1

Grc Third Party Risk Analyst Jobs in Rosenberg, TX

Risk Coordinator

Sugar Land, TX · On-site

$40K - $55K/yr

Risk Coordinator Location: Sugar Land, TX (In Office) Salary Range (Base): $40,000 - $55,000 ... third-party administrators (e.g., Sedgwick) - Conduct video review and support incident fact ...

Cyber Risk Lead

Houston, TX · On-site

$180 - $210/hr

Improve the fidelity of cyber risk measurements through engineering automation, analytics, and new data sources. * Connect risk, vulnerability, asset, GRC, and engineering workflow data to reduce ...

Cyber Risk Lead

Houston, TX · On-site

$180 - $210/hr

Improve the fidelity of cyber risk measurements through engineering automation, analytics, and new data sources. * Connect risk, vulnerability, asset, GRC, and engineering workflow data to reduce ...

Make banking a Fifth Third better ® We connect great people to great opportunities. Are you ready ... The Credit Analyst is knowledgeable on financial and risk analysis and demonstrates proficiency in ...

Make banking a Fifth Third better ® We connect great people to great opportunities. Are you ready ... The Credit Analyst is knowledgeable on financial and risk analysis and demonstrates proficiency in ...

Showing results 41-60

Grc Third Party Risk Analyst information

See Rosenberg, TX salary details

$39.7K

$77.3K

$111.1K

How much do grc third party risk analyst jobs pay per year?

As of Aug 9, 2026, the average yearly pay for grc third party risk analyst in Rosenberg, TX is $77,350.00, according to ZipRecruiter salary data. Most workers in this role earn between $50,400.00 and $89,200.00 per year, depending on experience, location, and employer.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What cities near Rosenberg, TX are hiring for Grc Third Party Risk Analyst jobs? Cities near Rosenberg, TX with the most Grc Third Party Risk Analyst job openings:
Infographic showing various Grc Third Party Risk Analyst job openings in Rosenberg, TX as of August 2026, with employment types broken down into 1% As Needed, 85% Full Time, 11% Part Time, and 3% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $77,350 per year, or $37.2 per hour.

Director - Technology Risk Consulting - Artificial Intelligence and Emerging Technology

RSM

Houston, TX

Full-time

Re-posted 15 days ago


Job description

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM.

Role Summary

The Director, AI & Emerging Technology Risk provides strategic leadership across client delivery, presales, and advisory services related to artificial intelligence and emerging technologies. This role blends AI expertise, enterprise risk management, technology risk leadership, solution architecture, and software development oversight to help clients innovate responsibly while managing risk. The Director plays a key role in shaping gotomarket strategy, supporting presales efforts, and serving as an executive advisor throughout the client lifecycle.

Artificial Intelligence & Emerging Technology Leadership

  • Advise executive stakeholders on AI and emerging-technology risk across governance, ethics, security, privacy, and operational resilience-grounded in how models are built, deployed, and monitored in production
  • Lead client decisioning on GenAI/ML adoption by translating business use cases into implementable architectures, control requirements, and delivery roadmaps (people/process/technology)
  • Track evolving model capabilities, platforms, and threat/regulatory trends to continuously refine solution patterns, controls, and sales positioning for risk-focused AI offerings

Enterprise Risk & Technology Risk Strategy

  • Design and operationalize AI/technology risk frameworks aligned to ERM-mapping controls to the AI/ML lifecycle (data, training, evaluation, deployment, monitoring, change management)
  • Assess enterprise-wide AI impacts across cybersecurity, privacy, model risk management (MRM), third-party risk, and compliance-producing actionable remediation plans and control implementation backlogs
  • Present AI risk posture, risk appetite alignment, and control maturity to Boards and executive committees using clear metrics (KRIs/KPIs), model inventories, and audit-ready documentation

Solutions Architecture & Software Oversight

  • Architect AI-enabled solutions for risk consulting clients (including GenAI/RAG patterns) with secure-by-design, scalable, and governable reference architectures
  • Evaluate SDLC and MLOps practices-cloud landing zones, APIs, data pipelines, CI/CD, model registries, and deployment strategies-to identify risk, control gaps, and engineering fixes
  • Embed "risk-by-design" into build plans: threat modeling, privacy engineering, evaluation/validation protocols, human-in-the-loop controls, monitoring/alerting, and incident response runbooks

Client Delivery & Practice Leadership

  • Lead AI risk and emerging-technology engagements from strategy to implementation-owning delivery plans, sprint execution, stakeholder management, and outcomes
  • Establish delivery governance (scope, RAID, quality gates, model validation checkpoints) and ensure solutions are production-ready, auditable, and defensible
  • Build and mentor cross-functional teams (risk, data science, engineering, security) and provide technical leadership across Managers and Senior Managers
  • Develop reusable accelerators (reference architectures, control libraries, evaluation harnesses, templates) and publish market-facing thought leadership to scale delivery and sales
  • Drive account expansion by identifying adjacent risk opportunities, quantifying value, and partnering with client leaders to turn delivery success into follow-on sales

GotoMarket Leadership

  • Own delivery sales for AI risk pursuits: qualify opportunities, shape deal strategy, and lead solutioning as the senior AI engineering/risk SME
  • Define and package AI risk solution offerings (e.g., GenAI governance, MRM uplift, secure RAG, AI SDLC/MLOps controls) with clear value propositions and deliverables
  • Lead proposal development-scoping, staffing model, delivery approach, assumptions, pricing inputs, and risk-managed implementation plan
  • Run client workshops and executive presentations that walk through architectures, control designs, and delivery plans-bridging engineering details to risk outcomes
  • Translate transformation goals into implementable AI risk solutions aligned to regulatory guidance, internal governance, and target-state technology architecture
  • Build trusted C-level relationships and maintain pipeline by connecting delivery success to measurable risk reduction, audit readiness, and operational resilience

Experience, Skills & Qualifications

  • Bachelor's or Master's degree in Computer Science, Engineering, Data Science, Risk, or related discipline (or equivalent practical experience)
  • 8-10+ years leading technology risk and/or AI engineering delivery in consulting or industry, including ownership of large client programs
  • Job relevant certification (ie, Azure, Aws, AI certifications, etc.)

Preferred Qualifications

  • Deep knowledge of modern AI/ML and GenAI (LLMs, RAG, evaluation, safety), and the ability to translate that into concrete risk controls and implementation patterns
  • Proven delivery sales experience: shaping pursuits, leading solutioning, contributing to pricing, and presenting to executive buyers
  • Strong understanding of cloud and data architecture, SDLC, and MLOps/LLMOps (CI/CD, IaC, observability, model registry, feature stores, policy-as-code)
  • Demonstrated ability to embed governance, security, privacy, and model risk management early in design/build, and to stand up audit-ready evidence and controls
  • Executive-level communicator who can translate between engineers, risk leaders, regulators/auditors, and business stakeholders; comfortable owning both delivery and commercial outcomes

At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits.

All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership.RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at 800-274-3978 or send us an email at careers@rsmus.com.

RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.

RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.

At RSM, an employee's pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.

Compensation Range: $126,500 - $254,700

Individualsselected for this role will be eligible for a discretionary bonus based on firm and individual performance.