1

Associate Vendor Risk Analyst Jobs in Virginia (NOW HIRING)

Identify, assess, and document risks across systems, applications, vendors, and cloud environments. * Conduct risk assessments and security reviews, including threat analysis, vulnerability analysis ...

Understanding of qualitative risk analysis and the ability to translate risk into clear business impact. * Awareness of AI/ML vendor risk and how AI-enabled services are assessed, monitored, and ...

Risk Manager

Mclean, VA · On-site

$55 - $60/hr

Perform risk tracking, trending, analysis, and executive reporting * Provide strategic thinking on next levels of maturity in Technology & Vendor Risk management * Act as a cross functional partner ...

Cybersecurity Risk Analyst Salary Range: $100,000 - $150,000 Clearance: TS/SCI + CI Poly Location ... Associate degree + 6 years * Bachelor's degree + 4 years * Master's degree - + 2 years * Qualifying ...

Support critical third-party vendor risk management activities * Develop, enhance, and maintain ... Support management reporting, metrics, and analysis related to model governance, AI governance, and ...

Support critical third-party vendor risk management activities * Develop, enhance, and maintain ... Support management reporting, metrics, and analysis related to model governance, AI governance, and ...

... and vendor-related tracking activities, while contributing to training, communications, and ... Work with over 170,000 diverse and talented Associates, all guided by The Five Principles. * Join a ...

... and vendor-related tracking activities, while contributing to training, communications, and ... Work with over 170,000 diverse and talented Associates, all guided by The Five Principles. * Join a ...

next page

Showing results 1-20

Associate Vendor Risk Analyst information

What is the difference between Associate Vendor Risk Analyst vs Vendor Risk Analyst?

AspectAssociate Vendor Risk AnalystVendor Risk Analyst
CertificationsCertifications like CISA, CRISC beneficialSimilar certifications often required
Work EnvironmentEntry-level, supporting risk assessmentsMore experienced, leading risk evaluations
Employer & Industry UsageCommon in financial, tech, and consulting firmsUsed across similar industries with increased responsibility

The Associate Vendor Risk Analyst typically performs supporting tasks in vendor risk management, focusing on data collection and initial assessments. The Vendor Risk Analyst has more experience, leading risk evaluations and making strategic recommendations. Both roles require similar certifications and are used in comparable industries, but the Vendor Risk Analyst holds greater responsibility and independence.

What are the most commonly searched types of Vendor Risk Analyst jobs in Virginia? The most popular types of Vendor Risk Analyst jobs in Virginia are:
What are popular job titles related to Associate Vendor Risk Analyst jobs in Virginia? For Associate Vendor Risk Analyst jobs in Virginia, the most frequently searched job titles are:
What cities in Virginia are hiring for Associate Vendor Risk Analyst jobs? Cities in Virginia with the most Associate Vendor Risk Analyst job openings:

$64.47/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 16 days ago


Job description

Position Title: Enterprise Risk Analyst The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify key cyber security risk factors in network connected medical devices and Special Purpose Systems (e.g., building automation systems, physical security systems, operational technology). These risk factors are summarized, evaluated, and reported using quantitative and qualitative scores to provide a VA authorizing official with awareness of the residual cyber risk prior to connecting these devices to the VA network. The Risk Analyst must acquire, review and leverage system documentation and data gathered through questionnaires and interviews with customers in the field and vendor/manufacturer representatives to accurately document critical security posture elements in a common reporting format. These elements include hardware/software inventory, communications profile, system interconnections, data types and stores, and the presence or lack of security controls, settings and mechanisms for a given device type. The Risk Analyst performs annual reviews to support effective continuous monitoring and to ensure documented residual risks are current, accurate, and complete. The analyst works within a Risk Management team and is expected to collaborate with Federal and contractor team mates to achieve best outcomes for the ERA process. You Have: Experience with Cybersecurity, risk management, or risk assessment for complex systems Experience with NIST SP 800-53 and NIST SP 800-30 Experience with documenting and depicting network topology and network protocols Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements Bachelor’s degree in Computer Science, Mathematics, Engineering or technical discipline and 10 years of relevant work experience or 18 years of relevant work experience in lieu of degree Nice If You Have: Experience with cybersecurity analysis of medical technology or Internet of Things (IoT) Experience with Governance, Risk, and Compliance (GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio CompTIA Security+ or Certified Risk Management Professional (CRISC) or Certified in Risk and Information Systems Control (CRISC) Public Trust clearance The hourly rate of pay for this position is $64.47/hr Benefits: PTO, Medical/Dental/Vision plan, Life and AD&D insurance, 401K Plan We are an Equal Opportunity Employer: We do not discriminate in employment opportunities or practices on the basis of race, color, religion, sex, national origin, age, disability, genetic information or any other characteristics protected by law.  This organization participates in E-Verify. #DICE