Source Job

$87,500–$111,500/yr
US Unlimited PTO

  • Conduct risk assessments for critical and operationally significant third-party entities.
  • Identify, track, and drive remediation of control gaps and security risks uncovered throughout the assessment lifecycle.
  • Partner closely with cross-functional teams to manage third-party risk holistically and stay ahead of emerging risks, including generative and agentic AI.

Cybersecurity Risk Management GRC AI

8 jobs similar to Sr Third Party Risk Analyst (TPRM)

Jobs ranked by similarity.

$125,000–$155,000/yr

  • Responsible for managing and growing a comprehensive third-party risk management program across the organization.
  • Ensuring that Privia Health's information assets are safeguarded against cyber threats originating from third and fourth parties.
  • Leading the Third Party Access Committee (TPAC), driving compliance with regulations and implementing industry best practices for vendor risk management.

Privia Health is a technology-driven, national physician enablement company that collaborates with medical groups, health plans, and health systems to optimize physician practices, improve patient experiences, and reward doctors for delivering high-value care. The Privia Platform is led by top industry talent and exceptional physician leadership.

Costa Rica

  • Lead end-to-end Third Party Risk Assessments for new and existing vendors.
  • Own the ongoing monitoring and tracking of vendor risk across Smartsheet's third-party portfolio.
  • Evaluate vendor security documentation and translate findings into clear, actionable risk summaries for stakeholders.

Smartsheet empowers people and teams to achieve anything. They provide tools for work management and scalable solutions, fostering a culture that values diverse perspectives and supports employee growth and impact.

US

  • Responsible for comprehensive information security risk assessments of third-party vendors.
  • Evaluate vendors to ensure they meet internal information security policies, HIPAA, PCI DSS requirements, and applicable regulatory standards.
  • Thoughtfully analyze vendor-provided documentation, proactively identify potential risks, and produce detailed and accurate assessment reports.

Planned Parenthood is the nation’s leading provider and advocate of high-quality, affordable sexual and reproductive health care. They have health centers, programs in schools and communities, and online resources, and are a trusted source of reliable education and information.

$80,000–$120,000/yr
US

  • Execute end-to-end third-party and vendor risk assessments.
  • Develop, maintain, and enhance risk metrics, dashboards, and reporting.
  • Assist with additional GRC activities as needed, including policy management, risk assessments, control testing, and compliance initiatives

Aprio is a Top 20 CPA and advisory firm that accounts for anything. With over 3,200 team members and 40 U.S. office locations, plus international offices, they bring proven expertise and strategic foresight to fast-growing industries.

$144,540–$180,960/yr
Canada

  • Own Security Governance: maintain and evolve security policies, standards, and control frameworks.
  • Lead the Security TPRM function across vendor lifecycle: intake/onboarding, due diligence, contracting handoffs, ongoing monitoring.
  • Build, coach, and scale the Governance and TPRM teams: hiring, performance management, career development, and team morale.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The majority of their roles are remote. They offer competitive benefits anchored to the core value of people come first.

US

  • Define and evolve security governance and risk management strategy, aligning function-level priorities with enterprise objectives and the security roadmap.
  • Lead security-related audits, assessments, and regulatory inquiries in partnership with Legal, Compliance, Privacy, and Internal Audit.
  • Manage and hold accountable a third-party GRC services vendor, ensuring delivery quality, prioritization, and alignment to Clover’s risk appetite.

Clover Health is reinventing health insurance by combining data with human empathy to keep members healthier. They've created custom software and analytics to empower their clinical staff to intervene and provide personalized care. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

$151,000–$170,000/yr
Global Unlimited PTO 11w maternity

  • As the first dedicated InfoSec hire, you'll secure organizational systems, data, and operations.
  • You will develop and maintain a practical framework for securely deploying AI tools across the organization.
  • You will lead security incident response, investigate alerts, and coordinate containment.

Customer.io's platform is used by over 8,000 companies to send billions of messages daily. They power automated communication and help teams send smarter messages using real-time behavioral data, operating as a globally distributed, remote-first company.

US

  • Serve as the outsourced CISO for 8–12 clients, providing executive-level security leadership on a fractional basis
  • Conduct security risk assessments, gap analyses, and penetration testing oversight for prospective and current clients
  • Develop and maintain security programs, policies, and incident response plans tailored to each client's risk profile and regulatory environment

Reputation Management Consultants (RMC) is an affiliated organization with a premier advisory firm specializing in reputation management and strategic consulting for mid-market companies and high-profile clients. They are launching a dedicated cybersecurity division to address a critical truth our clients face every day: a data breach is a reputation event; and are building an AI-powered cybersecurity practice from the ground up.