Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Third Party Risk Manager

$207.4k - $259.2k
Full-time

Archer

Archer is an aerospace company based in San Jose, California building an all-electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all-electric aircraft that can carry four passengers while producing minimal noise. Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members. Archer is an aerospace company based in San Jose, California building an all-electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all-electric aircraft that can carry four passengers while producing minimal noise. Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members. Job Overview Archer is building the future of urban air mobility. Our supply chain spans hundreds of vendors — from avionics hardware suppliers to cloud infrastructure providers — and a compromise anywhere in that ecosystem could impact aircraft certification, delay FAA approvals, or expose sensitive information. You are key to effective enforcement of our extended enterprise third-party risk posture. Archer is seeking a Senior Third Party Risk Management (TPRM) Engineer to execute our vendor cyber risk function across all tiers of our supplier ecosystem. In this high-visibility role, you will use platforms like BitSight to continuously monitor, investigate, triage, and action security risks introduced by third-party partners and their downstream (4th-party) suppliers. You will serve as the connective tissue between Security, Sourcing, Legal, and executive leadership — translating third party risk indicators into actionable threat intelligence and coordinated response actions while ensuring strict compliance with NIST SP 800-171, CMMC Level 2, and SOX ITGC requirements. This role requires both hands-on technical depth and program-building acumen. You will support and execute Archer's TPRM function from the ground up, develop risk-tiered due diligence processes, and ensure vendor security posture remains aligned with our CMMC Level 2, NIST SP 800-161, and DFARS obligations as we grow our defense programs. Key Responsibilities ● Operate BitSight and complementary EASM/continuous monitoring platforms as the primary lens into Archer's third-party attack surface. Maintain a tiered vendor inventory, configure portfolio monitoring, tune alert thresholds, and ensure new vendors are onboarded into the program at contract execution. ● Conduct deep-dive investigations into vendor risk signals — including unpatched CVEs, exposed services, credential leaks, certificate anomalies, business deterioration, and dark web indicators. Correlate external ratings data with internal telemetry to assess true business exposure and eliminate false positives before escalation. ● Extend visibility beyond direct vendors to identify and monitor critical 4th-party sub-processor dependencies. Map supply chain concentration risks, single points of failure, and foreign ownership or influence (FOCI) concerns for vendors supporting defense programs or handling CUI. ● Drive risk closure by issuing formal findings, coordinating with internal vendor relationship owners, and tracking remediation commitments through resolution. Engage procurement and legal channels when vendors are non-responsive or remediation timelines are unacceptable. ● Produce crisp, executive-quality risk briefings, board-level metrics, and ad-hoc deep-dives for the CISO, General Counsel, and program security leads. Escalate critical or rapidly-deteriorating vendor risk findings in near-real-time with clear business impact statements and recommended courses of action. ● Design and administer risk-tiered security questionnaires for new and renewing vendors. Evaluate responses, validate claims against external signals, execute integrated due diligence checkpoints in Archer's procurement workflow. ● Influence, develop and maintain TPRM policies, standards, and procedures aligned to NIST SP 800-161 (C-SCRM), CMMC Level 2 SR practices, and ISO 27036. Provide transparency to external audits and government assessments by maintaining organized evidence of vendor risk controls and remediation activity. ● Serve as the TPRM lead during vendor-related security incidents — coordinating with Archer's internal IR team, managing vendor communications under legal hold protocols, and driving root cause analysis and contractual remedies following a third-party breach. Required Qualifications ● 7+ years in cybersecurity with at least 3 years of dedicated third-party or supply chain risk management experience ● Demonstrated hands-on proficiency with BitSight or an equivalent continuous monitoring platform — including alert tuning, portfolio management, vendor engagement workflows, and peer benchmarking ● Deep working knowledge of NIST SP 800-161 (C-SCRM), NIST CSF, CMMC Level 2 SR and CA practices, and ISO 27036 as they apply to vendor security governance ● Experience conducting structured vendor security due diligence across SaaS, cloud infrastructure, hardware manufacturers, and professional services suppliers ● Proven ability to investigate and triage cyber risk findings at scale — correlating external signals with business context to produce prioritized, actionable intelligence for both technical and non-technical stakeholders ● Familiarity with 4th-party risk mapping, sub-processor disclosure reviews, and supply chain concentration risk analysis ● Excellent written and verbal communication skills — able to translate complex vendor risk findings into executive-ready briefings, board-level dashboards, and actionable ● Eligibility to obtain a DoD Secret security clearance Preferred Qualifications ● Certifications: CTPRP (Prevalent), CRISC, CISSP, CISM, or equivalent risk management credentials

  • Active DoD Secret or Top Secret/SCI clearance
  • Familiarity with ITAR/EAR data sharing constraints and their implications for
vendor contracting and CUI handling
  • Exposure to FOCI (Foreign Ownership, Control, or Influence) assessments
  • Experience integrating TPRM tooling with GRC platforms or building risk
workflow automation (e.g., auto-routing findings, SLA tracking, contract clause triggers) ● Prior startup or high-growth company experience — comfort operating with limited bureaucracy and building programs that scale with business growth Please note that this job description is intended to provide a general overview of the position and does not include an exhaustive list of responsibilities and qualifications At Archer we aim to attract, retain, and motivate talent that possess the skills and leadership necessary to grow our business. We drive a pay-for-performance culture and reward performance that supports the Company’s business strategy. For this position we are targeting a base pay between $207,400 - $259,200. Actual compensation offered will be determined by factors such as job-related knowledge, skills, and experience. ARCHER IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER COMMITTED TO DIVERSITY AND INCLUSIVITY IN THE WORKPLACE. ALL ASPECTS OF EMPLOYMENT ARE DECIDED ON THE BASIS OF MERIT, QUALIFICATIONS, AND BUSINESS NEEDS. WE DO NOT DISCRIMINATE BASED UPON RACE, COLOR, RELIGION, SEX, SEXUAL ORIENTATION, AGE, NATIONAL ORIGIN, DISABILITY STATUS, PROTECTED VETERAN STATUS, GENDER IDENTITY OR ANY OTHER CHARACTERISTIC

PROTECTED BY FEDERAL, STATE OR LOCAL LAWS.

ARCHER IS COMMITTED TO WORKING WITH AND PROVIDING REASONABLE ACCOMMODATIONS TO JOB APPLICANTS WITH PHYSICAL OR MENTAL DISABILITIES, AND THOSE WITH SINCERELY HELD RELIGIOUS BELIEFS. APPLICANTS WHO MAY REQUIRE REASONABLE ACCOMMODATION FOR ANY PART OF THE APPLICATION OR HIRING PROCESS SHOULD PROVIDE THEIR NAME AND CONTACT INFORMATION TO ARCHER’S PEOPLE TEAM AT View email address on click.appcast.io [View email address on click.appcast.io]. REASONABLE ACCOMMODATIONS WILL BE DETERMINED ON A

CASE-BY-CASE BASIS.

-------------------------------------------------------------------------------- INFORMATION COLLECTED AND PROCESSED AS PART OF ANY JOB APPLICATIONS YOU CHOOSE TO SUBMIT IS SUBJECT TO ARCHER'S CANDIDATE PRIVACY POLICY [ ARCHER IS UNABLE TO PROVIDE WORK VISA SPONSORSHIP FOR THIS POSITION AT THE

PRESENT TIME.

ARCHER IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER COMMITTED TO DIVERSITY AND INCLUSIVITY IN THE WORKPLACE. ALL ASPECTS OF EMPLOYMENT ARE DECIDED ON THE BASIS OF MERIT, QUALIFICATIONS, AND BUSINESS NEEDS. WE DO NOT DISCRIMINATE BASED UPON RACE, COLOR, RELIGION, SEX, SEXUAL ORIENTATION, AGE, NATIONAL ORIGIN, DISABILITY STATUS, PROTECTED VETERAN STATUS, GENDER IDENTITY OR ANY OTHER CHARACTERISTIC

PROTECTED BY FEDERAL, STATE OR LOCAL LAWS.

ARCHER AVIATION DOES NOT ENGAGE WITH EXTERNAL RECRUITING AGENCIES/INDIVIDUAL RECRUITERS WITH WHOM IT DOES NOT HAVE A PRIOR WRITTEN AGREEMENT. ARCHER RESERVES THE RIGHT TO MAKE USE OF ANY UNSOLICITED RESUMES THAT IT RECEIVES AND BEARS NO RESPONSIBILITY FOR PAYMENT OF ANY FEES ASSERTED FROM THE USE OF UNSOLICITED RESUMES. IF YOU ARE A RECRUITING AGENCY OR INDIVIDUAL RECRUITER WISHING TO DO BUSINESS WITH ARCHER, PLEASE REACH OUT TO View email address on click.appcast.io [View email address on click.appcast.io]. ALL EMPLOYMENT PROCESSES ARE MANAGED BY THE ARCHER PEOPLE TEAM.

Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Third Party Risk Manager in San Jose, CA vacancy
  • $110k

     ...Enterprise Risk Manager – $110K – San Jose, CA – Job # 3759 Who We Are: The Symicor Group is a boutique talent acquisition firm based...  ...with strategic goal setting and business planning. Reviewing third party independent reviews of risk, including but not limited to external... 
    Suggested

    BritePros Medical Staffing

    San Jose, CA
    13 hours ago
  • $5,098 - $5,304 per month

     .... The Conference and Coordinator also assists with S2 Access management and is part of the UHS Access Team, as well as oversees the SJSU...  ...All background checks are conducted through the university's third party vendor, Accurate Background. Some positions may also require... 
    Suggested
    Full time
    Contract work
    Summer work
    Work at office
    Immediate start
    Flexible hours
    Night shift
    Weekend work
    Weekday work

    San José State University

    San Jose, CA
    2 days ago
  • $142.6k - $261.5k

     ...organization faces today demands change. And with change comes risk. As a Risk Technology professional, you will be addressing client...  ...process controls transformation, application security, risk management technology enablement, continuous controls monitoring, and IT risk... 
    Suggested
    Work experience placement
    Summer holiday
    Flexible hours

    Ernst & Young Oman

    San Jose, CA
    2 days ago
  • $150k - $170k

     ...Job Description Job Description Risk Manager – Construction & Compliance Location: Bay Area & Northern California | Travel Required Salary Range: $150,000 – $170,000 (DOE) Employment Type: Full-Time | Hybrid Benefits: Excellent benefits package including... 
    Suggested
    Full time
    Contract work
    Temporary work
    Local area
    Relocation
    Relocation package
    Shift work

    Dynamic Office & Accounting Solutions

    Milpitas, CA
    19 days ago
  •  ...THE ROLE: Join the AMD Ventures team as a Venture Investment Manager and play a central role in advancing AMD’s growth strategy. You...  ...disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity... 
    Suggested

    Advanced Micro Devices

    Santa Clara, CA
    4 days ago
  •  ...accurate descriptions and potential allergens. Abide by all hotel policies and safety rules. Perform other duties as requested by management. Must be 21 years of age or older. Qualifications In compliance with California laws, Responsible Beverage Service and Food... 
    Local area
    Flexible hours
    Night shift

    Peregrine Corporation

    Los Gatos, CA
    3 days ago
  • Our client, a leader in the medical device industry, is seeking a dedicated and experienced Clinical Risk Project Manager to join their dynamic team. As a vital part of the Clinical Affairs department, you will support cross-functional teams to ensure the safety and regulatory... 
    Contract work
    Remote work
    Flexible hours

    ManpowerGroup Global, Inc.

    Santa Clara, CA
    3 days ago
  • $55 - $59 per hour

    Job Title: Clinical Risk Evaluation Project Manager Location: Santa Clara, CA 95054 (Multiple locations available: Santa Clara, CA; Sylmar, CA; Plano, TX; St. Paul, MN; or Remote) Duration: 8 Months (with potential extension) Work Arrangement: Preferably Onsite (Remote... 
    Hourly pay
    Remote work

    ManpowerGroup Global, Inc.

    Santa Clara, CA
    2 days ago
  •  ...contact, oversee campaign execution, project management and lead many aspects of program...  ...etc), UAC (Universal App Campaigns), 3rd Party Device Ads Act as a key day-to-day contact...  ...Understanding of the programmatic ecosystem and third-party inventory. ~ Experience with... 
    Summer holiday
    Work at office
    Work from home

    Kepler Group

    San Jose, CA
    more than 2 months ago
  • Preston Companies in Milpitas, CA, is seeking a skilled professional for a risk management role. The ideal candidate will have over 10 years of project management experience in the ACEC industry, focusing on both public and private works projects. This hybrid position involves... 
    Contract work

    Preston Companies

    Milpitas, CA
    3 days ago
  • $189k - $274k

    Supply Chain Risk Management Program Manager, Cloud corporate_fare Google place Sunnyvale, CA, USA Apply Bachelor's degree or equivalent practical experience. 8 years of experience in program or project management within supply chain management, operations, or management... 
    Full time
    Contract work

    Google Inc.

    Sunnyvale, CA
    5 days ago
  • $138k - $207k

     ...seamless organizational alignment before and during the event. Strategic Ecosystem & Vendor Management: Procure, negotiate contracts with, and orchestrate complex global third-party networks—including exhibit houses, labor unions, A/V production providers, and freight... 
    Work at office
    Worldwide
    Flexible hours

    Pure Storage

    Santa Clara, CA
    4 days ago
  • $28 - $32 per hour

     ...from you! What you’ll do: Take the lead in event execution: Oversee event setups, coordinate with vendors, direct event staff, manage timelines, and ensure seamless execution Mentor and motivate : Support and guide event staff to deliver exceptional service and... 
    Full time
    Local area
    Shift work
    Weekend work
    Afternoon shift

    WEDGEWOOD WEDDINGS

    San Jose, CA
    7 days ago
  •  ...in the Silicon Valley tech space. Your role will be to project manage event delivery from planning, to on-site, to post-event...  ...understanding the delivery timeline, tracking budget Work with client third party vendors to facilitate swag logistics, equipment deliveries and... 
    Work experience placement
    Remote work

    projectaugustus

    San Jose, CA
    3 days ago
  • $80k - $87.55k

     ...experienced hospitality leader ready to take ownership of your own venue? Wedgewood Weddings offers a structured pathway for seasoned managers to train in our proven venue management model. Our General Manager in Training (GMIT) program isn't a beginner's course-it's a... 
    Full time
    Local area
    Relocation
    Shift work
    Afternoon shift

    Wedgewood Weddings

    San Jose, CA
    1 day ago
  • $80k - $90k

     ...complexity. Demonstrates consultative approach to overall event management. Maintains and updates project timelines and event workbook....  ..., Security, Transportation and Janitorial, as well as third party suppliers, if applicable. Primary Responsibilities 80% - Serves... 
    Full time
    Part time
    Work at office

    Maritz

    Sunnyvale, CA
    1 day ago
  • $75k

     ...a CBRE Meeting & Events Planner, you will be responsible for managing employees that oversee the delivery of workplace experience services...  ...and contractual documentation. Oversee programs ran by third party vendors. This includes food delivery, organizing events,... 
    Contract work
    Work at office

    CBRE

    Milpitas, CA
    2 days ago
  •  ...related inquiries, issues, and requests for information. Supervise third party vendors that provide lease administration services to confirm...  .... Ensure all rent payments are made timely and accurately. Manage lease database, verify the accuracy and integrity of real... 
    Work experience placement
    Work at office
    Flexible hours
    Shift work

    Cosmotek College

    Santa Clara, CA
    1 day ago
  •  ...VC Stack is looking for a Director in Santa Clara to manage a $1.6 billion endowment alongside a team of investment professionals. The role requires in-depth involvement in selecting, monitoring, and evaluating investment managers across multiple asset classes. The ideal... 

    VC Stack

    Santa Clara, CA
    3 days ago
  • $9,673 - $10,000 per month

     ...Initiatives, the Director of the Event Management Office (EMO) provides strategic leadership...  ...coordination, equitable space access, risk mitigation, service alignment, and implementation...  ...are conducted through the university's third-party vendor, Accurate Background. Some... 
    Work at office
    Immediate start

    San Jose State University

    San Jose, CA
    5 days ago
  • $113.7k - $199k

     ...is seeking a dynamic, detail-oriented, and experienced Events Manager to join our team and manage events across our portfolio globally...  ...primary residence and the closest ServiceNow office using a third-party service. Equal Opportunity Employer ServiceNow is an equal... 
    Work at office
    Immediate start
    Remote work
    Flexible hours

    ServiceNow

    Santa Clara, CA
    3 days ago
  • A leading cybersecurity firm seeks a Managing Director for Cyber Risk Management in Santa Clara, CA. This role involves driving new business, managing client relationships, and leading engagement delivery. The ideal candidate will have 15+ years of experience in cybersecurity... 
    Remote job

    Palo Alto Networks

    Santa Clara, CA
    3 days ago
  •  ...Event Operations Manager Location: San Francisco, CA preferred; remote candidates may be considered with ability to travel as needed...  ...platforms such as Swoogo and Cvent for conferences, event series, and third‑party sponsorship activations. Develop and maintain registration... 
    Contract work
    Local area
    Remote work

    Russell Tobin

    Cupertino, CA
    1 day ago
  •  ...transport logistics, datacenter design and construction, equipment management, and network and facility operations. Bitdeer also offers...  ...financial resources, optimizing cash flow, and mitigating financial risks. We need someone with a strong analytical mindset, a solid... 
    Local area

    Bitdeer (NASDAQ: BTDR)

    San Jose, CA
    2 days ago
  • $150k - $245k

     ...career and become an integral part of our Global Treasury Operations team. The Treasury Analyst will report to one of our Treasury Managers. This role is ideal for someone with experience with bank accounts and portals, an interest in serving as a primary architect for... 
    Hourly pay
    Full time
    Work at office
    Immediate start
    Flexible hours
    3 days per week

    Netflix

    Los Gatos, CA
    2 days ago
  • $210k

     ...anywhere, and can change their plans at any time. Netflix's Corporate Treasury team is responsible for managing the company's capital structure, financial risk, and cash and banking activities, including our 14 billion dollar debt portfolio, a multi-billion dollar foreign... 
    Hourly pay
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Flexible hours

    Netflix

    Los Gatos, CA
    1 day ago
  • $47 - $50 per hour

     ...conferences, and special programs Support event operations by managing staffing logistics from onboarding through event execution...  ...information with unverified individuals or suspicious third parties If you are unsure whether a posting or recruiter is legitimate... 
    Contract work
    Weekend work
    Afternoon shift
    Early shift

    TCWGlobal

    Cupertino, CA
    2 days ago
  • $73.77k - $103.28k

     ...commercial real estate loans or lines of credit, most of which involve large amounts of money and important customers. The Portfolio Manager is responsible for identifying, soliciting and retaining existing commercial business relationships and/or commercial real estate... 

    Citizens Business Bank

    San Jose, CA
    5 days ago
  • $90k - $140k

     ...Redwood City and San Francisco. Title of position: Portfolio Manager Position type: Full-time Pay range: $90,000 - $140,000...  ...credits with varying complexity. In addition to managing credit risk, the AVP Portfolio Manager will focus on excellent customer service... 
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Avidbank

    San Jose, CA
    2 days ago
  •  ...company’s treasury operations, including cash positioning, liquidity management, bank relationship maintenance, and support for insurance and...  ...to support trade-related finance instruments. Insurance & Risk Management Support the company’s insurance program by coordinating... 
    Temporary work

    BayOne Solutions

    Santa Clara, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Third Party Risk Manager. Be the first to apply!