1

Grc Third Party Risk Analyst Jobs in Rosenberg, TX

Aramco Trading Americas Market Risk Analyst (1935) Market Risk Staff - Houston, TX. - Full Time ... NO THIRD-PARTY CANDIDATES ACCEPTED

... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

next page

Showing results 1-20

Grc Third Party Risk Analyst information

See Rosenberg, TX salary details

$39.7K

$77.3K

$111.1K

How much do grc third party risk analyst jobs pay per year?

As of Aug 29, 2026, the average yearly pay for grc third party risk analyst in Rosenberg, TX is $77,350.00, according to ZipRecruiter salary data. Most workers in this role earn between $50,400.00 and $89,200.00 per year, depending on experience, location, and employer.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What cities near Rosenberg, TX are hiring for Grc Third Party Risk Analyst jobs?

Cities near Rosenberg, TX with the most Grc Third Party Risk Analyst job openings:

Infographic showing various Grc Third Party Risk Analyst job openings in Rosenberg, TX as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 14% Part Time, and 5% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $77,350 per year, or $37.2 per hour.

Cybersecurity Risk & Compliance Analyst

Houston, TX

VoltaGrid
11 - 50 employees

Full-time

Posted 3 days ago

New


Job description

Position Title: Cybersecurity Risk & Compliance Analyst
Location: HOUSTON, TX
FLSA Class: EXEMPT
Responsible to: Senior Manager of Technical Operations

Position Summary: VoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst to help formalize and scale our risk governance, compliance, and policy framework across both IT and operational environments.

This role is central to evolving our cybersecurity program from reactive support to structured, institutionalized risk governance. You will drive clarity and consistency in how we manage risk, controls, policies, and audit readiness, ensuring alignment with both regulatory requirements and real-world operational needs.

The ideal candidate brings a strong understanding of GRC principles, paired with the ability to translate complex requirements into practical, enforceable processes that integrate seamlessly into day-to-day operations.

As VoltaGrid continues to scale, cybersecurity must evolve into a structured, measurable, and governance-driven function. This role ensures that our approach to risk and compliance is not just about meeting requirements, but about building a repeatable, scalable framework that supports secure growth across both digital and physical infrastructure. You will play a key role in establishing clarity, accountability, and trust in how VoltaGrid manages risk across the organization

Essential Duties and Responsibilities:

  • Develop, implement, and maintain cybersecurity policies, standards, and procedures, ensuring they are clear, actionable, and aligned with organizational needs.
  • Own and manage risk assessment processes, including identifying, evaluating, and tracking risks across IT and operational technology environments.
  • Support and drive compliance initiatives (e.g., SOC 2, ISO 27001), including control design, evidence collection, and audit coordination.
  • Establish and maintain a control framework that aligns security practices with regulatory and business requirements.
  • Partner with engineering, IT, and operations teams to ensure controls are implemented effectively and embedded into workflows.
  • Manage and track risk registers, control gaps, and remediation efforts, providing visibility to leadership.
  • Support third-party risk management, including vendor assessments and ongoing monitoring.
  • Collaborate with cybersecurity and technology teams to align security tooling and monitoring with compliance and risk objectives.
  • Assist in developing and maintaining security awareness and policy training programs.
  • Produce clear, executive-ready reporting on risk posture, compliance status, and program maturity.
  • Continuously evaluate and improve the organization’s governance model, processes, and documentation.

Other Requirements:

  • 3-6 years of experience in GRC, cybersecurity compliance, risk management, or related roles.
  • Strong understanding of common frameworks and standards such as:
    • SOC 2
    • ISO 27001
    • NIST CSF or similar
  • Experience developing and managing policies, controls, and risk assessments.
  • Familiarity with audit processes and evidence management.
  • Ability to translate technical and regulatory requirements into practical processes.
  • Strong organizational, analytical, and communication skills.

Preferred Qualification:

  • Experience in critical infrastructure, energy, or industrial environments.
  • Familiarity with OT/ICS risk and compliance considerations.
  • Experience with GRC tools or compliance automation platforms (e.g., Drata).
  • Understanding of third-party risk management frameworks.
  • Relevant certifications (e.g., CISA, CRISC, CISSP, ISO 27001 Lead Implementer)

VoltaGrid is an Equal Opportunity Employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, alienage or national origin, ancestry, citizenship status, age, disability or handicap, sex, marital status, veteran status, sexual orientation, genetic information, arrest record, or any other characteristic protected by applicable federal, state or local laws.

Our management team is dedicated to this policy with respect to recruitment, hiring, placement, promotion, transfer, training, compensation, benefits, employee activities, and general treatment during employmentÂ