1

Grc Third Party Risk Analyst Jobs in Silver Spring, MD

Security Analyst

Columbia, MD · Hybrid

$55 - $60/hr

Description Position Overview The Information Security Analyst II (GRC) provides support for ... the third-party risk management process • Maintain and update the risk register and track ...

Security Analyst

Columbia, MD · Hybrid

$55 - $60/hr

Description Position Overview The Information Security Analyst II (GRC) provides support for ... the third-party risk management process • Maintain and update the risk register and track ...

Procurement Risk & Compliance Lead

Centreville, VA · On-site

$155K/yr

Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management. Reporting to the Global Head of ...

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ...

The Due Diligence Analyst will support the client's Global Security, Compliance, and Risk ... third-party risk assessments. * Engage with cross-functional stakeholders including Security ...

New

Showing results 41-60

Grc Third Party Risk Analyst information

See Silver Spring, MD salary details

$46K

$89.6K

$128.7K

How much do grc third party risk analyst jobs pay per year?

As of Aug 23, 2026, the average yearly pay for grc third party risk analyst in Silver Spring, MD is $89,616.00, according to ZipRecruiter salary data. Most workers in this role earn between $58,400.00 and $103,400.00 per year, depending on experience, location, and employer.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What are popular job titles related to Grc Third Party Risk Analyst jobs in Silver Spring, MD?

For Grc Third Party Risk Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Grc Third Party Risk Analyst jobs in Silver Spring, MD look for?

The top searched job categories for Grc Third Party Risk Analyst jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Grc Third Party Risk Analyst jobs?

Cities near Silver Spring, MD with the most Grc Third Party Risk Analyst job openings:

Infographic showing various Grc Third Party Risk Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $89,616 per year, or $43.1 per hour.

$55 - $60/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Job description

Description
Position Overview The Information Security Analyst II (GRC) provides support for Governance, Risk, and Compliance activities aligned to NIST CSF, NIST SP 800-53, HIPAA Security Rule, and HITRUST CSF, PCI-DSS. The role supports risk assessments, audit readiness, control validation, and policy governance. Essential Duties and Responsibilities Support compliance initiatives aligned to NIST, HIPAA, and HITRUST, PCI-DSS frameworks Assist in maintaining control mappings and compliance documentation Perform control testing and support evidence collection for audits Support HITRUST certification readiness activities Support enterprise cyber-risk management activities Execute and oversee the third-party risk management process Maintain and update the risk register and track remediation Support responses to third-party security questionnaires. Support contract review tasks in support of Cyber and Data security language. Assist with development and maintenance of security policies and standards Maintain audit documentation repositories Support reporting on compliance metrics and KPIs Collaborate with cross-functional teams to address risk and compliance gaps Minimum Requirements 3-5 years of experience in information security, risk, or compliance Bachelor's degree in systems/ IT Security related field Certified in CISSP, CISM or CRISC -ISACA preferred Knowledge of NIST CSF, NIST 800-53, HIPAA, and HITRUST, PCI-DSS Strong analytical, documentation, and communication skills Ability to work collaboratively across teams. Self-Driven - Ability to manage tasks and organize project work
Skills
hipaa compliance, hitrust, nist, information security, security
Top Skills Details
hipaa compliance,hitrust,nist
Additional Skills & Qualifications
Security Analyst Contract alignment Implementing Security controls Risk Management - 3rd party risk management program Governance and Risk Management HIPAA and HI-TRUST experience is highly desired
Experience Level
Intermediate Level
Job Type & Location
This is a Contract to Hire position based out of Columbia, MD.
Pay and Benefits
The pay range for this position is $55.00 - $60.00/hr.
Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: Medical, dental & vision Critical Illness, Accident, and Hospital 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available Life Insurance (Voluntary Life & AD&D for the employee and dependents) Short and long-term disability Health Spending Account (HSA) Transportation benefits Employee Assistance Program Time Off/Leave (PTO, Vacation or Sick Leave)
Workplace Type
This is a hybrid position in Columbia,MD.
Application Deadline
This position is anticipated to close on Aug 28, 2026.
About TEKsystems
We're partners in transformation. We help clients activate ideas and solutions to take advantage of a new world of opportunity. We are a team of 80,000 strong, working with over 6,000 clients, including 80% of the Fortune 500, across North America, Europe and Asia. As an industry leader in Full-Stack Technology Services, Talent Services, and real-world application, we work with progressive leaders to drive change. That's the power of true partnership. TEKsystems is an Allegis Group company.
The company is an equal opportunity employer and will consider all applications without regards to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
About TEKsystems and TEKsystems Global Services
We're a leading provider of business and technology services. We accelerate business transformation for our customers. Our expertise in strategy, design, execution and operations unlocks business value through a range of solutions. We're a team of 80,000 strong, working with over 6,000 customers, including 80% of the Fortune 500 across North America, Europe and Asia, who partner with us for our scale, full-stack capabilities and speed. We're strategic thinkers, hands-on collaborators, helping customers capitalize on change and master the momentum of technology. We're building tomorrow by delivering business outcomes and making positive impacts in our global communities. TEKsystems and TEKsystems Global Services are Allegis Group companies. Learn more at TEKsystems.com.
The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.
San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.
Massachusetts Lie Detector: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.