1

Associate Vendor Risk Analyst Jobs (NOW HIRING)

Vendor Risk Associate ABOUT THE POSITION: This position will support the identification, vetting ... Excellent analytical skills and problem-solving capabilities * Team player who can collaborate ...

About the Role The Vendor Risk Management Analyst is an integral part of Latham's Global Finance team. This role will be responsible for assessing, monitoring, and mitigating risks associated with ...

Analyzing vendor risk profiles through various due diligence activities * Developing and implementing risk mitigation strategies * Analyzing vendor performance metrics and reports * Coordinating and ...

Risk Analyst LOCATION: South Jordan or Spanish Fork, Utah GRADE: 11 (salary range 57,283-85,681 ... Vendor Risk Management program, including vendor due diligence, risk assessments, ongoing ...

Risk Analyst

South Jordan, UT · On-site

$57K - $85K/yr

Risk Analyst LOCATION: South Jordan or Spanish Fork, Utah GRADE: 11 (salary range 57,283-85,681 ... Vendor Risk Management program, including vendor due diligence, risk assessments, ongoing ...

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... prioritization analyses for leadership. * Maintain and update the enterprise risk register ...

Support administration and adherence of enterprise risk management programs, including vendor risk ... Analyze and report Key Risk Indicators (KRIs) and Risk Appetite Statement (RAS) metrics. * Prepare ...

Support administration and adherence of enterprise risk management programs, including vendor risk ... Analyze and report Key Risk Indicators (KRIs) and Risk Appetite Statement (RAS) metrics. * Prepare ...

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Risk Analyst

South Jordan, UT · On-site

$57K - $85K/yr

The Risk Analyst reports to the VP-Risk Manager and is primarily responsible for supporting risk ... Assist with implementing, administering, and maintaining a robust Vendor Risk Management program ...

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

next page

Showing results 1-20

Associate Vendor Risk Analyst information

See salary details

$15

$40

$65

How much do associate vendor risk analyst jobs pay per hour?

As of Aug 24, 2026, the average hourly pay for associate vendor risk analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What is the difference between Associate Vendor Risk Analyst vs Vendor Risk Analyst?

AspectAssociate Vendor Risk AnalystVendor Risk Analyst
CertificationsCertifications like CISA, CRISC beneficialSimilar certifications often required
Work EnvironmentEntry-level, supporting risk assessmentsMore experienced, leading risk evaluations
Employer & Industry UsageCommon in financial, tech, and consulting firmsUsed across similar industries with increased responsibility

The Associate Vendor Risk Analyst typically performs supporting tasks in vendor risk management, focusing on data collection and initial assessments. The Vendor Risk Analyst has more experience, leading risk evaluations and making strategic recommendations. Both roles require similar certifications and are used in comparable industries, but the Vendor Risk Analyst holds greater responsibility and independence.

More about Associate Vendor Risk Analyst jobs

What cities are hiring for Associate Vendor Risk Analyst jobs?

Cities with the most Associate Vendor Risk Analyst job openings:

What are the most commonly searched types of Vendor Risk Analyst jobs?

The most popular types of Vendor Risk Analyst jobs are:

What states have the most Associate Vendor Risk Analyst jobs?

States with the most job openings for Associate Vendor Risk Analyst jobs include:

Infographic showing various Associate Vendor Risk Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 68% Full Time, 29% Part Time, 1% Temporary, and 1% Contract. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $84,210 per year, or $40.5 per hour.

GRC Vendor Risk Analyst

Community Financial System, Inc.

Syracuse, NY

Full-time

Posted 23 days ago


Job description

Overview

At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration.

Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.

To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.


Responsibilities

Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.

Essential Duties:

  • Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
  • Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
  • Partner with stakeholders across various business lines to gather responses and supporting evidence.
  • Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
  • Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
  • Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
  • Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
  • Support identity and access management governance, review, and related coordination activities as assigned.
  • Track remediation items, follow-up actions, and review outcomes to support timely resolution.
  • Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
  • Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
  • Perform other Information Security, third-party risk, and related governance duties as assigned by management.

Ancillary Duties:

As an integral member of CFSI, this position is responsible to provide assistance wherever necessary to help the Branches and the Bank in achieving their annual goals. This may include traveling to other branches in the area to provide support as needed and to ensure proper staffing and service levels.


Qualifications

Education, Training & Requirements:

  • Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered

Skills:

  • Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.

Experience:

  • 4+ years of experience in Information Security; OR
  • 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
  • 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
  • Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
  • Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
  • All applicants must be 18 years of age or older.