1

Grc Third Party Risk Analyst Jobs (NOW HIRING)

Risk Analyst

Deerfield, IL · On-site +1

$87K - $110K/yr

Experience working with GRC, ticketing, identity governance, or third-party risk management ... Strong analytical, critical thinking, and communication skills with the ability to evaluate complex ...

New

As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance ... Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ...

Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality ... Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ...

Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality ... Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or ...

$104 - $166/hr

Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement -- policy, control testing, and POA&M management ...

... analyst-assistive tooling to focus effort on judgment-intensive decisions. Education and Experience * 8+ years in information security, IT risk, or GRC, including 4+ years focused on third-party ...

Showing results 21-40

Grc Third Party Risk Analyst information

See salary details

$44.5K

$86.7K

$124.5K

How much do grc third party risk analyst jobs pay per year?

As of Aug 23, 2026, the average yearly pay for grc third party risk analyst in the United States is $86,688.00, according to ZipRecruiter salary data. Most workers in this role earn between $56,500.00 and $100,000.00 per year, depending on experience, location, and employer.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

More about Grc Third Party Risk Analyst jobs

What cities are hiring for Grc Third Party Risk Analyst jobs?

Cities with the most Grc Third Party Risk Analyst job openings:

What states have the most Grc Third Party Risk Analyst jobs?

States with the most job openings for Grc Third Party Risk Analyst jobs include:

Infographic showing various Grc Third Party Risk Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $86,688 per year, or $41.7 per hour.

Risk Analyst

Alera Group

Deerfield, IL • On-site, Remote

$87K - $110K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday

New


Alera Group rating

8.0

Company rating: 8.0 out of 10

Based on 30 frontline employees who took The Breakroom Quiz

167th of 311 rated insurance


Job description

OVERVIEW
Risk Analyst

Location: Deerfield, IL | Remote
Department: Corporate Services

Overview

At Alera Group, our corporate teams play a critical role in supporting the success of colleagues and clients across the country. From Human Resources and Finance to Technology, Legal, Marketing, and Operations, these professionals ensure our organization runs efficiently while enabling our teams to deliver exceptional service.

About Alera Group

Founded in 2017, Alera Group has grown to become the 14th largest broker of U.S. business. We are passionate about our clients’ success in Employee Benefits, Property & Casualty Insurance, and Financial Services. With offices nationwide, our collaborative approach allows us to deliver national strength with local service.

We are always looking to connect with talented professionals who want to contribute to a collaborative, high-growth environment and help drive strategic initiatives across a national organization.

Why Join Alera Group?
  • Collaborate with purpose – Work alongside colleagues who believe the best results come from strong partnerships, shared expertise, and supporting one another.
  • Build your career – Expand your expertise through meaningful work, continuous learning, and opportunities to grow across a national organization.
  • Make an impact – Help clients navigate complex challenges while contributing to solutions that make a difference for their businesses, employees, and communities.

RESPONSIBILITIES
  • Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements
  • Review SOC reports, security questionnaires, audit documentation, certifications, and other evidence to identify control gaps and potential business impacts
  • Coordinate and execute user access reviews, validating access appropriateness and ensuring identified issues are remediated promptly
  • Document risks, findings, recommendations, and remediation plans while maintaining accurate records within governance, risk, and compliance platforms
  • Serve as a trusted advisor to stakeholders by asking thoughtful questions, identifying underlying business needs, assessing potential risks, and translating ambiguous requests into clear risk assessment, governance, and compliance activities
  • Partner with Information Security, Technology, Legal, Procurement, and business stakeholders to identify requirements, resolve risk and compliance issues, and drive effective risk-based decision-making
  • Support internal and external audits, regulatory examinations, and compliance activities through evidence collection and documentation management
  • Develop risk metrics, reporting, and dashboards that drive visibility, support decision-making, and measure the effectiveness of third-party risk and governance programs
  • Identify opportunities to improve risk management processes, controls, reporting, governance practices, and automation capabilities

QUALIFICATIONS

Required Qualifications

  • 5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field
  • Hands-on experience performing third-party or vendor security risk assessments
  • Experience coordinating or performing user access reviews, access certifications, or identity governance activities
  • Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards
  • Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences
  • Experience working with GRC, ticketing, identity governance, or third-party risk management platforms
  • Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities
Certifications
  • CISA, CGRC or equivalent preferred
Preferred Qualifications
  • Experience within a regulated industry such as insurance, financial services, or healthcare
  • Experience supporting SOC 2, HIPAA, NYDFS, or similar regulatory and compliance programs
  • Experience with automated identity governance, access certification, or third-party risk management solutions
  • Experience supporting internal or external security and compliance audits
  • Ability to independently research requirements, develop risk-based recommendations, and communicate findings to stakeholders
  • Demonstrated ability to gather and clarify ambiguous requirements, ask effective probing questions, and develop practical risk-based solutions in collaboration with business stakeholders
Compensation
  • Salary Range: $87,000 - $110,000 annually
  • Bonus Eligible: Yes
Benefits

Eligible colleagues enjoy a comprehensive benefits package including:

  • Medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k)
  • Generous paid time off
  • Professional development and career growth opportunities

ADDITIONAL INFORMATION

Work Model:
This role is Remote
Preference for Central or Eastern Time Zone

Professional Development – Alera Group Academy

At Alera Group, growth isn’t left to chance. Through Alera Group Academy, we provide structured development opportunities designed to help you expand your expertise and build a meaningful career.

You’ll have access to:

  • Role-specific learning paths

  • Leadership development programs

  • Technical and compliance training

  • Industry certifications and continuing education support

  • Peer learning and knowledge-sharing communities

Whether you’re deepening technical expertise or preparing for leadership, we’re invested in helping you grow.

We're an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status, or any other protected class.

Alera Group is committed to protecting your privacy. Please review our Privacy Policy to understand what personal information we may collect and use as part of your application process.

#LI-NO1

#LI-Remote 


Location Type
Hybrid - 2 or less days in officeQualifications:

Required Qualifications

  • 5+ years of experience in cybersecurity risk, IT risk, information security, governance, risk and compliance (GRC), third-party risk, IT audit, or a related field
  • Hands-on experience performing third-party or vendor security risk assessments
  • Experience coordinating or performing user access reviews, access certifications, or identity governance activities
  • Familiarity with cybersecurity and compliance frameworks such as NIST CSF, SOC 2, CIS Controls, HIPAA, or similar standards
  • Strong analytical, critical thinking, and communication skills with the ability to evaluate complex situations, identify underlying business and risk requirements, and effectively communicate recommendations to both technical and non-technical audiences
  • Experience working with GRC, ticketing, identity governance, or third-party risk management platforms
  • Exercise sound judgment when evaluating risk scenarios, identifying gaps in information, and determining appropriate next steps, stakeholders, and remediation activities
Certifications
  • CISA, CGRC or equivalent preferred
Preferred Qualifications
  • Experience within a regulated industry such as insurance, financial services, or healthcare
  • Experience supporting SOC 2, HIPAA, NYDFS, or similar regulatory and compliance programs
  • Experience with automated identity governance, access certification, or third-party risk management solutions
  • Experience supporting internal or external security and compliance audits
  • Ability to independently research requirements, develop risk-based recommendations, and communicate findings to stakeholders
  • Demonstrated ability to gather and clarify ambiguous requirements, ask effective probing questions, and develop practical risk-based solutions in collaboration with business stakeholders
Compensation
  • Salary Range: $87,000 - $110,000 annually
  • Bonus Eligible: Yes
Benefits

Eligible colleagues enjoy a comprehensive benefits package including:

  • Medical, dental, and vision insurance
  • Life and disability coverage
  • 401(k)
  • Generous paid time off
  • Professional development and career growth opportunities
Education:UNAVAILABLEEmployment Type: FULL_TIME

What Alera Group employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom