education Endless Network and the Beijing Dalio Foundation. The core of the DFO’s culture is built around meaningful work and meaningful relationships and the family’s commitment to giving back. The office is headquartered in Westport CT with regional offices in New York City Singapore and Abu Dhabi.

Position Summary /:0:240:0

​ ​ The Vendor Risk Manager owns the end-to-end third-party risk lifecycle onboarding diligence monitoring and exit across a high-volume diverse vendor portfolio. You will synthesize risk across cybersecurity AI privacy financial and AML/CFT/sanctions domains into clear actionable risk positions performing structured threat modeling for high-exposure vendors. ​:0:240

Day-to-day responsibilities would include a combination of the following:0:240

Own the VRM program end-to-end strategy policy procedure workflow tooling metrics and executive reporting for CISO/CRO/board visibility. / ​ Lead holistic vendor risk assessments across cybersecurity AI risk privacy financial AML/CFT/sanctions. / Document residual risk acceptances with named accountable executives and time-boxed review dates coordinate with IT Legal Finance and Compliance as appropriate.:false:false:240 / ​Evaluate and monitor vendor security controls based on data sensitivity and business criticality leveraging industry frameworks and evidence such as SOC 2 ISO 27001 penetration testing and security assessments.:false:false:240 / Conduct structured threat models (STRIDE PASTA) for high risk vendors a nd document findings as durable artifacts informing contracting monitoring and exit planning. /:false:false:240 / Translate threat model outputs into concrete testable control requirements drawing from OWASP (ASVS API Security Top 10 LLM/Agentic Top 10) NIST (SP 800-53 SP 800-161 CSF 2.0 SP 800-207) and MITRE ATT;CK scale requirements to vendor tier.:false:false:240 / Partner with Legal to translate identified risks into enforceable contractual requirements. / Apply FAIR or comparable quantitative methods for high-impact vendor decisions expressing cyber risk in loss-exposure terms that resonate with senior leadership.:false:false:240 /:false:false:240 Advise IT Engineering and business teams on vendor integration architecture (SSO/SCIM OAuth conditional access DLP segmentation BYOK VPC peering) and maintain approved reference patterns. / ​ Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth produce program dashboards tracking throughput cycle time recertification compliance and remediation aging.:false:false:240

​ ​ The ideal candidate will possess the following knowledge skills attributes and values:0:240:0

Expert knowledge of third-party/vendor risk management / Strong risk assessment and analytical skills:false:false:240 / Technical understanding of enterprise security architecture:false:false:240 / Excellent communication and stakeholder management skills:false:false:240 / Proven ability to lead and optimize vendor risk programs:false:false:240

:720

Illustrative Benefits:0:240

100% company paid medical premiums:0:240 / 17 company paid holidays:0:240 / Friday summer hours:0:240 /;Monthly community happy hours:0:240 / Hybrid work environment:0:240 /;Free catered food services for in-office days:0:240 / Generous PTO offering:0:240 / Casual dress code:0:240 / 150% 401(k) match up to $7,500 and 100% match above $7,500 ($15k match limit):0:240 / Gym reimbursement back up childcare services insurance financial and legal services and much more!:0:240

Qualifications:0:240

Bachelor’s degree in Information Security Risk Management Computer Science Cybersecurity or a related discipline.:0:240 / At least 7 years of progressive experience across vendor risk management cybersecurity architecture security engineering GRC audit or related fields.:0:240 / Experience managing the full third-party/vendor risk lifecycle including vendor onboarding due diligence risk assessments continuous monitoring recertification remediation tracking and vendor exit planning with at least 2 years owning an end-to-end TPRM program.:false:false:0 / Strong technical knowledge of cybersecurity frameworks standards and methodologies including NIST ISO 27001/27002 OWASP MITRE ATT;CK Shared Assessments threat modeling approaches (STRIDE/PASTA) and risk management practices.:false:false:0 / Hands-on experience evaluating enterprise security controls cloud and integration architectures SOC 2 Type II reports ISO certifications penetration testing results data protection requirements and third-party security risks across complex technology environments.:false:false:0 / Ability to communicate complex technical and risk concepts to executive stakeholders collaborate effectively across business functions / 10% travel as required based on business needs.:false:false:0

Compensation:0:0:240

;ObjectId;ClassId;Properties;1;5;1;1;Calibri;Calibri;Calibri;1;Calibri;22;normaltextrun;1;true;normaltextrun;1;Default Paragraph Font Compensation for the role includes a competitive salary in the range from $ 175,000 -$ 26 0,000 (inclusive of a merit-based bonus dependent on / years of experience level of education obtained as well as applicable skillset) and an excellent benefits package including paid time off ranging from 15 to 25 days based on years of service paid sick and safe leave dental vision life and disability insurance paid parental time off birth mother recovery pay sick family member pay parental ramp back up program gym reimbursement and generous employer match for 401k. /:0:0

:0:0

Please note we are unable to provide immigration sponsorship for this position. /:0:0

At the DFO we believe our biggest asset is our people. We are proud to be an equal opportunity employer hiring and developing individuals from diverse backgrounds and experiences to add to our collaborative culture. The DFO treats all candidates and employees with respect and does not discriminate in our recruiting hiring and promoting processes and general treatment during employment including on the basis of actual or perceived race creed color religion sex age sexual orientation gender identity and/or expression alienage or national origin ancestry citizenship status marital status veteran status or disability /.

Location and market context

This job is based in Westport on-site. Local candidates benefit from being close to DFO Referrals's teams and regional hiring market. Confirm the exact in-office expectation and any relocation support with the employer.

About risk management jobs

Risk jobs own the methodology for identifying, assessing, and escalating enterprise, operational, and technology risk. Second-line teams set risk appetite and challenge the first line. Jobs like this one are typically evaluated against frameworks such as enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices.

How to position yourself for this risk management job

Strong candidates emphasize risk assessment methodology, appetite and escalation, cross-functional partnership, and clear reporting to senior leadership and the board. In your resume and outreach, tie your experience to how DFO Referrals would apply enterprise and operational risk frameworks, NIST AI RMF, and risk-appetite and escalation practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

More GRC jobs in Westport

Hiring for Risk?

Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.

Post a job  Pricing from $99 · About GRC Careers · Hiring toolkit

Want to be next in a job like this?

Jobs like Vendor Risk Manager in Westport, CT open regularly. Be first to know, privately. No current employer ever sees you looking.

New Risk jobs, the moment they post.

One click unsubscribe.
Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

Employer, or see something wrong with this posting? Report this posting and we will review it promptly.