12 third party risk manager jobs at 11 companies in Vallejo, CA
2w
Save
Mark Applied
Hide
2w
Third Party Security Risk Specialist
Yolo County, California, United States
$9k-$12k/moHybridFull Time
State Controller's Office: California's fiscal controller managing state financial operations and assets.
Develop and run third-party security risk management: assess SOC/ISO reports and SIG/CAIQ questionnaires, evaluate pen tests and vulnerabilities, coordinate vendor onboarding/offboarding, apply NIST/CIS/ISO standards, and provide security recommendations.
Third Party Risk Management and Customer Trust Lead
Foster City, California, United States
$210k-$270k/yrHybridFull Time
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in third-party/vendor risk or GRC, ability to assess vendor risk from SOC 2/pen tests/architecture, contract review/redlining, knowledge of GDPR/CCPA, cross-functional collaboration, and building scalable vendor review processes.
SOC 2, GDPR, CCPA, NIST AI RMF, ISO 42001, EU AI Act
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
10+ YOEBachelor's degree and 10+ years in corporate compliance, third-party risk, supplier due diligence, or related fields. Requires compliance expertise, client advisory, communication, presentation, and relationship management skills.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
Senior Software Engineer, Trust and Third Party Risk Management
United States or Toronto or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$195k-$263k/yrRemoteFull Time
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years software engineering experience; strong TypeScript/React or backend Node.js skills; experience building production web applications; solid database and REST/GraphQL API design knowledge; collaboration and technical leadership.
EliseAI: AI platform automating housing and healthcare business operations.
8+ YOE3+ Mgmt8+ years in GRC or related field with 3+ years leadership; deep expertise in SOC1/SOC2/PCI/HIPAA/ISO/HITRUST; audit program management; vendor risk and third‑party due diligence experience; able to work onsite 4–5 days/week.
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE10+ years in information security with vendor/third-party risk in regulated environments; cloud security; ISO 27001/NIST 800-53/SOC 2/PCI DSS; automation and AI security interest.
Austin or Chicago or New York City or Salt Lake City or San Francisco
$117k-$185k/yrOnsiteFull Time
Gong: AI platform analyzing customer interactions to improve sales performance.
7+ YOE7+ years in third‑party/vendor risk management or GRC; strong knowledge of security/privacy frameworks, vendor assessments, and TPRM tooling; excellent communication and risk translation skills.