1

Freelance Third Party Risk Analyst Jobs in Alabama

Risk Analyst

Montgomery, AL · On-site +1

$87K - $110K/yr

Perform third-party security and compliance risk assessments for new and existing vendors ... Strong analytical, critical thinking, and communication skills with the ability to evaluate complex ...

Familiarity with supplier risk, third-party risk, or vendor assessment processes Why Exiger: Exiger ... risk analytics, and deliver insights that directly impact national security decision-making. Why ...

Familiarity with supplier risk, third-party risk, or vendor assessment processes Why Exiger: Exiger ... risk analytics, and deliver insights that directly impact national security decision-making. Why ...

... Third-party technology dependencies AI and emerging technology risks Oversees development of risk scenarios, loss-event libraries, threat intelligence inputs, and control effectiveness analyses to ...

Data Privacy & 3rd Risk Analyst FTC | Hybrid | Birmingham - 45k - 55k We're recruiting a Data Privacy analyst who has experience mapping out data sharing, usage and processing, PII usage across a ...

... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

Logan, Everest's growing proprietary 3rd party capital platform, covering the respective risk oversight responsibilities such as RCSAs, Operational Risk Heatmap and risk assessments of strategic ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

Working knowledge of secure systems engineering and software assurance, including static analysis, secure configuration, FOSS/third-party risk, SBOM concepts, and OWASP/DISA application-security ...

next page

Showing results 1-20

Freelance Third Party Risk Analyst information

What does a freelance third party risk analyst do?

A Freelance Third Party Risk Analyst assesses and monitors the risks that external vendors, contractors, and partners may pose to an organization. Their responsibilities include evaluating vendor security practices, ensuring compliance with regulations, and recommending risk mitigation strategies. As freelancers, they typically work with multiple clients or on specific projects, providing independent risk assessments and helping organizations minimize vulnerabilities linked to third parties.

What are the key skills and qualifications needed to thrive as a freelance third party risk analyst?

To thrive as a Freelance Third Party Risk Analyst, you need a strong background in risk assessment, compliance, and vendor management, often supported by a degree in business, information security, or a related field. Familiarity with risk management frameworks (such as ISO 27001 or NIST), third-party risk assessment tools, and certifications like Certified Third Party Risk Professional (CTPRP) are commonly required. Excellent analytical thinking, communication, and stakeholder management skills help build trust and ensure clear reporting. These competencies are crucial for effectively identifying, mitigating, and communicating third-party risks to protect organizational interests.

What are the most common challenges a freelance third party risk analyst faces when working with multiple clients?

As a Freelance Third Party Risk Analyst, a common challenge is adapting to different clients' risk frameworks, documentation standards, and compliance requirements. Each organization may use unique tools and expect varying levels of detail in risk assessments, requiring flexibility and strong communication skills. Additionally, freelancers often need to efficiently manage their time across projects, prioritize tasks, and ensure confidentiality when handling sensitive vendor information. Building trust quickly with new stakeholders and staying current with evolving regulations are also key aspects of success in this role.

What is the difference between Freelance Third Party Risk Analyst vs Freelance Compliance Analyst?

AspectFreelance Third Party Risk AnalystFreelance Compliance Analyst
CertificationsRisk management, vendor risk, or related certificationsCompliance, audit, or regulatory certifications
Work EnvironmentAssessing third-party vendors, remote or client sitesEnsuring adherence to laws/regulations, often remote
Industry UsageFinancial, healthcare, tech sectorsFinancial, healthcare, corporate sectors

Both roles involve regulatory knowledge and risk assessment, but the Freelance Third Party Risk Analyst focuses on evaluating third-party vendors' risks, while the Freelance Compliance Analyst concentrates on ensuring organizational adherence to laws and regulations. They share similar certifications and work environments, often overlapping in industries like finance and healthcare.

Can a freelance third party risk analyst work from home?

Yes, freelance third party risk analysts often work from home, as the role primarily involves analyzing data, reviewing reports, and communicating with clients remotely. Strong skills in cybersecurity tools, risk assessment frameworks, and virtual collaboration platforms facilitate remote work in this field.

What are the most commonly searched types of Third Party Risk Analyst jobs in Alabama?

The most popular types of Third Party Risk Analyst jobs in Alabama are:

What are popular job titles related to Freelance Third Party Risk Analyst jobs in Alabama?

For Freelance Third Party Risk Analyst jobs in Alabama, the most frequently searched job titles are:

What job categories do people searching Freelance Third Party Risk Analyst jobs in Alabama look for?

The top searched job categories for Freelance Third Party Risk Analyst jobs in Alabama are:

Infographic showing various Freelance Third Party Risk Analyst job openings in Alabama as of August 2026, with employment types broken down into 100% Full Time. Highlights an 83% In-person, and 17% Remote job distribution.

Risk Analyst

Alera Group

Montgomery, AL • On-site, Remote

$87K - $110K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 5 days ago


Alera Group rating

7.5

Company rating: 7.5 out of 10

Based on 31 frontline employees who took The Breakroom Quiz

225th of 312 rated insurance


Job description

OVERVIEW
Risk Analyst

Location: Deerfield, IL | Remote
Department: Corporate Services

Overview

At Alera Group, our corporate teams play a critical role in supporting the success of colleagues and clients across the country. From Human Resources and Finance to Technology, Legal, Marketing, and Operations, these professionals ensure our organization runs efficiently while enabling our teams to deliver exceptional service.

About Alera Group

Founded in 2017, Alera Group has grown to become the 14th largest broker of U.S. business. We are passionate about our clients’ success in Employee Benefits, Property & Casualty Insurance, and Financial Services. With offices nationwide, our collaborative approach allows us to deliver national strength with local service.

We are always looking to connect with talented professionals who want to contribute to a collaborative, high-growth environment and help drive strategic initiatives across a national organization.

Why Join Alera Group?
  • Collaborate with purpose – Work alongside colleagues who believe the best results come from strong partnerships, shared expertise, and supporting one another.
  • Build your career – Expand your expertise through meaningful work, continuous learning, and opportunities to grow across a national organization.
  • Make an impact – Help clients navigate complex challenges while contributing to solutions that make a difference for their businesses, employees, and communities.

RESPONSIBILITIES
  • Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements
  • Review SOC reports, security questionnaires, audit documentation, certifications, and other evidence to identify control gaps and potential business impacts
  • Coordinate and execute user access reviews, validating access appropriateness and ensuring identified issues are remediated promptly
  • Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms
  • Serve as a trusted advisor to stakeholders by asking thoughtful questions, identifying underlying business needs, assessing potential risks, and translating ambiguous requests into clear risk assessment, governance, and compliance activities
  • Partner with Information Security, Technology, Legal, Procurement, and business stakeholders to identify requirements, resolve risk and compliance issues, and drive effective risk-based decision-making
  • Support internal and external audits, regulatory examinations, and compliance activities through evidence collection and documentation management
  • Develop risk metrics, reporting, and dashboards that drive visibility, support decision-making, and measure the effectiveness of third-party risk and governance programs
  • Identify opportunities to improve risk management processes, controls, reporting, governance practices, and automation capabilities

QUALIFICATIONS

Required Qualifications

  • 5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field
  • Hands-on experience performing third-party or vendor security risk assessments
  • Experience coordinating or performing user access reviews, access certifications, or identity governance activities
  • Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards
  • Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences
  • Experience working with GRC, ticketing, identity governance, or third-party risk management platforms
  • Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities
Certifications
  • CISA, CGRC or equivalent preferred
Preferred Qualifications
  • Experience within a regulated industry such as insurance, financial services, or healthcare
  • Experience supporting SOC 2, HIPAA, NYDFS, or similar regulatory and compliance programs
  • Experience with automated identity governance, access certification, or third-party risk management solutions
  • Experience supporting internal or external security and compliance audits
  • Ability to independently research requirements, develop risk-based recommendations, and communicate findings to stakeholders
  • Demonstrated ability to gather and clarify ambiguous requirements, ask effective probing questions, and develop practical risk-based solutions in collaboration with business stakeholders
Compensation
  • Salary Range: $87,000 - $110,000 annually
  • Bonus Eligible: Yes
Benefits

Eligible colleagues enjoy a comprehensive benefits package including:

  • Medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k)
  • Generous paid time off
  • Professional development and career growth opportunities

ADDITIONAL INFORMATION

Work Model:
This role is Remote
Preference for Central or Eastern Time Zone

Professional Development – Alera Group Academy

At Alera Group, growth isn’t left to chance. Through Alera Group Academy, we provide structured development opportunities designed to help you expand your expertise and build a meaningful career.

You’ll have access to:

  • Role-specific learning paths

  • Leadership development programs

  • Technical and compliance training

  • Industry certifications and continuing education support

  • Peer learning and knowledge-sharing communities

Whether you’re deepening technical expertise or preparing for leadership, we’re invested in helping you grow.

We're an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status, or any other protected class.

Alera Group is committed to protecting your privacy. Please review our Privacy Policy to understand what personal information we may collect and use as part of your application process.

#LI-NO1

#LI-Remote 


Location Type
Hybrid - 2 or less days in officeQualifications:

Required Qualifications

  • 5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field
  • Hands-on experience performing third-party or vendor security risk assessments
  • Experience coordinating or performing user access reviews, access certifications, or identity governance activities
  • Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards
  • Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences
  • Experience working with GRC, ticketing, identity governance, or third-party risk management platforms
  • Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities
Certifications
  • CISA, CGRC or equivalent preferred
Preferred Qualifications
  • Experience within a regulated industry such as insurance, financial services, or healthcare
  • Experience supporting SOC 2, HIPAA, NYDFS, or similar regulatory and compliance programs
  • Experience with automated identity governance, access certification, or third-party risk management solutions
  • Experience supporting internal or external security and compliance audits
  • Ability to independently research requirements, develop risk-based recommendations, and communicate findings to stakeholders
  • Demonstrated ability to gather and clarify ambiguous requirements, ask effective probing questions, and develop practical risk-based solutions in collaboration with business stakeholders
Compensation
  • Salary Range: $87,000 - $110,000 annually
  • Bonus Eligible: Yes
Benefits

Eligible colleagues enjoy a comprehensive benefits package including:

  • Medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k)
  • Generous paid time off
  • Professional development and career growth opportunities
Education:UNAVAILABLEEmployment Type: FULL_TIME

What Alera Group employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom