36 third party risk jobs at 29 companies in California

1mo
Save
Mark Applied
Hide
Third Party Risk Management and Customer Trust Lead
Foster City, California, United States
$210k-$270k/yr HybridFull Time
Replit
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in third-party/vendor risk or GRC, ability to assess vendor risk from SOC 2/pen tests/architecture, contract review/redlining, knowledge of GDPR/CCPA, cross-functional collaboration, and building scalable vendor review processes.
SOC 2, GDPR, CCPA, NIST AI RMF, ISO 42001, EU AI Act
1mo
Save
Mark Applied
Hide
Third Party Risk Management (TPRM) Analyst (Remote)
United States or California
$85k-$120k/yr RemoteFull Time
CrowdStrike
CrowdStrikeNASDAQ: CRWD: Provides cloud-native endpoint protection and cybersecurity services.
Experience in third-party/vendor risk management, GRC/TPRM tooling, security risk assessment methodologies and control frameworks; bachelor's degree or equivalent experience; preferred security certifications (CISSP, CISM, CRISC, CTPRP).
ServiceNow, OneTrust, ProcessUnity, GRC, BitSight, SecurityScorecard, SOC 1, SOC 2, ISO 27001, ISO 27002, NIST 800-53, CSA-CCM, GDPR, PCI-DSS, SBOM, AI, CrowdStrike
5d
Save
Mark Applied
Hide
Senior GRC / Third-Party Risk / Data Protection Analyst
California, United States
$104k-$166k/yr RemoteFull Time
Peraton
Peraton: National security and mission-critical government technology services provider.
8+ YOEBachelor's degree or equivalent experience, 8+ years in security GRC, third-party risk, or data protection, active CISA or CGRC, NIST control testing, POA&M management, DLP, GRC, U.S. citizenship, and California clearance.
NIST SP 800-53 Rev. 5, SIG, CAIQ, Microsoft Purview, Netskope, Forcepoint, GRC platform, DLP, POA&M, ARC-AMPE, IRS Publication 1075, HIPAA, HITECH, CCPA, CMS, SAWs
2w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey
1mo
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
1mo
Save
Mark Applied
Hide
Third Party Risk Management Capability Lead
Newport Beach, California, United States
$113k-$139k/yr HybridFull Time
Pacific Life
Pacific Life: Provides life insurance, annuities, and investment products for financial security.
5+ YOE5+ years TPRM/GRC experience, bachelor’s degree or equivalent, deep knowledge of TPRM frameworks and interconnected risk domains, relevant certifications (CISA, CRISC, CISSP, CRVPM, CTPRP) and experience with TPRM platforms and monitoring.
NIST CSF, ISO 27001, ISO 22301, Shared Assessments SIG/VRMMM
6d
Save
Mark Applied
Hide
Security Analyst, Third-Party Ecosystem Risk Management
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam or United States or Canada or United Kingdom or Europe
$119k-$176k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
4+ YOERequires 4+ years in vendor risk management, third-party security assessments, risk lifecycle management, security frameworks, program maturation, documentation, communication, and AI-assisted tooling.
SOC 2, ISO 27001, NIST CSF, OneTrust, ProcessUnity, Whistic, SecurityScorecard
1w
Save
Mark Applied
Hide
Subject Matter Expert - Compliance & Third-Party Risk Management
San Francisco or Chicago or New York
$200k-$290k/yr OnsiteFull Time
Moody's
Moody'sNYSE: MCO: Global provider of financial credit ratings and risk data.
10+ YOE10+ years in corporate compliance or third-party risk management; expertise in compliance frameworks and risk solutions; strong client-facing communication; willingness to travel up to 50%; bachelor's degree required.
Artificial Intelligence (AI)
1mo
Save
Mark Applied
Hide
Product Mgr, Third-Party Risk Management
Austin or Santa Clara
$108k-$149k/yr OnsiteFull Time
Applied Materials
Applied MaterialsNASDAQ: AMAT: Produces equipment and services for chip and display manufacturing.
3+ YOEBachelor's degree and 3–5+ years in product management, procurement technology, or risk/compliance systems; experience with OneTrust or similar GRC platforms; experience configuring enterprise SaaS and integrations/APIs.
OneTrust, ServiceNow, Archer, MetricStream, D&B, Rapid Ratings, Sayari, APIs
1mo
Save
Mark Applied
Hide
Product Mgr, Third-Party Risk Management
Austin or Santa Clara
$108k-$149k/yr OnsiteFull Time
Applied Materials
Applied MaterialsNASDAQ: AMAT: Manufacturers of equipment for semiconductor and display production.
3+ YOEBachelor's degree and 3–5+ years in product management or procurement/risk systems; experience with OneTrust or similar GRC platforms, configuring enterprise SaaS, integrations/APIs, and strong stakeholder and analytical skills.
OneTrust, ServiceNow, Archer, MetricStream, D&B, Rapid Ratings, Sayari
1w
Save
Mark Applied
Hide
Let's begin! Subject Matter Expert - Compliance & Third-Party Risk Management (14424)
San Francisco, California, United States
$200k-$290k/yr OnsiteFull Time
Moody's
Moody'sNYSE: MCO: Provides credit ratings, financial research, and risk management software.
10+ YOEBachelor's degree and 10+ years in corporate compliance, third-party risk, supplier due diligence, or related fields. Requires compliance expertise, client advisory, communication, presentation, and relationship management skills.
AI
1mo
Save
Mark Applied
Hide
Privacy Program Manager, Third Party Risk Measurement - PDPO
San Jose, California, United States
$134k-$236k/yr OnsiteFull Time
TikTok
TikTok: Global short-form video hosting and social media platform.
5+ YOE5+ years GRC/privacy experience, knowledge of controls frameworks, data privacy regulations, risk identification and mitigation, strong communication and cross-functional collaboration skills.
ISO, NIST, GDPR, CCPA
2mo
Save
Mark Applied
Hide
Senior Cybersecurity Risk Analyst - USA Remote
Washington or Boston or Dallas or Chicago or Miami or Denver or Orange or Los Angeles or Las Vegas or Sacramento or Phoenix or San Diego or United States
$130k-$160k/yr RemoteFull Time
Danaher
DanaherNYSE: DHR: Develops scientific instruments and diagnostic tools for healthcare markets.
7+ YOE7+ years in third-party/vendor risk, enterprise risk, or vendor security; experience administering vendor questionnaires, reviewing SOC 2/ISO 27001 evidence, scoring at scale, reviewing cybersecurity contract provisions, and operating enterprise risk registers.
Shared Assessments SIG, NIST SP 800-161, ISO/IEC 27036, GDPR, HIPAA, PCI DSS, SOX, SOC 2, ISO 27001, NIST AI RMF, ISO/IEC 42001, OneTrust, ServiceNow IRM, RSA Archer
1mo
Save
Mark Applied
Hide
Manager of Risk & Trust Operations
New York City or San Francisco
OnsiteFull Time
Reflection AI
Reflection AI: Developing open-source frontier artificial intelligence models and coding agents.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
GRC platforms
1w
Save
Mark Applied
Hide
Assistant Vice President (AVP) Security Risk Management
California, United States
RemoteFull Time
CVS Health
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
10+ YOE3+ MgmtRequires 10+ years in information security, cybersecurity risk, technology risk, or IT audit; 5+ years in third-party or M&A cyber risk; 3+ years leading teams; relevant degree or equivalent experience.
NIST CSF, NIST 800-53, ISO 27001, HITRUST, SOC 2, PCI DSS, TPRM, GRC
1mo
Save
Mark Applied
Hide
Senior Software Engineer, Trust and Third Party Risk Management
United States or Toronto or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$195k-$263k/yr RemoteFull Time
Vanta
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years software engineering experience; strong TypeScript/React or backend Node.js skills; experience building production web applications; solid database and REST/GraphQL API design knowledge; collaboration and technical leadership.
TypeScript, React, Node.js, REST, GraphQL, AI agents, LLM APIs, OpenAI, Anthropic, eval frameworks
3w
Save
Mark Applied
Hide
Governance, Risk Management and Compliance, Senior Director
San Jose, California, United States
$225k-$250k/yr OnsiteFull Time
Astera Labs
Astera LabsNASDAQ: ALAB: Designs connectivity solutions for cloud and AI infrastructure.
10+ YOE5+ Mgmt10+ years in GRC/internal audit with 5+ years leading teams; experience with SOX, ERM, SOC 2/ISO 27001/NIST, third-party risk, and executive/Board reporting.
SOX, COSO, SOC 2, ISO 27001, NIST, GDPR, CCPA
1d
Save
Mark Applied
Hide
Field Marketing Manager, Third Party & Partner Events
San Francisco or New York City
$105k-$245k/yr HybridFull Time
Figma
FigmaNew York Stock Exchange: FIG: Collaborative interface design and prototyping software for teams.
4+ YOERequires 4+ years in event logistics, event operations, or field marketing; vendor and contract negotiation, complex project planning, live-event risk management, and excellent written and verbal communication.
Cvent, RainFocus, Salesforce, Soominfo, AI
2mo
Save
Mark Applied
Hide
Director of Governance, Risk, and Compliance
New York City or San Francisco or Toronto
$200k-$275k/yr OnsiteFull Time
EliseAI
EliseAI: AI platform automating housing and healthcare business operations.
8+ YOE3+ Mgmt8+ years in GRC or related field with 3+ years leadership; deep expertise in SOC1/SOC2/PCI/HIPAA/ISO/HITRUST; audit program management; vendor risk and third‑party due diligence experience; able to work onsite 4–5 days/week.
2mo
Save
Mark Applied
Hide
Senior Product Manager (KYC - Fraud & Risk)
Toronto or Vancouver or San Diego or Dublin or North America or Europe or Asia
$120k-$155k/yr RemoteFull Time
Trulioo
Trulioo: Provides identity and business verification for global regulatory compliance.
8+ YOE8+ years product management experience focused on KYC/identity, fraud, or risk; experience with ML/Data Science, third-party data providers, and end-to-end product lifecycle; strong analytical and communication skills; Bachelor's or equivalent experience.
ML, LLMs, AI/ML Ops