The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST ... Third-Party Risk Management * Perform security reviews of vendors, suppliers, and third-party ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST ... Third-Party Risk Management * Perform security reviews of vendors, suppliers, and third-party ...
Share Consultant II, Technology 3rd Party Risk Management - Tax Transformation with Facebook Share Consultant II, Technology 3rd Party Risk Management - Tax Transformation with LinkedIn Share ...
Share Consultant II, Technology 3rd Party Risk Management - Tax Transformation with Facebook Share Consultant II, Technology 3rd Party Risk Management - Tax Transformation with LinkedIn Share ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST ... Third-Party Risk Management * Perform security reviews of vendors, suppliers, and third-party ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST ... Third-Party Risk Management * Perform security reviews of vendors, suppliers, and third-party ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
CBAP ® - Certified Business Analysis Professional * Certified in Risk and Information System ... to third-party risk, vendor management, or related compliance processes. * Strong verbal and ...
CBAP ® - Certified Business Analysis Professional * Certified in Risk and Information System ... to third-party risk, vendor management, or related compliance processes. * Strong verbal and ...
Principal Program Manager
Reston, VA · On-site
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Principal Program Manager
Reston, VA · On-site
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to ... Enrolled Agent * CBAP - Certified Business Analysis Professional * Certified in Risk and ...
Senior Analyst, Cybersecurity GRC
Washington, DC · On-site
$113K - $146K/yr
... Third Party Risk Management (TPRM) and Governance and Risk functions in conducting vendor due ... Senior Analyst, Cybersecurity GRC Responsibilities: - Review and understand current IT Risk ...
Senior Analyst, Cybersecurity GRC
Washington, DC · On-site
$113K - $146K/yr
... Third Party Risk Management (TPRM) and Governance and Risk functions in conducting vendor due ... Senior Analyst, Cybersecurity GRC Responsibilities: - Review and understand current IT Risk ...
Enterprise Risk Analyst
Manassas, VA · On-site
$64.47/hr
... and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public ... GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio ...
Enterprise Risk Analyst
Manassas, VA · On-site
$64.47/hr
... and third parties to facilitate enterprise risk analysis Ability to obtain and maintain a Public ... GRC) Experience with Assessment and Authorization (A&A) and eMASS Experience with Excel and Visio ...
... Third Party Risk Management (TPRM) and Governance and Risk functions in conducting vendor due ... broader GRC efforts. This position is 100% Onsite and not open for Remote. Senior Analyst ...
... Third Party Risk Management (TPRM) and Governance and Risk functions in conducting vendor due ... broader GRC efforts. This position is 100% Onsite and not open for Remote. Senior Analyst ...
... third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and ... Synthesize complex analyses from multiple stakeholders into concise, executive-ready ...
... third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and ... Synthesize complex analyses from multiple stakeholders into concise, executive-ready ...
In this role, you'll use your analytical expertise and understanding of risk principles to apply ... Experience with evaluating supplier or third-party risk indicators, including ownership, beneficial ...
In this role, you'll use your analytical expertise and understanding of risk principles to apply ... Experience with evaluating supplier or third-party risk indicators, including ownership, beneficial ...
Supply Chain Risk Specialist
Mclean, VA · On-site +1
$99K/yr
In this role, you'll use your analytical expertise and understanding of risk principles to apply ... Experience with evaluating supplier or third-party risk indicators, including ownership, beneficial ...
Supply Chain Risk Specialist
Mclean, VA · On-site +1
$99K/yr
In this role, you'll use your analytical expertise and understanding of risk principles to apply ... Experience with evaluating supplier or third-party risk indicators, including ownership, beneficial ...
... third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and ... Synthesize complex analyses from multiple stakeholders into concise, executive-ready ...
... third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and ... Synthesize complex analyses from multiple stakeholders into concise, executive-ready ...
... third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and ... Synthesize complex analyses from multiple stakeholders into concise, executive-ready ...
... third-party risk programs. * Assess adherence to the DUS Guide, program requirements, and ... Synthesize complex analyses from multiple stakeholders into concise, executive-ready ...
Supply Chain Risk Specialist
Mclean, VA · On-site
$99K/yr
In this role, you'll use your analytical expertise and understanding of risk principles to apply ... Experience with evaluating supplier or third-party risk indicators, including ownership, beneficial ...
Supply Chain Risk Specialist
Mclean, VA · On-site
$99K/yr
In this role, you'll use your analytical expertise and understanding of risk principles to apply ... Experience with evaluating supplier or third-party risk indicators, including ownership, beneficial ...
... topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk ... Five to seven years as a research analyst, consultant, or practitioner where you have led or been ...
... topics: risk quantification, third-party risk, systemic risk, compliance, and cyber risk ... Five to seven years as a research analyst, consultant, or practitioner where you have led or been ...
Security Governance Risk & Compliance (GRC) Analyst with Security Clearance
Washington, DC · On-site
$130K - $170K/yr
As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include ... Facilitate the third-party vendor on-boarding and annual review process by evaluating the security ...
Security Governance Risk & Compliance (GRC) Analyst with Security Clearance
Washington, DC · On-site
$130K - $170K/yr
As a Security Governance Risk & Compliance (GRC) Analyst, your responsibilities will include ... Facilitate the third-party vendor on-boarding and annual review process by evaluating the security ...
Senior Security Engineer, GRC
Reston, VA · On-site +1
$119K - $163K/yr
Conduct third-party vendor risk assessments, including use case-specific risk analysis, ongoing ... What You\'ll Bring * 8+ years of experience in GRC, information security compliance, or a closely ...
Senior Security Engineer, GRC
Reston, VA · On-site +1
$119K - $163K/yr
Conduct third-party vendor risk assessments, including use case-specific risk analysis, ongoing ... What You\'ll Bring * 8+ years of experience in GRC, information security compliance, or a closely ...
Grc Third Party Risk Analyst information
See Reston, VA salary details
$46.3K - $53.9K
9% of jobs
$60.4K is the 25th percentile. Wages below this are outliers.
$53.9K - $61.4K
18% of jobs
$61.4K - $69K
0% of jobs
$69K - $76.6K
6% of jobs
$76.6K - $84.1K
2% of jobs
$84.1K - $91.7K
4% of jobs
$91.7K - $99.3K
2% of jobs
The median wage is $100.4K / yr.
$99.3K - $106.8K
52% of jobs
$106.8K - $114.4K
6% of jobs
$114.4K - $122K
0% of jobs
$122K - $129.5K
0% of jobs
$46.3K
$90.2K
$129.5K
How much do grc third party risk analyst jobs pay per year?
What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?
What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?
What is a GRC Third Party Risk Analyst?
What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?
| Aspect | Grc Third Party Risk Analyst | Grc Vendor Risk Analyst |
|---|---|---|
| Certifications | Certifications like CRISC, CISA often preferred | Same certifications commonly required |
| Work Environment | Focuses on third-party relationships and risk assessments | Primarily evaluates vendor-specific risks and compliance |
| Industry Usage | Used across finance, healthcare, and tech sectors | Commonly found in industries with extensive vendor networks |
The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

Other
Medical, Dental, Vision, Life, Retirement
Posted 13 days ago
Job description
Position Summary
The Governance, Risk & Compliance (GRC) Analyst is responsible for supporting and maintaining the organization's cybersecurity governance, risk management, and compliance programs. This role works across Information Security, Engineering, Product, IT, and business stakeholders to ensure compliance with applicable regulatory, contractual, and industry security requirements.Â
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC 27001 requirements through evidence collection, control monitoring, risk assessments, audit support, policy management, and remediation tracking.Â
Key ResponsibilitiesÂ
Compliance & Audit ManagementÂ
- Maintain compliance programs aligned with NIST CSF, CMMC, Cyber Essentials Plus, SOC 2, and ISO/IEC 27001.
- Coordinate internal and external audits, assessments, and attestation activities.
- Collect, validate, and maintain compliance evidence and audit artifacts.
- Track audit findings and remediation activities through completion.
- Support control testing and validation to ensure ongoing compliance.Â
Governance & Risk ManagementÂ
- Conduct security risk assessments and assist with enterprise risk management activities.
- Maintain risk registers, track mitigation plans, and monitor remediation progress.
- Assist with development and maintenance of security policies, standards, procedures, and guidelines.
- Monitor security and compliance control effectiveness and identify opportunities for improvement.
- Support control mapping and crosswalk activities across multiple compliance frameworks.Â
Third-Party Risk ManagementÂ
- Perform security reviews of vendors, suppliers, and third-party service providers.
- Track vendor assessment findings and remediation activities.
- Support ongoing monitoring of third-party security and compliance risks.Â
Customer & Regulatory SupportÂ
- Respond to customer security questionnaires, due diligence requests, and compliance inquiries.
- Support sales and customer-facing teams with security documentation and assurance materials.
- Assist with documenting compliance posture and security program maturity.Â
Program AdministrationÂ
- Maintain GRC platforms and compliance repositories.
- Develop metrics, dashboards, and compliance reporting for management.
- Coordinate annual security awareness, compliance, and policy review activities.
- Support continuous improvement initiatives across the security and compliance program.Â
Required Qualifications
- Bachelor's degree in Cybersecurity, Information Security, Information Systems, Business, or related field (or equivalent experience).
- 3+years of experience in Governance, Risk, and Compliance, Information Security, Audit, or related disciplines.
- Working knowledge of: Â
- NIST Cybersecurity Framework (CSF)
- CMMC
- Cyber Essentials Plus
- ISO/IEC 27001
- SOC 2
- Risk assessment methodologies
- Experience supporting audits, assessments, or certification activities.Â
- Strong written communication, documentation, and organizational skills.
- Ability to manage multiple priorities and deadlines in a fast-paced environment.Â
Benefits at Babel Street (just to name a few...)
- Health Benefits: Babel Street covers 85-100% monthly premium costs for Medical, Dental, Vision, Life & Disability insurances - for you and your family!
- Retirement Plans:Â Babel Street offers both a Traditional and Roth 401(K) with a very competitive match.
- Unlimited Flexible Leave: We trust our employees to manage their own time and balance their personal and work lives.
- Holidays: Babel Street provides employees with 12 paid Federal Holidays
- Tuition Reimbursement: We are committed to investing in our employees. One way we do that is with our Tuition Reimbursement Program for continuing education.        Â
Babel Street is an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected Veteran status, age, or any other characteristic protected by law. Further, Babel Street will not discriminate against applicants for inquiring about, discussing or disclosing their pay or, in certain circumstances, the pay of their coworker, Pay Transparency Nondiscrimination. In addition, Babel Street's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request, we will provide you with more information about such accommodations.
About Babel Street
Sourced by ZipRecruiter
Company size
1 - 10 Employees
Headquarters location
Reston, VA, US
Year founded
2009