1

Associate Vendor Risk Analyst Jobs in Santa Clara, CA

Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners ... Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on ...

As a key analyst of the Fraud Risk Management team for Intuit's Business Credit Card, you will be ... Evaluate, onboard, and manage external fraud tools, vendors, and partnerships to ensure ...

As a key analyst of the Fraud Risk Management team for Intuit's Business Credit Card, you will be ... Evaluate, onboard, and manage external fraud tools, vendors, and partnerships to ensure ...

As a key analyst of the Fraud Risk Management team for Intuit's Business Credit Card, you will be ... Evaluate, onboard, and manage external fraud tools, vendors, and partnerships to ensure ...

Analyze incident, change, and problem management data toidentifytrends and improvement opportunities * Drive workflow optimization and automation within ServiceNow Vendor Risk Management * Review and ...

Experience in IT sourcing, vendor risk management, or third-party compliance audits. * Understanding of contract terms, TCO analysis, and budget planning.

next page

Showing results 1-20

Associate Vendor Risk Analyst information

See Santa Clara, CA salary details

$18

$47

$77

How much do associate vendor risk analyst jobs pay per hour?

As of Aug 31, 2026, the average hourly pay for associate vendor risk analyst in Santa Clara, CA is $47.55, according to ZipRecruiter salary data. Most workers in this role earn between $35.00 and $57.88 per hour, depending on experience, location, and employer.

What is the difference between Associate Vendor Risk Analyst vs Vendor Risk Analyst?

AspectAssociate Vendor Risk AnalystVendor Risk Analyst
CertificationsCertifications like CISA, CRISC beneficialSimilar certifications often required
Work EnvironmentEntry-level, supporting risk assessmentsMore experienced, leading risk evaluations
Employer & Industry UsageCommon in financial, tech, and consulting firmsUsed across similar industries with increased responsibility

The Associate Vendor Risk Analyst typically performs supporting tasks in vendor risk management, focusing on data collection and initial assessments. The Vendor Risk Analyst has more experience, leading risk evaluations and making strategic recommendations. Both roles require similar certifications and are used in comparable industries, but the Vendor Risk Analyst holds greater responsibility and independence.

What are the most commonly searched types of Vendor Risk Analyst jobs in Santa Clara, CA?

The most popular types of Vendor Risk Analyst jobs in Santa Clara, CA are:

What job categories do people searching Associate Vendor Risk Analyst jobs in Santa Clara, CA look for?

The top searched job categories for Associate Vendor Risk Analyst jobs in Santa Clara, CA are:

What cities near Santa Clara, CA are hiring for Associate Vendor Risk Analyst jobs?

Cities near Santa Clara, CA with the most Associate Vendor Risk Analyst job openings:

GRC Risk Management Analyst

San Jose, CA • On-site

CYNET SYSTEMS
IT Services • 501 - 1,000 employees

$68 - $72/hr

Contractor

Medical, Dental, Vision, Life, Retirement

Posted 25 days ago


Job description

Job Overview:

Pay Range: $68.97hr - $72.8hr

Requirement/Must Have:

  • Education: Bachelor’s degree in Information Security, Risk Management, Business, Computer Science, or a related field.
  • Experience: 1–4 years in enterprise risk, third-party risk, GRC, information security, or a related area.
  • Knowledge of inherent and residual risk, likelihood and impact, controls, treatment, acceptance, and monitoring.
  • Working technical knowledge of enterprise and cloud environments, including networking, operating systems, identity and access management, encryption, secure configuration, vulnerability management, logging and monitoring, application security, and incident response.
  • Ability to interpret technical evidence such as architecture and data-flow diagrams, access reviews, configuration outputs, vulnerability and penetration-test reports, security logs, and independent assurance reports, and to identify when deeper technical validation is required.
  • Ability to assess business impact, apply risk criteria, and communicate clear, defensible recommendations.
  • Strong analytical, organizational, stakeholder-management, and written and verbal communication skills.
  • Proficiency with Microsoft Office and familiarity with GRC, analytics, or automation tools.
  • Practical experience using generative AI, scripting, workflow automation, or low-code tools to improve repeatable business processes, with an understanding of prompt design, output validation, sensitive-data handling, access controls, model limitations, and responsible human oversight.
  • Must be able to commute to San Jose, CA or Austin, TX and work on-site at least 3 days per week.

Responsibilities:

  • Conduct end-to-end third-party risk assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review.
  • Administer risk-based vendor questionnaires covering security governance, data protection, access control, vulnerability management, incident response, business continuity, cloud services, and subcontractor oversight; review responses and supporting evidence, clarify gaps with vendors, and translate findings into risk ratings and remediation actions.
  • Maintain enterprise and vendor risk registers with clear risk statements, ratings, owners, treatment plans, and status.
  • Analyze security, privacy, resilience, regulatory, concentration, and fourth-party risks based on business criticality and data sensitivity.
  • Perform technical risk analysis by reviewing system architecture, data flows, cloud and network configurations, identity and access models, encryption, logging, vulnerability results, penetration-test findings, software dependencies, and incident-response capabilities; distinguish design intent from operating effectiveness and document evidence-based conclusions.
  • Apply hands-on security knowledge to validate control implementation through practical review of technical artifacts, targeted demonstrations, sample-based testing, and collaboration with engineers and system owners; translate technical weaknesses and threat scenarios into clear likelihood, impact, residual-risk, and remediation recommendations.
  • Partner with Security, IT, Legal, Privacy, Procurement, and business owners to validate findings and drive proportionate mitigation.
  • Track remediation, escalate material risks and exceptions, and prepare concise leadership reporting, including KRIs, trends, and heat maps.
  • Support policy governance, control testing, issue management, compliance monitoring, and alignment with NIST, ISO 27001, CMMC, and applicable requirements.
  • Design and use analytics, automation, and AI-assisted workflows to improve questionnaire triage, evidence extraction, control mapping, risk-statement drafting, issue classification, continuous monitoring, and reporting; measure process gains and maintain human approval, secure handling of sensitive data, output validation, auditability, and compliance with organizational AI governance requirements.

Nice to Have:

  • Relevant certification or active pursuit, such as Security+ or an AI fundamentals credential.
  • Experience with GRC platforms, vendor monitoring tools, audit support, or control evidence collection.
  • Familiarity with NIST CSF, ISO 27001, CMMC, SOC 2, GDPR, CCPA, or similar requirements.
  • Experience creating clear procedures, SOPs, or workflow documentation in a technology or regulated environment.

Benefits
 
Our Benefits Include:
  • Medical, Dental, and Vision Insurance
  • 401(k) Retirement Plan
  • Health Savings Account (HSA)
  • Disability Insurance (Short-Term and Long-Term)
  • Life and AD&D Insurance
  • Paid Sick Leave (where required by applicable state or local law)
  • Supplemental Insurance Plans
  • Identity Theft Protection
  • Pet Insurance
  • Employee Wellness Programs
  • Employee Assistance Program (EAP)
  • Career Growth and Professional Development Opportunities
Disclaimer: Benefits eligibility, accrual rates, and usage limits may vary based on employment status, length of service, and work location. Paid Sick Leave is provided in strict accordance with applicable state and municipal mandates. Cynet Systems Inc. reserves the right to modify, amend, or terminate any benefit plans at any time in accordance with applicable laws.

About Cynet Systems

Founded in 2010 and headquartered in the Washington, DC metro area, Cynet Systems Inc. is a leading technology staffing and workforce solutions company serving Fortune 500 companies, government agencies, and enterprise organizations across the United States and Canada. We deliver agile, scalable talent solutions across IT, engineering, life sciences, clinical, and professional staffing, powered by a high-performing recruitment engine operating across North America and Asia.
As a nationally and locally certified Minority Business Enterprise (MBE), Cynet Systems is committed to helping organizations build high-performing teams while empowering professionals to grow rewarding careers. Our organization is certified to ISO 9001, ISO 14001, ISO 27001, and SOC 2 Type II standards, reflecting our commitment to quality, security, operational excellence, and customer success.

Cynet Systems logo

About Cynet Systems

Sourced by ZipRecruiter

Cynet Systems Inc is a staffing and recruiting corporation nestled in Ashburn, VA, USA. Established in 2010, the company operates within the Information Technology and Services sector, specializing in providing effective workforce solutions to different business needs, including IT consulting, direct hire, and contract staffing services. Through the years, Cynet Systems has built an impressive portfolio, going beyond borders and expanding its operations internationally in Canada and India. Rooted in its core values of teamwork, leadership, and commitment, Cynet Systems helps businesses unlock their full potential by providing versatile and competent professionals that perfectly align with their needs. Fueled by their unwavering mission to deliver top-tier talent to businesses worldwide, Cynet Systems garnered various recognitions including SIA's fastest-growing staffing firms and Best Place to Work in Virginia for 2019.

Industry

It services

Company size

501 - 1,000 Employees

Headquarters location

Sterling, VA, US

Year founded

2010

Social media