Skip to content
AGJ, the AI governance job board
Menu

Job description template

Third-Party Risk Manager

The Third-Party Risk Manager owns the vendor and supplier risk program, from onboarding due diligence through ongoing monitoring and offboarding. This template reflects how the role is scoped at organizations with material outsourcing and vendor exposure. Replace the [highlighted fields] with your specifics, trim what does not apply, and post.

Download PDF Download reference sheet

TitleThird-Party Risk Manager
DepartmentRisk Management / Third-Party Risk / Procurement
Reports to[Chief Risk Officer / Head of Operational Risk / VP Procurement]
Location[Remote / Hybrid / On-site]
Employment typeFull-time
Salary[Salary range. Postings with a range perform significantly better, and several states require one.]

Position overview

The Third-Party Risk Manager leads [Company]'s third-party and vendor risk management program. This role governs how the organization identifies, assesses, mitigates, and monitors risks introduced by suppliers, service providers, and other external relationships across their full lifecycle.

Partnering with procurement, information security, legal, compliance, and business owners, the Third-Party Risk Manager sets due diligence standards, drives ongoing monitoring, and manages concentration and fourth-party risk. The role keeps the organization protected as its reliance on outside providers grows.

This is a hands-on program leadership role for a risk professional who can balance rigor with the pace the business needs to onboard and manage vendors.

Key responsibilities

Third-party risk program

Due diligence and onboarding

Lead risk assessments across information security, privacy, financial, operational, regulatory, and reputational domains before contracts are signed. Evaluate:

Ongoing monitoring

Contracts and risk provisions

Partner with legal and procurement to embed risk, security, privacy, and audit provisions into contracts. Confirm right-to-audit, breach notification, and service-level terms reflect the organization's risk appetite.

Concentration and resilience

Assess concentration risk, single points of failure, and critical-vendor dependencies. Support business continuity and exit planning for material relationships.

Offboarding

Manage the risk aspects of vendor exit, including data return or destruction, access removal, and closure of the relationship in the inventory.

Required qualifications

Preferred certifications

One or more of: CTPRP, CRISC, CISA, CISSP, CIA, or equivalent risk certification.

Technical knowledge

Third-party risk management, vendor due diligence, risk tiering, ongoing monitoring, contract risk review, concentration and fourth-party risk, business continuity, information security controls, and GRC and vendor risk platforms.

Essential competencies

Analytical judgment, stakeholder management, negotiation and influence, clear communication, program management, and the ability to balance risk rigor with business speed.

Success measures: first 12 months

About [Company]

[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]

Post this role on GRC Careers

Reach professionals who specialize in third-party and vendor risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.

Post this role

See how others are hiring

Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.

Browse GRC jobs

Stay close to the market

Frequently asked questions

What does a Third-Party Risk Manager do?

A Third-Party Risk Manager owns the program for managing risk from vendors and suppliers. They set due diligence standards, assess vendors before onboarding, monitor them over time, embed risk provisions in contracts, and manage concentration and offboarding risk.

What qualifications and certifications does a Third-Party Risk Manager need?

Most bring 6 to 10 years in third-party risk, vendor management, operational risk, or information security, plus a bachelor's degree. Common certifications include CTPRP and CRISC, and sometimes CISA or CISSP.

What frameworks does a Third-Party Risk Manager use?

Common references include the Shared Assessments SIG questionnaire, NIST guidance, ISO 27036 for supplier relationship security, ISO 27001, and COSO ERM, alongside sector-specific regulatory expectations for outsourcing.

What is concentration risk in third-party risk management?

Concentration risk is the exposure that arises when an organization depends heavily on a single vendor, a small group of vendors, or a shared underlying provider. Managing it means identifying critical dependencies and planning for continuity and exit.