1

Grc Third Party Risk Analyst Jobs in Virginia (NOW HIRING)

Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...

Showing results 21-40

Grc Third Party Risk Analyst information

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in Virginia?

For Grc Third Party Risk Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Grc Third Party Risk Analyst jobs in Virginia look for?

The top searched job categories for Grc Third Party Risk Analyst jobs in Virginia are:

What cities in Virginia are hiring for Grc Third Party Risk Analyst jobs?

Cities in Virginia with the most Grc Third Party Risk Analyst job openings:

Infographic showing various Grc Third Party Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 79% Full Time, and 21% Contract. Highlights an 100% In-person job distribution.

Principal, Technology, Cyber & AI Risk

Reston, VA • On-site


Fannie Mae
Finance and Insurance • 5 - 10K employees

9.2

Company rating: 9.2 out of 10

Based on 9 frontline employees who took The Breakroom Quiz

Great coworkers

People enjoy working here

Good employer


Full-time

Medical, Life

Posted 20 days ago


Job description

Playing an essential role in the U.S. economy, Fannie Mae is foundational to housing finance. Here, your expertise can help fuel purpose-driven innovation that expands access to homeownership and affordable rental housing across the country. Join Fannie Mae to grow your career and help people find a place to call home.

Job Description

In this highly influential role, you will help shape the strategic direction of Third Party Risk Management (TPRM) capabilities, policies, governance, and operating practices. You will work across business, technology, cybersecurity, operational resilience, legal, procurement, and risk functions to address complex third-party and fourth-party risk matters and strengthen enterprise resilience.

This role requires more than deep risk expertise. You will anticipate emerging risks and stakeholder needs, advise senior leaders on complex risk decisions, influence enterprise-wide approaches, and lead high-impact initiatives without relying on direct authority. Your ability to connect business objectives, regulatory expectations, and enterprise risk considerations will help Fannie Mae make informed decisions and continue advancing the maturity and effectiveness of its Third Party Risk Management program.

The Way You Will Make a Difference
  • Shape the strategic direction of Third Party Risk Management capabilities, policies, governance, and operating models by anticipating emerging risks, industry trends, and evolving stakeholder needs.
  • Influence enterprise third-party risk strategy by evaluating business objectives, regulatory expectations, and risk considerations and recommending strategic tradeoffs, governance enhancements, and sustainable solutions.
  • Lead highly complex, cross-functional risk initiatives involving stakeholders across business, technology, cybersecurity, operational resilience, legal, procurement, and risk functions.
  • Serve as a strategic advisor to senior leadership by providing forward-looking perspectives and recommendations on complex third-party and fourth-party risk matters.
  • Exercise independent judgment to identify, assess, escalate, and support mitigation of material third-party risks that could affect business operations, regulatory compliance, security, reputation, financial success, or enterprise resilience.
  • Build alignment across organizations by navigating competing priorities, influencing stakeholders, and helping establish consistent approaches to Third Party Risk Management across the enterprise.
  • Drive continuous improvement in Third Party Risk Management governance, data, automation, analytics, processes, and risk management practices to strengthen program effectiveness and maturity.
  • Strengthen organizational risk capability by sharing expertise, mentoring peers, influencing best practices, and helping teams apply effective approaches to complex risk decisions.
Minimum Required Qualifications
  • Bachelor's Degree or Equivalent
  • 8 years of relevant professional experience.
  • Demonstrated experience assessing and managing complex technology, third-party, or enterprise risk matters.
  • Experience providing strategic risk advice and recommendations that support significant business or enterprise decisions.
  • Demonstrated ability to lead complex, cross-functional initiatives and influence outcomes across multiple stakeholder groups without direct authority.
  • Experience evaluating risk and control considerations and developing well-supported recommendations for management.
  • Ability to exercise independent judgment when evaluating complex or potentially material risk matters.
  • Strong communication and stakeholder-management capabilities, including the ability to translate complex risk considerations into clear, actionable recommendations.
  • Shows curiosity and adaptability in learning and responsibly applying new technologies, including artificial intelligence, to reimagine how we work.
Desired Experience
  • Significant experience in Third Party Risk Management, third-party technology risk; or a closely related risk discipline
  • Experience operating within a highly regulated or similarly complex business environment.
  • Experience advising senior leaders on complex risk matters and influencing decisions across organizational boundaries.
  • Experience leading enterprise-level risk initiatives involving multiple business, technology, cybersecurity, procurement, legal, operational resilience, or risk stakeholders.
  • Experience improving risk management governance, processes, data, analytics, automation, or operating practices.
  • Experience mentoring colleagues, sharing subject-matter expertise, and influencing risk management best practices.

#LI - TW1 - Hybrid

Qualifications

Active Directory (AD), Active Directory (AD), Amazon Web Services (AWS), Artificial Intelligence (AI), Atlassian JIRA, Authentication Management, Backup and Recovery (Software), Business Insight Skills, Business Process Management Skills, Calendar and Scheduling Tools, Cleaning and Transforming Data, Cloud Technology, Collaborating Cross-Functionally, Communicating in Technical Writing, Communicating Technical Information, Communication, Configuration Management (CM), Conflict Resolution, Coordination, Customer and Market Insights, Customer Relationship Management (CRM), CyberArk, Cybersecurity Analysis, Data Analysis, Data Analysis Interpretation {+ 60 more}

Education:

Bachelor's Level Degree (Required)

The future is what you make it to be. Discover compelling opportunities at Fanniemae.com/careers.

For most roles, employees are expected to work onsite on a regular basis at their designated office location. In-office work cadence is determined by your manager. Proximity within a reasonable commute to your designated office location is preferred unless the job is noted as open to remote.


Fannie Mae is an equal opportunity employer and considers qualified applicants for employment without regard to race, color, religion, sex, national origin, disability, age, sexual orientation, gender identity/gender expression, marital or parental status, or any other protected factor. Fannie Mae is committed to providing reasonable accommodations to qualified individuals with disabilities who are employees or applicants for employment, unless to do so would cause undue hardship to the company. If you need assistance using our online system and/or you need a reasonable accommodation related to the hiring/application process, please complete this form.

The hiring range for this role is set forth below. Final salaries will generally vary within that range based on factors that include but are not limited to, skill set, depth of experience, certifications, and other relevant qualifications. This position is eligible to participate in a Fannie Mae incentive program (subject to the terms of the program). As part of our comprehensive benefits package, Fannie Mae offers a broad range of Health, Life, Voluntary Lifestyle, and other benefits and perks that enhance an employee's physical, mental, emotional, and financial well-being. See more here.

Requisition compensation:

175000

to

239000


What Fannie Mae employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom