1

Cyber Third Party Risk Analyst Jobs in Virginia (NOW HIRING)

Third-Party Risk Analyst

Mclean, VA · On-site

$45 - $47/hr

Third-Party Risk Analyst Location: McLean, VA (5 days - Onsite) Job Overview The Third-Party Risk Analyst will support Enterprise Operationally Critical Third Parties (EOCTP) and Enterprise ...

Third Party Risk Analyst Duration: Long Term Contract Hybrid in Vienna, VA Dedicated resource to support the design, testing, implementation, documentation, and continuous enhancement of Third Party ...

Champion continuous improvement and innovation by identifying opportunities to strengthen data quality, automation, analytics, and governance, advancing the maturity of the Third Party Risk ...

Champion continuous improvement and innovation by identifying opportunities to strengthen data quality, automation, analytics, and governance, advancing the maturity of the Third Party Risk ...

Third Party Risk Manager Location: Vienna, VA Type: Contract Work Model: Hybrid - onsite and remote Business unit: Procurement Main focus: support enhancements to the Third-Party Risk methodology and ...

Experience supporting Third-Party Risk Management (TPRM), vendor risk, or enterprise risk ... Strong analytical, problem-solving, and organizational skills. * Excellent communication and ...

Third Party Risk Manager Location: Merrifield, VA Type: Contract Work Model: Hybrid - onsite and remote * Support the design, testing, implementation, documentation, and continuous enhancement of ...

next page

Showing results 1-20

Cyber Third Party Risk Analyst information

What is a cyber third party risk analyst?

Cyber Third Party Risk Analysts are professionals responsible for assessing, monitoring, and managing cybersecurity risks associated with an organization's third-party vendors, suppliers, and partners. They evaluate the security practices and controls of these external parties to ensure they meet the organization's security standards and regulatory requirements. By identifying vulnerabilities and recommending mitigation strategies, these analysts help protect sensitive data and reduce the risk of cyber incidents originating from third-party relationships.

How does a cyber third party risk analyst typically collaborate with other departments to manage vendor risks?

A Cyber Third Party Risk Analyst frequently works cross-functionally with teams such as procurement, legal, IT, and compliance to assess and monitor the cybersecurity posture of vendors. This collaboration often includes coordinating risk assessments, reviewing contractual requirements related to data security, and ensuring that vendors meet the organization's cybersecurity standards. Regular communication and joint meetings help align expectations and address any identified risks promptly. By working closely with these departments, the analyst ensures a holistic approach to third-party risk management and helps protect sensitive business information.

What are the key skills and qualifications needed to thrive as a cyber third party risk analyst, and why are they important?

To thrive as a Cyber Third Party Risk Analyst, you need expertise in cybersecurity principles, risk management frameworks, and vendor risk assessment, usually supported by a degree in information security or a related field. Familiarity with tools like Archer, OneTrust, or BitSight, as well as certifications such as CISSP, CISA, or CRISC, is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for evaluating vendors and collaborating across departments. These skills help ensure an organization’s security posture by identifying and mitigating risks posed by third-party relationships.

What is the difference between Cyber Third Party Risk Analyst vs Cyber Security Analyst?

AspectCyber Third Party Risk AnalystCyber Security Analyst
Primary FocusAssessing and managing risks from third-party vendors and partnersProtecting organizational systems and data from cyber threats
CertificationsISO 27001, CISSP, CISA often preferredCISSP, CEH, Security+ common
Work EnvironmentVendor assessments, risk reports, compliance reviewsNetwork monitoring, incident response, security audits
Industry UsageFinance, healthcare, and organizations with extensive third-party relationshipsAll industries, especially IT and finance

The Cyber Third Party Risk Analyst specializes in evaluating and mitigating risks posed by third-party vendors, while the Cyber Security Analyst focuses on defending organizational systems from cyber threats. Both roles require relevant certifications and work in security-related environments, but their core responsibilities differ in scope and focus.

What cities in Virginia are hiring for Cyber Third Party Risk Analyst jobs?

Cities in Virginia with the most Cyber Third Party Risk Analyst job openings:

Infographic showing various Cyber Third Party Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Third-Party Risk Analyst

Mclean, VA • On-site

$45 - $47/hr

Contractor

Re-posted 8 days ago


Job description

Title: Third-Party Risk Analyst
Location: McLean, VA (5 days - Onsite)
 
Job Overview
The Third-Party Risk Analyst will support Enterprise Operationally Critical Third Parties (EOCTP) and Enterprise Vulnerability Incident Management (VIM) programs. This role partners closely with Governance Advisors and enterprise stakeholders to drive risk oversight, data analysis, reporting, and program execution within a financial services environment.
 
Key Responsibilities
Risk & Program Management
  • Partner with the Governance Advisor to execute EOCTP and VIM programs.
  • Ensure divisions comply with internal guidance for managing third-party risk.
  • Support crisis response activities involving third parties.
  • Project manage the data management platform supporting EOCTP and VIM.
  • Launch and review risk assessments across operational, financial, legal/compliance, reputational, and lifecycle domains.
  • Analyze program requirements and propose solutions, risks, and impact assessments.
Data Analysis & Reporting
  • Aggregate and analyze enterprise data for periodic and ad hoc reporting.
  • Independently extract and interpret KRIs and KPIs.
  • Develop monthly and quarterly third-party metrics dashboards.
  • Maintain the Vulnerability Incident Management tracker.
  • Synthesize complex data into clear, executive-ready insights.
  • Document and track vulnerability incidents and control evidence.
Stakeholder & Project Coordination
  • Establish and maintain strong relationships with enterprise stakeholders.
  • Facilitate meetings, forums, and follow-ups to drive project goals.
  • Support leadership using OneTrust workflows and processes.
  • Monitor and document third-party risk and cybersecurity trends.
Documentation & Communications
  • Create professional communications including:
    • Procedures and guidance
    • Job aids
    • PowerPoint presentations
    • Questionnaire templates
    • Dashboards and reports
  • Produce incident summaries and executive-level write-ups.
Required Qualifications
  • Bachelor’s degree in Risk Management, Business Administration, Finance, Data Analytics, Project Management, Information Security, or related field.
  • 5+ years of experience in risk management or third-party risk management (financial services preferred).
  • Strong hands-on data analysis experience.
  • Advanced proficiency in Microsoft Office Suite:
    • Excel (required)
    • Word
    • PowerPoint
    • Power BI
  • Experience aggregating and interpreting enterprise data.
  • Excellent professional writing and communication skills.
  • Strong multitasking and time-management abilities.
  • Experience in third-party risk assessment, remediation, and monitoring.
  • Knowledge of cybersecurity or information security incident management.
  • Familiarity with third-party risk frameworks and methodologies.
  • Ability to work onsite Monday–Friday in McLean, VA.
Preferred Qualifications
  • Experience with OneTrust platform.
  • Background in financial services risk environments.
  • Exposure to enterprise vulnerability management programs.
Key Skills
  • Enterprise Risk Management
  • Third-Party Risk Management (TPRM)
  • Data Analysis & Aggregation
  • KPI/KRI Development
  • Executive Reporting
  • Microsoft Excel (Advanced)
  • Power BI
  • Stakeholder Management
  • Incident Management
  • Strong Written Communication