18 third party risk manager jobs at 17 companies in Berkeley, CA
2mo
Save
Mark Applied
Hide
2mo
Program Manager, Third Party Risk
Atlanta or Chicago or New York City or Seattle or South San Francisco
$124k-$185k/yrOnsiteFull Time
Stripe: Provides global financial infrastructure and payment processing for businesses.
4+ YOE4+ years in risk or compliance (third-party risk preferred), program/project management, stakeholder management, strong communication, cross-functional collaboration, and data analysis skills.
Third Party Risk Management and Customer Trust Lead
Foster City, California, United States
$210k-$270k/yrHybridFull Time
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in third-party/vendor risk or GRC, ability to assess vendor risk from SOC 2/pen tests/architecture, contract review/redlining, knowledge of GDPR/CCPA, cross-functional collaboration, and building scalable vendor review processes.
SOC 2, GDPR, CCPA, NIST AI RMF, ISO 42001, EU AI Act
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
Applied MaterialsNASDAQ: AMAT: Produces equipment and services for chip and display manufacturing.
3+ YOEBachelor's degree and 3–5+ years in product management, procurement technology, or risk/compliance systems; experience with OneTrust or similar GRC platforms; experience configuring enterprise SaaS and integrations/APIs.
Applied MaterialsNASDAQ: AMAT: Manufacturers of equipment for semiconductor and display production.
3+ YOEBachelor's degree and 3–5+ years in product management or procurement/risk systems; experience with OneTrust or similar GRC platforms, configuring enterprise SaaS, integrations/APIs, and strong stakeholder and analytical skills.
Privacy Program Manager, Third Party Risk Measurement - PDPO
San Jose, California, United States
$134k-$236k/yrOnsiteFull Time
TikTok: Global short-form video hosting and social media platform.
5+ YOE5+ years GRC/privacy experience, knowledge of controls frameworks, data privacy regulations, risk identification and mitigation, strong communication and cross-functional collaboration skills.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
Senior Software Engineer, Trust and Third Party Risk Management
United States or Toronto or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$195k-$263k/yrRemoteFull Time
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years software engineering experience; strong TypeScript/React or backend Node.js skills; experience building production web applications; solid database and REST/GraphQL API design knowledge; collaboration and technical leadership.
EquinixNASDAQ: EQIX: Provides global data center colocation and digital interconnection services.
Proven experience in procurement governance and third-party risk management in complex global enterprises; experience building governance frameworks, audit-ready controls, executive reporting, and leading global teams; bachelor’s required; senior people leadership experience.
Governance, Risk Management and Compliance, Senior Director
San Jose, California, United States
$225k-$250k/yrOnsiteFull Time
Astera LabsNASDAQ: ALAB: Designs connectivity solutions for cloud and AI infrastructure.
10+ YOE5+ Mgmt10+ years in GRC/internal audit with 5+ years leading teams; experience with SOX, ERM, SOC 2/ISO 27001/NIST, third-party risk, and executive/Board reporting.
EliseAI: AI platform automating housing and healthcare business operations.
8+ YOE3+ Mgmt8+ years in GRC or related field with 3+ years leadership; deep expertise in SOC1/SOC2/PCI/HIPAA/ISO/HITRUST; audit program management; vendor risk and third‑party due diligence experience; able to work onsite 4–5 days/week.
AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Experienced project manager to scope and run Wallet and Payments projects, coordinate cross-functional engineering and third-party partners, prepare documentation, communicate status, manage risk, and drive process improvements.
5+ YOEBachelor's in a technical field or equivalent, 5+ years program management, third-party partnership and risk management experience; cross-functional project leadership; data center experience preferred.
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
United States or Canada or Columbus or Austin or San Francisco or New York City
$172k-$238k/yrRemoteFull Time
UpstartNasdaq: UPST: AI-powered lending marketplace for consumer and automotive loans.
7+ YOE7+ years in third-party risk/vendor management or related regulated financial services operations; experience overseeing critical vendor relationships, risk tiering, due diligence, monitoring, issue remediation, and leading analysts.
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE10+ years in information security with vendor/third-party risk in regulated environments; cloud security; ISO 27001/NIST 800-53/SOC 2/PCI DSS; automation and AI security interest.
Austin or Chicago or New York City or Salt Lake City or San Francisco
$117k-$185k/yrOnsiteFull Time
Gong: AI platform analyzing customer interactions to improve sales performance.
7+ YOE7+ years in third‑party/vendor risk management or GRC; strong knowledge of security/privacy frameworks, vendor assessments, and TPRM tooling; excellent communication and risk translation skills.