1

Grc Third Party Risk Analyst Jobs in Virginia (NOW HIRING)

Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...

Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...

Enterprise Risk Analyst

VA · On-site

$56.52/hr

Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis ... Experience with Governance, Risk, and Compliance (GRC) * Experience with Assessment and ...

Showing results 21-40

Grc Third Party Risk Analyst information

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in Virginia? For Grc Third Party Risk Analyst jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Grc Third Party Risk Analyst jobs in Virginia look for? The top searched job categories for Grc Third Party Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Grc Third Party Risk Analyst jobs? Cities in Virginia with the most Grc Third Party Risk Analyst job openings:
Infographic showing various Grc Third Party Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 13% Part Time, and 4% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Senior, Technology 3rd Party Risk - Tax Transformation

Deloitte

Rosslyn, VA • On-site

Full-time

Re-posted 20 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 92 frontline employees who took The Breakroom Quiz

45th of 150 rated financial services


Job description

The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.

At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.

Recruiting for this role ends on May 31, 2027

Work you'll do 

The Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.

Responsibilities include:

  • Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
  • Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
  • Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
  • Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
  • Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
  • Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.

A successful candidate would possess these skills:

  • Strong communicator with the ability to tailor messages for technical and non-technical audiences. 
  • Collaborative relationship builder who works effectively across functions and levels to drive alignment. 
  • Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams. 
  • Confident facilitator who influences without authority and helps move issues to resolution.

The Team 

Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients. 

Qualifications 

Required:

  • Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
  • Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
  • 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
  • Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
  • Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
  • Limited immigration sponsorship may be available.
  • Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
  • One of the following active accreditations obtained:
    • Licensed CPA in state of practice/primary office if eligible to sit for the CPA
    • If not CPA eligible:
      • Licensed Attorney
      • Enrolled Agent
      • CBAP - Certified Business Analysis Professional
      • Certified in Risk and Information System Controls (CRISC)
      • Microsoft Azure
      • Project Management Professional (PMP)

Preferred:

  • Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes. 
  • Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences. 
  • Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels. 
  • Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs. 
  • Experience supporting business process improvement, transformation, or technology-enabled change initiatives. 
  • Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Qualifications:

The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.

At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.

Recruiting for this role ends on May 31, 2027

Work you'll do 

The Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.

Responsibilities include:

  • Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
  • Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
  • Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
  • Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
  • Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
  • Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.

A successful candidate would possess these skills:

  • Strong communicator with the ability to tailor messages for technical and non-technical audiences. 
  • Collaborative relationship builder who works effectively across functions and levels to drive alignment. 
  • Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams. 
  • Confident facilitator who influences without authority and helps move issues to resolution.

The Team 

Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients. 

Qualifications 

Required:

  • Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
  • Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
  • 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
  • Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
  • Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
  • Limited immigration sponsorship may be available.
  • Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
  • One of the following active accreditations obtained:
    • Licensed CPA in state of practice/primary office if eligible to sit for the CPA
    • If not CPA eligible:
      • Licensed Attorney
      • Enrolled Agent
      • CBAP - Certified Business Analysis Professional
      • Certified in Risk and Information System Controls (CRISC)
      • Microsoft Azure
      • Project Management Professional (PMP)

Preferred:

  • Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes. 
  • Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences. 
  • Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels. 
  • Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs. 
  • Experience supporting business process improvement, transformation, or technology-enabled change initiatives. 
  • Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom