1

Grc Third Party Risk Analyst Jobs in Colorado (NOW HIRING)

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... Qualifications * 5+ years of experience in enterprise risk management, GRC, cybersecurity risk ...

Oversee vendor/third-party risk within the cyber risk portfolio to ensure supply-chain risk is ... Build, lead, and develop a team of senior managers and analysts; set objectives, manage performance ...

next page

Showing results 1-20

Grc Third Party Risk Analyst information

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in Colorado? For Grc Third Party Risk Analyst jobs in Colorado, the most frequently searched job titles are:
What job categories do people searching Grc Third Party Risk Analyst jobs in Colorado look for? The top searched job categories for Grc Third Party Risk Analyst jobs in Colorado are:
What cities in Colorado are hiring for Grc Third Party Risk Analyst jobs? Cities in Colorado with the most Grc Third Party Risk Analyst job openings:

Third-Party Risk Analyst

NELNET BUSINESS SOLUTIONS

Centennial, CO • Hybrid

$60K - $70K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 11 days ago


Job description

Nelnet is a diversified and innovative company committed to enriching lives through the power of service as a student loan servicer, professional services company, consumer loan originator and servicer, payments processor, renewable energy solutions, and K-12 and higher education expert. For over 40 years, Nelnet has been serving its customers, associates, and communities.

The perks of working at Nelnet go beyond our benefits package. When you join the Nelnet team, you're part of a community invested in the success of each individual. That support comes through in our work, as we are united by our mission of creating opportunities for people where they live, learn, and work.

The Third-Party Risk Analyst is a contributor within Nelnet's Risk Management team. This role supports risk assessments and ongoing oversight of third-party relationships across the organization. This role helps safeguard Nelnet against key risks by evaluating third-party controls, identifying risk gaps, and recommending remediation aligned with regulatory requirements and internal standards. The Analyst partners closely with senior team members and internal stakeholders to support the third-party risk management lifecycle and contributes to process improvements that support the continued maturity of the Third-Party Risk Management Program.JOB RESPONSIBILITIES:
  • Facilitate third-party risk assessments for new and existing third-party relationships, with guidance from senior team members as needed.

  • Assist in assessing fourth-party and subcontractor risk exposure for third-party relationships.

  • Review and analyze documentation provided by the third-party, document assessment results, identity risk gaps, and recommend remediation actions aligned with Regulatory Requirements and Nelnet standards.

  • Deliver reporting, dashboards, and analytics for ongoing oversight, trends, and escalation.

  • Support the ongoing maintenance and administration of third-party policies, procedures, and guidelines.

  • Partner with internal stakeholders and subject matter experts to support the third-party risk management lifecycle.

  • Build and maintain strong cross-functional relationships across business segments to support collaboration throughout the third-party risk management lifecycle.

  • Utilize existing tools and technology, including AI, to support process efficiency, and identify opportunities for improvement.

  • Maintain awareness of emerging risks and industry trends through continued education and research, sharing relevant insights with the team.

  • Participate in and support the delivery of third-party risk management training for Nelnet Associates.

Annual compensation range for this role is $60,000-$70,000 depending on experience.

This position offers a hybrid work option. Nelnet values flexibility and understands the importance of work-life integration. Our hybrid work environment allows associates living within 30 miles of an office location to work remotely for part of the week, while also fostering collaboration and team connection through in-office presence three days per week.

Please note that we are unable to provide visa sponsorship for this position. To be considered, candidates must already be authorized to work in the United States without the need for current or future sponsorship.

EDUCATION:

Bachelor's in technology, risk, business, or related field (equivalent experience may substitute).

EXPERIENCE:

1-3 years in risk management, third-party risk management, audit, cybersecurity, or compliance.

Education or certifications in risk, audit, cyber, or project management preferred.

Familiarity with regulatory requirements and frameworks such as SOC 1/SOC 2, ISO, NIST, and others.

COMPETENCIES/SKILLS:
  • Ability to review and interpret vendor documentation to support risk assessments and identify control gaps.

  • Sound judgment to identify risk gaps and escalate issues appropriately based on risk severity.

  • Self-starter with the ability to work independently, communicate clearly, and escalate issues effectively to stakeholders.

  • Strong organizational skills to manage concurrent assessments and maintain audit-ready documentation.

  • Ability to collaborate effectively with internal stakeholders and subject matter experts across the third-party risk management lifecycle.

Our benefits package includes medical, dental, vision, HSA and FSA, generous earned time off, 401K/student loan repayment, life insurance & AD&D insurance, employee assistance program, employee stock purchase program, tuition reimbursement, performance-based incentive pay, short- and long-term disability, and a robust wellness program. Click here to learn more about our benefits: Benefits & Perks - Nelnet Inc.


Nelnet is committed to providing a welcoming and respectful workplace where all associates have the opportunity to succeed. As an Equal Opportunity Employer, we ensure that all qualified applicants are considered for employment. Employment decisions are made without regard to race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. We value the unique contributions of every team member and believe that a positive work environment benefits everyone.


Qualified individuals with disabilities who require reasonable accommodations in order to apply or compete for positions at Nelnet may request such accommodations by contacting Corporate Recruiting at 402-486-5725 orcorporaterecruiting@nelnet.net.


Nelnet is a Drug Free and Tobacco Free Workplace.


Use of Artificial Intelligence in Hiring


We may use automated or artificial intelligence enabled tools to assist with the initial review of applications, such as identifying relevant skills or experience. These tools are used to support human review and do not make hiring decisions. A recruiter reviews applications and determines which candidates move forward in the hiring process. For more information, see our Privacy Policy and Pre-Use Notice: Automated Tools in Hiring