| Title | Third-Party Risk Manager |
|---|---|
| Department | Risk Management / Third-Party Risk / Procurement |
| Reports to | [Chief Risk Officer / Head of Operational Risk / VP Procurement] |
| Location | [Remote / Hybrid / On-site] |
| Employment type | Full-time |
| Salary | [Salary range. Postings with a range perform significantly better, and several states require one.] |
Position overview
The Third-Party Risk Manager leads [Company]'s third-party and vendor risk management program. This role governs how the organization identifies, assesses, mitigates, and monitors risks introduced by suppliers, service providers, and other external relationships across their full lifecycle.
Partnering with procurement, information security, legal, compliance, and business owners, the Third-Party Risk Manager sets due diligence standards, drives ongoing monitoring, and manages concentration and fourth-party risk. The role keeps the organization protected as its reliance on outside providers grows.
This is a hands-on program leadership role for a risk professional who can balance rigor with the pace the business needs to onboard and manage vendors.
Key responsibilities
Third-party risk program
- Develop and maintain the Third-Party Risk Management (TPRM) framework and policy.
- Define risk tiering and due diligence requirements by vendor criticality.
- Maintain the third-party inventory and risk register.
- Report on program status and vendor risk posture to leadership.
Due diligence and onboarding
Lead risk assessments across information security, privacy, financial, operational, regulatory, and reputational domains before contracts are signed. Evaluate:
- Information security and data protection controls
- Financial stability and business continuity
- Regulatory and compliance posture
- Concentration and fourth-party dependencies
Ongoing monitoring
- Run periodic reassessments based on vendor tier and risk.
- Monitor performance, security ratings, and external risk signals.
- Track remediation of identified vendor issues to closure.
- Manage vendor risk exceptions and approvals.
Contracts and risk provisions
Partner with legal and procurement to embed risk, security, privacy, and audit provisions into contracts. Confirm right-to-audit, breach notification, and service-level terms reflect the organization's risk appetite.
Concentration and resilience
Assess concentration risk, single points of failure, and critical-vendor dependencies. Support business continuity and exit planning for material relationships.
Offboarding
Manage the risk aspects of vendor exit, including data return or destruction, access removal, and closure of the relationship in the inventory.
Required qualifications
- Bachelor's degree in Business, Risk Management, Information Systems, Finance, or a related discipline.
- 6 to 10 years of experience in third-party risk, vendor management, operational risk, or information security.
- Strong knowledge of due diligence, risk assessment, and vendor lifecycle management.
- Familiarity with security, privacy, and regulatory requirements that apply to outsourced services.
- Experience operating a vendor risk platform or GRC tool.
- Ability to work across procurement, legal, security, and business stakeholders.
Preferred certifications
One or more of: CTPRP, CRISC, CISA, CISSP, CIA, or equivalent risk certification.
Technical knowledge
Third-party risk management, vendor due diligence, risk tiering, ongoing monitoring, contract risk review, concentration and fourth-party risk, business continuity, information security controls, and GRC and vendor risk platforms.
Essential competencies
Analytical judgment, stakeholder management, negotiation and influence, clear communication, program management, and the ability to balance risk rigor with business speed.
Success measures: first 12 months
- Refresh the TPRM framework, policy, and risk tiering model.
- Complete a full inventory of active third parties.
- Reassess all critical and high-risk vendors.
- Stand up an ongoing monitoring cadence by tier.
- Reduce the backlog of overdue vendor assessments.
- Strengthen risk provisions in the standard contract template.
- Establish concentration and fourth-party risk reporting.
- Deliver a leadership dashboard on vendor risk posture.
About [Company]
[Two or three sentences about your organization, the maturity of your program, and what the first year looks like. Candidates in this field respond to honesty about whether they are joining a build or an established function.]
Post this role on GRC Careers
Reach professionals who specialize in third-party and vendor risk management rather than hoping they find you in a general feed. Hand reviewed, live within one business day.
See how others are hiring
Review live GRC jobs postings to benchmark scope, level, and posted salary before you publish yours.
Stay close to the market
Job alerts
Get new GRC jobs roles sent to you as they post.
Newsletter
Hiring trends, salary signals, and new templates from GRC Careers.
Frequently asked questions
What does a Third-Party Risk Manager do?
A Third-Party Risk Manager owns the program for managing risk from vendors and suppliers. They set due diligence standards, assess vendors before onboarding, monitor them over time, embed risk provisions in contracts, and manage concentration and offboarding risk.
What qualifications and certifications does a Third-Party Risk Manager need?
Most bring 6 to 10 years in third-party risk, vendor management, operational risk, or information security, plus a bachelor's degree. Common certifications include CTPRP and CRISC, and sometimes CISA or CISSP.
What frameworks does a Third-Party Risk Manager use?
Common references include the Shared Assessments SIG questionnaire, NIST guidance, ISO 27036 for supplier relationship security, ISO 27001, and COSO ERM, alongside sector-specific regulatory expectations for outsourcing.
What is concentration risk in third-party risk management?
Concentration risk is the exposure that arises when an organization depends heavily on a single vendor, a small group of vendors, or a shared underlying provider. Managing it means identifying critical dependencies and planning for continuity and exit.