12 third party risk manager jobs at 11 companies in Vallejo, CA

2w
Save
Mark Applied
Hide
Third Party Security Risk Specialist
Yolo County, California, United States
$9k-$12k/mo HybridFull Time
State Controller's Office
State Controller's Office: California's fiscal controller managing state financial operations and assets.
Develop and run third-party security risk management: assess SOC/ISO reports and SIG/CAIQ questionnaires, evaluate pen tests and vulnerabilities, coordinate vendor onboarding/offboarding, apply NIST/CIS/ISO standards, and provide security recommendations.
SOC 1, SOC 2, SOC 3, ISO/IEC 27001, SIG, CAIQ, NIST 800-53, NIST CSF, CIS20
1mo
Save
Mark Applied
Hide
Third Party Risk Management and Customer Trust Lead
Foster City, California, United States
$210k-$270k/yr HybridFull Time
Replit
Replit: Cloud-based platform for building and hosting software applications.
8+ YOE8+ years in third-party/vendor risk or GRC, ability to assess vendor risk from SOC 2/pen tests/architecture, contract review/redlining, knowledge of GDPR/CCPA, cross-functional collaboration, and building scalable vendor review processes.
SOC 2, GDPR, CCPA, NIST AI RMF, ISO 42001, EU AI Act
2w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey
1mo
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
7+ YOE7+ years in security-focused TPRM, experience with vendor risk assessments, cloud/SaaS/AI security reviews, program building, audits, and remediation tracking; Bachelor's or Master's degree in related field.
CAIQ, SIG, SOC 2 Type 2, Penetration Test, NIST, ISO 27001, PCI-DSS, AWS, Azure, GCP, Covey Scout
3d
Save
Mark Applied
Hide
Security Analyst, Third-Party Ecosystem Risk Management
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam or United States or Canada or United Kingdom or Europe
$119k-$176k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
4+ YOERequires 4+ years in vendor risk management, third-party security assessments, risk lifecycle management, security frameworks, program maturation, documentation, communication, and AI-assisted tooling.
SOC 2, ISO 27001, NIST CSF, OneTrust, ProcessUnity, Whistic, SecurityScorecard
6d
Save
Mark Applied
Hide
Let's begin! Subject Matter Expert - Compliance & Third-Party Risk Management (14424)
San Francisco, California, United States
$200k-$290k/yr OnsiteFull Time
Moody's
Moody'sNYSE: MCO: Provides credit ratings, financial research, and risk management software.
10+ YOEBachelor's degree and 10+ years in corporate compliance, third-party risk, supplier due diligence, or related fields. Requires compliance expertise, client advisory, communication, presentation, and relationship management skills.
AI
1mo
Save
Mark Applied
Hide
Manager of Risk & Trust Operations
New York City or San Francisco
OnsiteFull Time
Reflection AI
Reflection AI: Developing open-source frontier artificial intelligence models and coding agents.
15+ YOE15+ years in risk operations, compliance, internal audit or information security with leadership experience; experience building controls assurance, third-party risk, incident response, and AI safety; familiarity with auditors/regulators and GRC platforms.
GRC platforms
1mo
Save
Mark Applied
Hide
Senior Software Engineer, Trust and Third Party Risk Management
United States or Toronto or San Francisco or New York City or London or Dublin or Tel Aviv or Sydney
$195k-$263k/yr RemoteFull Time
Vanta
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years software engineering experience; strong TypeScript/React or backend Node.js skills; experience building production web applications; solid database and REST/GraphQL API design knowledge; collaboration and technical leadership.
TypeScript, React, Node.js, REST, GraphQL, AI agents, LLM APIs, OpenAI, Anthropic, eval frameworks
2mo
Save
Mark Applied
Hide
Director of Governance, Risk, and Compliance
New York City or San Francisco or Toronto
$200k-$275k/yr OnsiteFull Time
EliseAI
EliseAI: AI platform automating housing and healthcare business operations.
8+ YOE3+ Mgmt8+ years in GRC or related field with 3+ years leadership; deep expertise in SOC1/SOC2/PCI/HIPAA/ISO/HITRUST; audit program management; vendor risk and third‑party due diligence experience; able to work onsite 4–5 days/week.
3w
Save
Mark Applied
Hide
GRC Manager
San Francisco or New York or United States
$150k-$250k/yr HybridFull Time
Baseten
Baseten: Scalable infrastructure platform for deploying and serving AI models.
5+ YOE5+ years GRC or security compliance experience in SaaS/cloud; strong knowledge of SOC 2, ISO 27001, NIST, GDPR; audit and certification management; third-party risk and cross-functional collaboration.
Vanta, Drata, Secureframe, Anecdotes, AWS, GCP
2mo
Save
Mark Applied
Hide
Vendor Security Manager
San Francisco, California, United States
OnsiteFull Time
Sierra
Sierra: Conversational AI platform for building enterprise customer agents
10+ YOE10+ years in information security with vendor/third-party risk in regulated environments; cloud security; ISO 27001/NIST 800-53/SOC 2/PCI DSS; automation and AI security interest.
AWS, GCP, IAM, VPC, encryption, logging, monitoring, GRC tooling
2w
Save
Mark Applied
Hide
Senior TPRM Security Lead
Austin or Chicago or New York City or Salt Lake City or San Francisco
$117k-$185k/yr OnsiteFull Time
Gong
Gong: AI platform analyzing customer interactions to improve sales performance.
7+ YOE7+ years in third‑party/vendor risk management or GRC; strong knowledge of security/privacy frameworks, vendor assessments, and TPRM tooling; excellent communication and risk translation skills.
Zip