Third Party Risk Manager
Location: Remote
Compensation: To Be Discussed
Reviewed: Fri, Sep 11, 2026
This job expires in: 30 days
Job Summary
To build and lead an enterprise Third-Party Risk Management program, the full-time remote Third Party Risk Manager will manage vendor lifecycle processes, conduct risk assessments, and ensure compliance with regulatory requirements for sensitive data handling.
Key responsibilities
- Lead and mature the Third-Party Risk Management program, including vendor intake, risk tiering, and ongoing monitoring
- Develop and manage the User Access Review program, ensuring compliance with access controls and audit requirements
- Produce reports and collaborate cross-functionally to maintain vendor risk posture and support audit readiness
Required qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Risk Management, or a related field
- 6-8 years of experience in information security, risk, or compliance, with a focus on vendor management programs
- Hands-on audit experience with ISO 27001, ISO 27701, and ISO 42001
- Experience developing and managing User Access Review programs and least-privilege access controls
- Strong understanding of HIPAA, GDPR, and security requirements for PHI and sensitive PII
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 42,189 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee