1

Contract Third Party Risk Analyst Jobs in Lowell, MA

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program. You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security ...

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program. You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security ...

Fintech Risk Analyst

Boston, MA · On-site

$100 - $125/hr

Fintech Risk Analyst Department: Risk Management Employment Type: Full Time Location: Remote ... Experience in Third-Party Risk Management (TPRM) and related interagency guidance (e.g., OCC, FDIC ...

WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation ... Hands-on experience conducting third-party risk assessments for AI vendors, LLM platforms, AI APIs ...

next page

Showing results 1-20

Contract Third Party Risk Analyst information

See Lowell, MA salary details

$15

$40

$65

How much do contract third party risk analyst jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for contract third party risk analyst in Lowell, MA is $40.15, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.89 per hour, depending on experience, location, and employer.

What is a contract third party risk analyst?

A Contract Third Party Risk Analyst is a professional who evaluates and manages the risks associated with an organization's external vendors, suppliers, or partners. Their main role is to assess the security, compliance, and operational risks that third parties might pose, especially when handling sensitive data or critical business functions. They often review contracts, conduct risk assessments, and ensure that third parties comply with relevant regulations and internal policies. This helps organizations reduce potential financial, reputational, or legal impacts from working with external entities.

What are the key skills and qualifications needed to thrive as a contract third party risk analyst?

To thrive as a Contract Third Party Risk Analyst, you need a solid understanding of risk management, vendor assessment processes, and relevant regulatory frameworks, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, contract management systems, and certifications such as CTPRA (Certified Third Party Risk Assessor) is highly valuable. Strong analytical skills, attention to detail, and effective communication enable you to identify risks and work collaboratively with stakeholders. These skills ensure organizations can mitigate vendor-related risks and maintain compliance in an increasingly complex regulatory environment.

What are common challenges faced by contract third party risk analysts when evaluating new vendors?

Contract Third Party Risk Analysts often encounter challenges such as incomplete or inconsistent documentation from vendors, rapidly changing regulatory requirements, and time constraints for onboarding. They must balance thorough due diligence with business needs for efficiency, often working closely with procurement, legal, and IT security teams. Building strong communication skills and developing robust assessment templates can help analysts efficiently identify and mitigate potential risks while maintaining positive vendor relationships.

What is the difference between Contract Third Party Risk Analyst vs Vendor Risk Analyst?

AspectContract Third Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CTPRP, CRISC often preferredSimilar certifications, often including CTPRP or CRISC
Work EnvironmentTypically in finance, healthcare, or corporate sectors managing third-party risksSimilar industries, focusing on vendor assessments and risk mitigation
Employer UsageUsed by organizations managing contractual third-party relationshipsCommonly employed by companies evaluating vendor and supplier risks

The Contract Third Party Risk Analyst and Vendor Risk Analyst roles share many similarities, including required certifications and work environments. Both focus on assessing and mitigating risks associated with external entities, but the Contract Third Party Risk Analyst often emphasizes contractual obligations, while the Vendor Risk Analyst concentrates on evaluating vendor performance and compliance.

What are the most commonly searched types of Third Party Risk Analyst jobs in Lowell, MA?

The most popular types of Third Party Risk Analyst jobs in Lowell, MA are:

What are popular job titles related to Contract Third Party Risk Analyst jobs in Lowell, MA?

For Contract Third Party Risk Analyst jobs in Lowell, MA, the most frequently searched job titles are:

What job categories do people searching Contract Third Party Risk Analyst jobs in Lowell, MA look for?

The top searched job categories for Contract Third Party Risk Analyst jobs in Lowell, MA are:

Infographic showing various Contract Third Party Risk Analyst job openings in Lowell, MA as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 15% Part Time, and 4% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $83,516 per year, or $40.2 per hour.

GRC Analyst - Third Party Risk

Whoop

Boston, MA • On-site

$70K - $110K/yr

Full-time

Re-posted yesterday


Job description

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program. You will help manage third-party vendor risk reviews, and operational requests, in cross-functional security compliance workflows. Success in this role requires strong attention to detail, responsiveness and accountability through completion in a fast-paced environment.
The key focus of this role will be helping ensure third-party vendor assessment requests are reviewed, prioritized, routed, tracked, and completed effectively. You will use intake and ticketing data to identify workflow trends, recurring questions, handoff gaps, and opportunities to improve guidance, templates, reporting, automation, and stakeholder experience.
RESPONSIBILITIES:
  • Support day-to-day third-party vendor risk assessments - manage and triage GRC third-party vendor assessment intakes and accurate tracking through resolution
  • Perform vendor risk reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
  • Assist with third-party risk program management activities

QUALIFICATIONS:
  • 2+ years of experience in GRC - third-party risk management experience preferred
  • Understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls - ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS
  • Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management
  • Being a team player and working to achieve common goal in a dynamic setting
  • A minimum bachelor's degree in any discipline. Computer science, cyber security and risk or technology degrees preferred.

This role is based in the WHOOP office located in Boston, MA. The successful candidate must be prepared to relocate if necessary to work out of the Boston, MA office.
Interested in the role, but don't meet every qualification? We encourage you to still apply! At WHOOP, we believe there is much more to a candidate than what is written on paper, and we value character as much as experience. As we continue to build a diverse and inclusive environment, we encourage anyone who is interested in this role to apply.
WHOOP is an Equal Opportunity Employer and participates in E-verify to determine employment eligibility
The WHOOP compensation philosophy is designed to attract, motivate, and retain exceptional talent by offering competitive base salaries, meaningful equity, and consistent pay practices that reflect our mission and core values.
At WHOOP, we view total compensation as the combination of base salary, equity, and benefits, with equity serving as a key differentiator that aligns our employees with the long-term success of the company and allows every member of our corporate team to own part of WHOOP and share in the company's long-term growth and success.
The U.S. base salary range for this full-time position is $70,000 - $110,000. Salary ranges are determined by role, level, and location. Within each range, individual pay is based on factors such as job-related skills, experience, performance, and relevant education or training.
In addition to the base salary, the successful candidate will also receive benefits and a generous equity package.
These ranges may be modified in the future to reflect evolving market conditions and organizational needs. While most offers will typically fall toward the starting point of the range, total compensation will depend on the candidate's specific qualifications, expertise, and alignment with the role's requirements.

Whoop logo

About Whoop

Sourced by ZipRecruiter

At WHOOP, we're on a mission to unlock human performance. WHOOP empowers users (Olympians, Professional Athletes, Fitness Enthusiasts, etc) to perform at a higher level through a deeper understanding of their bodies and daily lives.

Industry

Fitness and sports centers

Company size

501 - 1,000 Employees

Headquarters location

Boston, MA, US

Year founded

2012