36 third party risk jobs at 29 companies in California
1mo
Save
Mark Applied
Hide
1mo
Third Party Risk Management and Customer Trust Lead
Foster City, California, United States
$210k-$270k/yrHybridFull Time
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in third-party/vendor risk or GRC, ability to assess vendor risk from SOC 2/pen tests/architecture, contract review/redlining, knowledge of GDPR/CCPA, cross-functional collaboration, and building scalable vendor review processes.
SOC 2, GDPR, CCPA, NIST AI RMF, ISO 42001, EU AI Act
Senior GRC / Third-Party Risk / Data Protection Analyst
California, United States
$104k-$166k/yrRemoteFull Time
Peraton: National security and mission-critical government technology services provider.
8+ YOEBachelor's degree or equivalent experience, 8+ years in security GRC, third-party risk, or data protection, active CISA or CGRC, NIST control testing, POA&M management, DLP, GRC, U.S. citizenship, and California clearance.
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
Pacific Life: Provides life insurance, annuities, and investment products for financial security.
5+ YOE5+ years TPRM/GRC experience, bachelor’s degree or equivalent, deep knowledge of TPRM frameworks and interconnected risk domains, relevant certifications (CISA, CRISC, CISSP, CRVPM, CTPRP) and experience with TPRM platforms and monitoring.
NIST CSF, ISO 27001, ISO 22301, Shared Assessments SIG/VRMMM
Moody'sNYSE: MCO: Global provider of financial credit ratings and risk data.
10+ YOE10+ years in corporate compliance or third-party risk management; expertise in compliance frameworks and risk solutions; strong client-facing communication; willingness to travel up to 50%; bachelor's degree required.
Applied MaterialsNASDAQ: AMAT: Produces equipment and services for chip and display manufacturing.
3+ YOEBachelor's degree and 3–5+ years in product management, procurement technology, or risk/compliance systems; experience with OneTrust or similar GRC platforms; experience configuring enterprise SaaS and integrations/APIs.
Applied MaterialsNASDAQ: AMAT: Manufacturers of equipment for semiconductor and display production.
3+ YOEBachelor's degree and 3–5+ years in product management or procurement/risk systems; experience with OneTrust or similar GRC platforms, configuring enterprise SaaS, integrations/APIs, and strong stakeholder and analytical skills.
10+ YOEBachelor's degree and 10+ years in corporate compliance, third-party risk, supplier due diligence, or related fields. Requires compliance expertise, client advisory, communication, presentation, and relationship management skills.
Privacy Program Manager, Third Party Risk Measurement - PDPO
San Jose, California, United States
$134k-$236k/yrOnsiteFull Time
TikTok: Global short-form video hosting and social media platform.
5+ YOE5+ years GRC/privacy experience, knowledge of controls frameworks, data privacy regulations, risk identification and mitigation, strong communication and cross-functional collaboration skills.
Washington or Boston or Dallas or Chicago or Miami or Denver or Orange or Los Angeles or Las Vegas or Sacramento or Phoenix or San Diego or United States
$130k-$160k/yrRemoteFull Time
DanaherNYSE: DHR: Develops scientific instruments and diagnostic tools for healthcare markets.
7+ YOE7+ years in third-party/vendor risk, enterprise risk, or vendor security; experience administering vendor questionnaires, reviewing SOC 2/ISO 27001 evidence, scoring at scale, reviewing cybersecurity contract provisions, and operating enterprise risk registers.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
Assistant Vice President (AVP) Security Risk Management
California, United States
RemoteFull Time
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
10+ YOE3+ MgmtRequires 10+ years in information security, cybersecurity risk, technology risk, or IT audit; 5+ years in third-party or M&A cyber risk; 3+ years leading teams; relevant degree or equivalent experience.
Senior Software Engineer, Trust and Third Party Risk Management
United States or Toronto or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$195k-$263k/yrRemoteFull Time
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years software engineering experience; strong TypeScript/React or backend Node.js skills; experience building production web applications; solid database and REST/GraphQL API design knowledge; collaboration and technical leadership.
Governance, Risk Management and Compliance, Senior Director
San Jose, California, United States
$225k-$250k/yrOnsiteFull Time
Astera LabsNASDAQ: ALAB: Designs connectivity solutions for cloud and AI infrastructure.
10+ YOE5+ Mgmt10+ years in GRC/internal audit with 5+ years leading teams; experience with SOX, ERM, SOC 2/ISO 27001/NIST, third-party risk, and executive/Board reporting.
Field Marketing Manager, Third Party & Partner Events
San Francisco or New York City
$105k-$245k/yrHybridFull Time
FigmaNew York Stock Exchange: FIG: Collaborative interface design and prototyping software for teams.
4+ YOERequires 4+ years in event logistics, event operations, or field marketing; vendor and contract negotiation, complex project planning, live-event risk management, and excellent written and verbal communication.
EliseAI: AI platform automating housing and healthcare business operations.
8+ YOE3+ Mgmt8+ years in GRC or related field with 3+ years leadership; deep expertise in SOC1/SOC2/PCI/HIPAA/ISO/HITRUST; audit program management; vendor risk and third‑party due diligence experience; able to work onsite 4–5 days/week.
Toronto or Vancouver or San Diego or Dublin or North America or Europe or Asia
$120k-$155k/yrRemoteFull Time
Trulioo: Provides identity and business verification for global regulatory compliance.
8+ YOE8+ years product management experience focused on KYC/identity, fraud, or risk; experience with ML/Data Science, third-party data providers, and end-to-end product lifecycle; strong analytical and communication skills; Bachelor's or equivalent experience.