Third Party Risk Manager
$207.4k - $259.2kFull-time
Archer
Archer is an aerospace company based in San Jose, California building an all-electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all-electric aircraft that can carry four passengers while producing minimal noise. Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members. Archer is an aerospace company based in San Jose, California building an all-electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all-electric aircraft that can carry four passengers while producing minimal noise. Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members. Job Overview Archer is building the future of urban air mobility. Our supply chain spans hundreds of vendors — from avionics hardware suppliers to cloud infrastructure providers — and a compromise anywhere in that ecosystem could impact aircraft certification, delay FAA approvals, or expose sensitive information. You are key to effective enforcement of our extended enterprise third-party risk posture. Archer is seeking a Senior Third Party Risk Management (TPRM) Engineer to execute our vendor cyber risk function across all tiers of our supplier ecosystem. In this high-visibility role, you will use platforms like BitSight to continuously monitor, investigate, triage, and action security risks introduced by third-party partners and their downstream (4th-party) suppliers. You will serve as the connective tissue between Security, Sourcing, Legal, and executive leadership — translating third party risk indicators into actionable threat intelligence and coordinated response actions while ensuring strict compliance with NIST SP 800-171, CMMC Level 2, and SOX ITGC requirements. This role requires both hands-on technical depth and program-building acumen. You will support and execute Archer's TPRM function from the ground up, develop risk-tiered due diligence processes, and ensure vendor security posture remains aligned with our CMMC Level 2, NIST SP 800-161, and DFARS obligations as we grow our defense programs. Key Responsibilities
- Operate BitSight and complementary EASM/continuous monitoring platforms as the primary lens into Archer's third-party attack surface. Maintain a tiered vendor inventory, configure portfolio monitoring, tune alert thresholds, and ensure new vendors are onboarded into the program at contract execution.
- Conduct deep-dive investigations into vendor risk signals — including unpatched CVEs, exposed services, credential leaks, certificate anomalies, business deterioration, and dark web indicators. Correlate external ratings data with internal telemetry to assess true business exposure and eliminate false positives before escalation.
- Extend visibility beyond direct vendors to identify and monitor critical 4th-party sub-processor dependencies. Map supply chain concentration risks, single points of failure, and foreign ownership or influence (FOCI) concerns for vendors supporting defense programs or handling CUI.
- Drive risk closure by issuing formal findings, coordinating with internal vendor relationship owners, and tracking remediation commitments through resolution. Engage procurement and legal channels when vendors are non-responsive or remediation timelines are unacceptable.
- Produce crisp, executive-quality risk briefings, board-level metrics, and ad-hoc deep-dives for the CISO, General Counsel, and program security leads. Escalate critical or rapidly-deteriorating vendor risk findings in near-real-time with clear business impact statements and recommended courses of action.
- Design and administer risk-tiered security questionnaires for new and renewing vendors. Evaluate responses, validate claims against external signals, execute integrated due diligence checkpoints in Archer's procurement workflow.
- Influence, develop and maintain TPRM policies, standards, and procedures aligned to NIST SP 800-161 (C-SCRM), CMMC Level 2 SR practices, and ISO 27036. Provide transparency to external audits and government assessments by maintaining organized evidence of vendor risk controls and remediation activity.
- Serve as the TPRM lead during vendor-related security incidents — coordinating with Archer's internal IR team, managing vendor communications under legal hold protocols, and driving root cause analysis and contractual remedies following a third-party breach.
- 7+ years in cybersecurity with at least 3 years of dedicated third-party or supply chain risk management experience
- Demonstrated hands-on proficiency with BitSight or an equivalent continuous monitoring platform — including alert tuning, portfolio management, vendor engagement workflows, and peer benchmarking
- Deep working knowledge of NIST SP 800-161 (C-SCRM), NIST CSF, CMMC Level 2 SR and CA practices, and ISO 27036 as they apply to vendor security governance
- Experience conducting structured vendor security due diligence across SaaS, cloud infrastructure, hardware manufacturers, and professional services suppliers
- Proven ability to investigate and triage cyber risk findings at scale — correlating external signals with business context to produce prioritized, actionable intelligence for both technical and non-technical stakeholders
- Familiarity with 4th-party risk mapping, sub-processor disclosure reviews, and supply chain concentration risk analysis
- Excellent written and verbal communication skills — able to translate complex vendor risk findings into executive-ready briefings, board-level dashboards, and actionable
- Eligibility to obtain a DoD Secret security clearance
- Certifications: CTPRP (Prevalent), CRISC, CISSP, CISM, or equivalent risk management credentials
- Active DoD Secret or Top Secret/SCI clearance
- Familiarity with ITAR/EAR data sharing constraints and their implications for vendor contracting and CUI handling
- Exposure to FOCI (Foreign Ownership, Control, or Influence) assessments
- Experience integrating TPRM tooling with GRC platforms or building risk workflow automation (e.g., auto-routing findings, SLA tracking, contract clause triggers)
- Prior startup or high-growth company experience — comfort operating with limited bureaucracy and building programs that scale with business growth
Vacancy posted 17 days ago
Similar jobs that could be interesting for youBased on the Third Party Risk Manager in California vacancy
- ...geographic information systems, and emergency medical services. The Risk Manager is responsible for developing, coordinating, and managing the... ...other claim‑related matters with Human Resources, managers, third‑party administrators, insurance representatives, legal counsel, and...SuggestedContract workTemporary workFor contractorsLocal areaFlexible hoursAfternoon shift
$110k
...Enterprise Risk Manager – $110K – San Jose, CA – Job # 3759 Who We Are: The Symicor Group is a boutique talent acquisition firm based... ...with strategic goal setting and business planning. Reviewing third party independent reviews of risk, including but not limited to external...Suggested$102.96k
...Overview The Risk Manager leads and supports the Risk Management Team. The Risk Manager manages all facets of the risk management function... ...and timely administration of claims in collaboration with third-party claims administrator for liability, worker\'s compensation, and...SuggestedContract workWork at office$97k - $114k
...Responsibilities: MV Transportation is seeking a dedicated, experienced Risk Manager to oversee all aspects of risk management, safety... ...closely with internal teams, insurance carriers, and third-party administrators to ensure efficient processing and resolution....SuggestedContract workWork at officeLocal areaImmediate start- ...Enterprise Risk Manager Under direction of the Deputy General Counsel, the Enterprise Risk Manager develops, implements, manages, and... ...Deputy General Counsel. Coordinate with the District's third-party administrator (TPA) to manage, monitor, and resolve claims efficiently...SuggestedFor contractorsWork at office
- ...Risk Manager Applications will be accepted and reviewed on a continuous basis. This recruitment may close at any time after that date... ...risk management, workplace safety and industrial hygiene, third-party loss prevention, self insured, self-administered liability claims...Contract workLocal area
$10,471.07 per month
...available, as we're looking for the right person to serve as Risk Manager in our Human Resources Department. The ideal candidate is... ...risk management, workplace safety and industrial hygiene, third-party loss prevention, self insured, self-administered liability claims...Full timeContract workLocal areaImmediate startFlexible hours$174.4k - $213.2k
...Description This Opportunity WSP is seeking a Senior Risk Manager to join our Project Controls group in San Francisco, CA. Your... ...authorized to work in the United States. NOTICE TO THIRD PARTY AGENCIES: WSP does not accept unsolicited resumes...Contract workLocal areaFlexible hours$108k - $180k
...accessible and affordable. Position Summary SHEIN Global Security & Risk Management oversees security infrastructure, risk management, data... ...units, critical processes and information assets. Conduct third‑party risk assessments and security reviews of third‑party...Temporary workWork at officeFlexible hours- The Risk Manager is responsible for leading and overseeing Mono County's comprehensive risk management program, protecting the County's... ...departments, legal counsel, insurance carriers, brokers, and third-party administrators to investigate claims, manage litigation, implement...Work at officeShift work
- ...sales goal objectives by developing and managing a client portfolio. Provides customers with... ...1 SPF referral per month. Generate 2 third party referrals annually. Generate 2... ...by RMM, manage problem loans to minimize risk. Communicate status and developments to...Full timeWork experience placement
$125.84k - $157.3k
As Marqeta’s Investor Relations Manager you will support the company’s investor relations efforts. The team is focused on maximizing... ...underlying business and financial metric assumptions Collaborate with third‑party service providers, including those for web‑hosting,...Work at officeRemote workFlexible hours1 day per week$160k - $170k
...’d love to have you join us. Responsibilities and Duties The Risk Manager is responsible for the day-to-day identification, assessment,... ...brokers, insurance-appointed counsel, internal stakeholders, and third-party claimants, and plays a critical role in protecting the...Work at officeNight shiftWeekend work$174.4k - $213.2k
...WSP is seeking a Senior Risk Manager to join our Project Controls group in San Francisco, CA. Your Impact Act as the risk management subject matter expert on assigned project, program, portfolio being accountable for the risk management performance on assigned commissions...Contract workLocal area$90k - $105k
...RISK MANAGER Location: Los Angeles, CA , The Valley Schedule: Full-Time- Onsite Pay: $90,000 - $105,000/year Type: Direct Hire Overview: A well-established nonprofit institution is seeking a Risk Manager to join their Finance team...Full timeFor contractorsWork at officeLocal area- ...Position At XL Industries Inc Reports to: Vice President / Director Risk Management Responsibilities Responsible for the administration of risk management programs and initiatives for XL Construction and XL Industries other affiliated entities. This position regularly...Contract workFor contractorsFor subcontractor
- ...Facility Risk Manager Under the supervision of the Director of PI/RM/CO, the Facility Risk Manager (FRM) has broad responsibility to protect the hospital's assets from loss. The FRM is responsible for coordinating the loss control efforts and advising management and...Local area
$90k - $105k
...RISK MANAGER Location: Los Angeles, CA, The Valley Schedule: Full-Time- Onsite Pay: $90,000 - $105,000/year Type: Direct Hire Overview: A well-established nonprofit institution is seeking a Risk Manager to join their Finance team. Reporting directly to the CFO, this role...Full timeWork at office$20 per hour
...test solutions, located in Irvine California. Responsibilities: Oversee the lifecycle of contractual technical Full-time Assistant Managers help oversee in-store operations and can demonstrate leadership. The Assistant Manager plays a major role in ensuring the store is...Hourly payFull timePart timeSummer workWork at officeImmediate startFlexible hours$175k - $225k
...Position Summary The Director of Enterprise Risk Management (ERM) reports to the Chief Enterprise Risk Officer and leads the execution... ...related to strategic initiatives, new products, technologies, and third‑party relationships. Governance, Committees & Reporting Lead ERM...Work at officeLocal areaFlexible hours- ...Job Description Job Description Risk Manager Position Summary Under the direction of the Director, Insurance, Safety & Risk... ...injured workers, operations management, insurance carriers, third-party administrators, brokers, and legal counsel. Monitor claim...For contractorsWork experience placementWork at office
$156k - $234k
...the Career for You? The Vice President, Head of Enterprise Risk Management (ERM) is a senior leadership role responsible for designing,... ...incident response coordination. Vendor Risk Management Oversee the Third-Party/Vendor Risk Management program, ensuring appropriate due...$140k - $200k
...innovative financial solutions. You will apply your financial management and data analytics expertise to solve complex client problems and... ...client sales of additional actuarial, financial, and/or risk solutions Provides consulting quality reviews and client delivery...Temporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours$75k - $150k
...Overview East West Bank is seeking a Portfolio Manager. Responsibilities Monitor loan repayment... .... Responsible for underwriting credit risk of new and existing loan deals and... ...credit supervision. Review and analyze third‑party reports such as appraisals, field exams...- ...Loan Portfolio Manager West Coast Community Bank is a top-rated community bank with... ...analyze borrower financials. Access credit risk and evaluate collateral. Required... ...do not accept unsolicited resumes from third-party recruiters or agencies. Submissions...Casual workWork at officeLocal areaAfternoon shift
$124.7k - $127k
...TITLE: SENIOR PORTFOLIO MANAGER STATUS: EXEMPT REPORTS TO: MANAGER - COMMERCIAL... ...needs, and goals to make acceptable risk determinations for existing portfolio.... ...EXTERNAL: Industry peers and leaders, legal third-party vendors, community, regulators and trade...Work at officeRemote work$141.9k - $204.1k
...and other industries worldwide. Role Summary Investor Relations Manager reporting to the Vice President, Investor Relations. Core strategic... ...; proactively identify deviations, key drivers, and emerging risks or opportunities in Street expectations; deliver timely, data‑driven...Full timeWorldwideShift work$100k - $115k
...again". We are looking for a highly specialized Clinical Risk Manager who seamlessly blends sharp clinical risk acumen with deep empathy... ...their email address ends with @prenuvo.com. We do not use third-party recruitment services or any other email domains for hiring...Immediate startRemote workFlexible hours$125k - $135k
...Control Risks' Embedded Consulting team is hiring a Regional Operations Manager for the Americas to join our team supporting a major tech client. This role will work with their investigations team that helps monitor and mitigate platform risks to the company as well as...Work at officeRemote workFlexible hours- ...direction of the VP of Lending, the Portfolio Manager is responsible for managing the day‑to‑... ...with internal loan policy as well as third‑party guidelines such as and not limited to... ...portfolio are periodically reviewed and risk‑rated, as per the Risk Rating System. Support...Work experience placementWork at officeWeekend workAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third Party Risk Manager. Be the first to apply!

