707,628open jobs
41,965companies
100,608added this week
Browse all
Salary
$122k – $236k per year (Estimated)
Location
Remote/Hybrid (Westport, United States)
Seniority
Senior · 7+ years exp
Overview
Company
Impact
Profile match

Vendor Risk Manager  

Dalio Family Office  

Dalio Family Office Overview:   

The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes OceanX, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO’s culture is built around meaningful work and meaningful relationships and the family’s commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi. 

Position Summary:   

The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across cybersecurity, AI, privacy, financial, and AML/CFT/sanctions domains into clear, actionable risk positions, performing structured threat modeling for high-exposure vendors.  

Day-to-day responsibilities would include a combination of the following:  

  • Own the VRM program end-to-end: strategy, policy, procedure, workflow, tooling, metrics, and executive reporting for CISO/CRO/board visibility.
  • Lead holistic vendor risk assessments across cybersecurity, AI risk, privacy, financial, AML/CFT/sanctions.
  • Document residual risk acceptances with named accountable executives and time-boxed review dates; coordinate with IT, Legal, Finance, and Compliance as appropriate. 
  • Evaluate and monitor vendor security controls based on data sensitivity and business criticality, leveraging industry frameworks and evidence such as SOC 2, ISO 27001, penetration testing, and security assessments. 
  • Conduct structured threat models (STRIDE, PASTA) for high risk vendors, and document findings as durable artifacts informing contracting, monitoring, and exit planning. 
  • Translate threat model outputs into concrete, testable control requirements drawing from OWASP (ASVS, API Security Top 10, LLM/Agentic Top 10), NIST (SP 800-53, SP 800-161, CSF 2.0, SP 800-207), and MITRE ATT&CK; scale requirements to vendor tier. 
  • Partner with Legal to translate identified risks into enforceable contractual requirements.
  • Apply FAIR or comparable quantitative methods for high-impact vendor decisions, expressing cyber risk in loss-exposure terms that resonate with senior leadership. 
  • Advise IT, Engineering and business teams on vendor integration architecture (SSO/SCIM, OAuth, conditional access, DLP, segmentation, BYOK, VPC peering) and maintain approved reference patterns.
  • Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth; produce program dashboards tracking throughput, cycle time, recertification compliance, and remediation aging. 

The ideal candidate will possess the following knowledge, skills, attributes, and values:  

  • Expert knowledge of third-party/vendor risk management  
  • Strong risk assessment and analytical skills  
  • Technical understanding of enterprise security architecture  
  • Excellent communication and stakeholder management skills  
  • Proven ability to lead and optimize vendor risk programs  

Illustrative Benefits:      

  • 100% company paid medical premiums  
  • 17 company paid holidays  
  • Friday summer hours  
  •  Monthly community happy hours  
  • Hybrid work environment  
  •  Free catered food services for in-office days  
  • Generous PTO offering   
  • Casual dress code  
  • 150% 401(k) match up to $7,500 and 100% match above $7,500 ($15k match limit)  
  • Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!  

Qualifications:  

  • Bachelor’s degree in Information Security, Risk Management, Computer Science, Cybersecurity, or a related discipline. 
  • At least 7 years of progressive experience across vendor risk management, cybersecurity architecture, security engineering, GRC, audit, or related fields.  
  • Experience managing the full third-party/vendor risk lifecycle, including vendor onboarding, due diligence, risk assessments, continuous monitoring, recertification, remediation tracking, and vendor exit planning, with at least 2 years owning an end-to-end TPRM program.  
  • Strong technical knowledge of cybersecurity frameworks, standards, and methodologies including NIST, ISO 27001/27002, OWASP, MITRE ATT&CK, Shared Assessments, threat modeling approaches (STRIDE/PASTA), and risk management practices.  
  • Hands-on experience evaluating enterprise security controls, cloud and integration architectures, SOC 2 Type II reports, ISO certifications, penetration testing results, data protection requirements, and third-party security risks across complex technology environments.  
  • Ability to communicate complex technical and risk concepts to executive stakeholders, collaborate effectively across business functions
  • 10% travel as required based on business needs. 

Compensation:  

Compensation for the role includes a competitive salary in the range from $175,000-$260,000 (inclusive of a merit-based bonus, dependent on years of experience, level of education obtained, as well as applicable skillset) and an excellent benefits package, including paid time off ranging from 15 to 25 daysbased on years of service, paid sick and safe leave, dental, vision, life and disability insurance, paid parental time off, birth mother recovery pay, sick family member pay, parental ramp back up program, gym reimbursement andgenerous employer match for 401k.  

Please notewe are unable to provide immigration sponsorship for this position. 

At the DFO, we believe our biggest asset is our people. We are proud to be an equal opportunity employer, hiring and developing individuals from diverse backgrounds and experiences to add to our collaborative culture. The DFO treats all candidates and employees with respect and does not discriminate in our recruiting, hiring, and promoting processes and general treatment during employment, including on the basis of actual or perceived race, creed, color, religion, sex, age, sexual orientation, gender identity and/or expression, alienage or national origin, ancestry, citizenship status, marital status, veteran status, or disability. 

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
707,628 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Westport
Engineer, LLM 8 hours ago
In office • 8+ years exp
Python
AI/ML
DeepSpeed
LoRA
vLLM
Fine-tuning
Embeddings
RLHF
Quantization
AI Agents
TensorRT
PEFT
QLoRA
TensorRT-LLM
Transformers
PyTorch
LLM
RAG
Hallucination
OpenAI
DPO
FSDP
LLM Evaluation
LLM Guardrails
KV Cache
Tool Use
RLAIF
DevOps
Azure
Kubernetes
Azure AKS
Apply
$124k per year (gross) • Remote/Hybrid • Full-Time • Vilnius
DevOps
GCP
Azure
CI/CD
GitOps
AWS
Kubernetes
Linux
Cybersecurity
ISO 27001
SOC 2
Apply
$83k – $244k per year (Estimated) • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • Belén
Python
SQL
Python
FastAPI
Databases
Redis
Databricks
AI/ML
LangGraph
AutoGen
LangChain
LlamaIndex
Reinforcement Learning
Prompt Engineering
AI Agents
CrewAI
LLM
RAG
Multi-Agent Systems
DevOps
GCP
Azure
CI/CD
AWS
Apply
$36k – $66k per year • In office • Top Secret • Internship • Bachelor's Degree • Tampa
Python
PowerShell
AI/ML
LLM
Red Teaming
Cryptography
GPG
Apply
Software Engineer 8 hours ago
In office
Python
Databases
DynamoDB
AI/ML
Copilot
Claude Code
AI Agents
AWS Bedrock AgentCore
DevOps
CI/CD
Git
AWS
AWS Lambda
GitHub
API Gateway
Apply
$116k – $225k per year (Estimated) • Remote/Hybrid • 7+ years exp • Bachelor's Degree • Westport
Apply
Executive Assistant 7 days ago
$90k – $205k per year • Remote/Hybrid • 8+ years exp • Westport
Management
Monday.com
Outlook
OneDrive
SharePoint
Apply
$400k – $475k per year • In office • 12+ years exp • Westport
Apply
$116k – $225k per year (Estimated) • Remote/Hybrid • 12+ years exp • Bachelor's Degree • Westport
Apply
$300k – $405k per year • Remote/Hybrid • 7+ years exp • Bachelor's Degree • New York
Python
AI/ML
Ray
Apply
$45k – $75k per year • In office • Full-Time • Westport
Apply
$64k – $74k per year • In office • Contractor • Westport
Apply
$84k – $94k per year • In office • Contractor • Westport
Apply
$56k – $94k per year • In office • Contractor • Westport
Apply
$225k – $375k per year • Remote/Hybrid • 5+ years exp • Bachelor's Degree • Westport
Apply
See all jobs
This is one of many
707,628 more open roles from verified company boards, updated every day.