49 third party risk manager jobs at 42 companies in Hell's Kitchen, NY
1mo
Save
Mark Applied
Hide
1mo
Third Party Risk Manager
New York City or Chicago or Indianapolis or Charlotte
$60k-$115k/yrRemoteFull Time
Crowe: Global professional services firm providing audit, tax, and consulting.
5+ YOEBachelor's degree,5–8+ years IT/cybersecurity/third-party risk experience,one of CISSP/CISA/CTPRA required (CRISC preferred),knowledge of SOC2/ISO27001/NIST/HIPAA/PCI,ability to lead teams and travel 20%–50% annually.
American ExpressNYSE: AXP: Global financial services and credit card payment network.
3+ YOERequires 3+ years in third-party resilience risk management or business continuity, a bachelor's degree, strong problem-solving and communication skills, and stakeholder collaboration experience.
BlackRockNYSE: BLK: Provides investment management and financial technology services globally.
10+ YOE10+ years enterprise/third-party risk experience, BS/BA required, experience building third-party testing programs and operational resilience, strong communication and stakeholder management, working knowledge of third-party regulatory requirements.
Regeneron PharmaceuticalsNASDAQ: REGN: Discovers and develops medicines for serious diseases.
12+ YOEBachelor's degree,12+ years progressive TPRM experience in regulated industries,previous people management experience,ability to use AI-enabled risk tools,and partner across Procurement,Legal,Compliance and InfoSec.
Lord Abbett: Independent investment firm providing active asset management services.
5+ YOEBachelor's preferred; 5+ years in cybersecurity/technology risk with TPRM experience; familiarity with NIST, ISO 27001, SOC 2; knowledge of IAM, cloud security; relevant certs (CISSP,CISA,GIAC,Security+,CRVPM) a plus.
RegeneronNasdaq: REGN: Discovers and manufactures medicines for serious diseases.
12+ YOE3+ MgmtBachelor’s degree; 12+ years in TPRM; experience in pharmaceutical/biotech regulated environments; leadership experience; experience with TPRM technologies and AI-enabled tools.
TPRM platforms, AI-enabled risk tools, automation, data analytics
SMBC GroupNew York Stock Exchange: SMFG: Provides global banking, investment, securities, and consumer finance services.
12+ YOE7+ MgmtBachelor's degree, 12+ years in vendor/third-party/operational risk, 7+ years leadership, strong regulatory and stakeholder experience, vendor risk frameworks and audit/regulatory management.
3+ YOERequires 3+ years in risk assessment and third-party risk management, TPRM platform experience, security documentation assessment, knowledge of NIST, ISO 27001, and Cyber Risk Institute frameworks, plus strong Microsoft Office, communication, and analytical skills.
Microsoft Office, Prevalent, NIST Cybersecurity Framework, ISO/IEC 27001, Cyber Risk Institute Profile, SOC 2
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
Municipal Credit Union: Provides banking and financial services to members in New York.
5+ YOEBachelor's degree and 5+ years in financial services and vendor/third‑party risk management; knowledge of operational risk, regulatory compliance, IT risk; preferred third‑party/vendor certifications.
Betterment: Automated investment management and retirement planning platform.
4+ YOE4+ years in financial services operational risk (third-party risk, fraud, incident management, etc.), proficiency with SQL and AI/automation tools, strong written/verbal communication and judgment. CISA a plus.
Director, Third-Party Risk Management and Technical Information Security Lead
New York City or Thessaloniki
$177k-$294k/yrHybridFull Time
PfizerNYSE: PFE: Develops and manufactures vaccines and medicines for global healthcare
8+ YOEBachelor’s degree with 8+ years, master’s with 7+ years, or Ph.D. with 5+ years; 8+ years in cybersecurity, cyber risk, GRC, TPRM, security architecture, IT risk, or audit; team leadership required.
Moody'sNYSE: MCO: Global provider of financial credit ratings and risk data.
10+ YOE10+ years in corporate compliance or third-party risk management; expertise in compliance frameworks and risk solutions; strong client-facing communication; willingness to travel up to 50%; bachelor's degree required.
Capital OneNYSE: COF: A diversified financial services providing banking and credit products.
4+ YOERequires a high school diploma or GED, 4+ years of financial services risk management, and 2+ years each in payment networks, third-party risk or governance, and risk, compliance, or legal oversight.
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOERequires 4+ years risk management in financial services, 2+ years payment network and third‑party/risk governance experience, HS diploma or GED, testing/monitoring, data analysis, stakeholder collaboration, and strong communication.
Dalio Family Office: Manages the private wealth and philanthropy of the Dalio family.
7+ YOE7+ years in vendor/third-party risk, cybersecurity, or related fields; bachelor’s degree in a related discipline; experience owning TPRM programs, threat modeling, and communicating risk to executives.
STRIDE, PASTA, OWASP, ASVS, API Security Top 10, LLM/Agentic Top 10, NIST SP 800-53, NIST SP 800-161, NIST CSF 2.0, NIST SP 800-207, MITRE ATT&CK, SOC 2, ISO 27001, SSO, SCIM, OAuth, DLP, BYOK, VPC peering, FAIR