1

Internship Vendor Risk Analyst Jobs in Oregon (NOW HIRING)

... Governance, and vendor business owners to manage thirdparty risk holistically. * Develop and ... cybersecurity, or technical/analytical roles . * Experience operating in fastpaced ...

Experience with vendor risk assessments and compliance frameworks. * Background in pricing strategy, cost modeling, or financial analysis. Special Requirements/Security Clearance * DoD Top Secret ...

Senior Security Compliance Analyst

OR · Remote

$110K - $140K/yr

We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and ... Conduct third-party vendor risk assessments, ensuring compliance with security policies and ...

... analyses, and escalation framework across all entities. * Own the Information Security Compliance ... vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization ...

OR · On-site

Experience leading analysts, managing a vendor oversight function, or owning cross-functional third-party risk, operational risk, compliance, or financial services control programs. Preferred ...

OR · On-site

The Global Risk Data & Analytics Fellow is a unique opportunity for a data-driven and risk-minded ... As volunteers, interns and fellows receive a monthly stipend to help defray their expenses ...

Operations Analyst

$50K - $80K/yr

... with paying vendor/partner invoices.- Support risk management processes (identifying risks ... Interns.- May serve as a mentor to fellow Sawdey MSD Team members.- Understand and adhere to ...

next page

Showing results 1-20

Internship Vendor Risk Analyst information

What is a vendor risk analyst?

A vendor risk analyst is a professional responsible for assessing and managing risks associated with third-party vendors and suppliers. They evaluate vendor security, compliance, and operational risks, often using risk management tools and frameworks to ensure vendor relationships do not pose threats to the organization. Strong analytical skills and knowledge of industry regulations are essential for this role.

What is an Internship Vendor Risk Analyst?

An Internship Vendor Risk Analyst is an entry-level position, often designed for students or recent graduates, that focuses on assessing and managing the risks associated with third-party vendors. Interns in this role help organizations evaluate the security, compliance, and reliability of vendors by analyzing documentation, conducting risk assessments, and supporting ongoing risk monitoring activities. They work under the guidance of senior analysts to ensure vendors meet company standards and regulatory requirements, gaining hands-on experience in risk management and vendor oversight.

How to become a risk analyst with no experience?

To become a risk analyst with no experience, focus on gaining relevant knowledge through online courses or certifications in risk management, finance, or data analysis. Entry-level roles often require strong analytical skills, proficiency with Excel or data tools, and a willingness to learn on the job; internships or volunteer opportunities can also provide practical experience.

What are some common challenges Internship Vendor Risk Analysts face when assessing third-party vendors?

Internship Vendor Risk Analysts often encounter challenges such as limited access to comprehensive vendor data, navigating complex regulatory requirements, and balancing multiple stakeholder interests. Interns must learn to evaluate risk with incomplete information and communicate findings clearly to both internal teams and vendors. Building strong analytical and communication skills, as well as understanding the organization's risk appetite, are key to overcoming these challenges and making meaningful contributions during the internship.

Is risk analyst an entry level job?

A risk analyst role can be entry level or require experience, depending on the organization. Entry-level risk analyst positions typically require a bachelor's degree in finance, economics, or a related field, and may involve basic data analysis skills and familiarity with risk management tools. More advanced roles may require several years of experience or specialized certifications.

What are the key skills and qualifications needed to thrive as an Internship Vendor Risk Analyst, and why are they important?

To thrive as an Internship Vendor Risk Analyst, you need a solid understanding of risk assessment, vendor management principles, and basic knowledge of compliance frameworks, often supported by coursework in finance, business, or information security. Familiarity with tools like Excel, risk management software, and platforms such as SAP Ariba or RSA Archer is typically expected. Attention to detail, analytical thinking, and effective communication are standout soft skills for gathering data and collaborating with internal stakeholders. These skills are crucial for identifying potential vendor risks, ensuring regulatory compliance, and supporting organizational decision-making.

How much do risk analyst interns make at Fannie Mae?

Risk analyst interns at Fannie Mae typically earn an hourly wage that ranges from $20 to $30, depending on experience and location. Internships often last for 10 to 12 weeks during the summer, providing valuable experience in risk assessment and financial analysis.

What is the difference between Internship Vendor Risk Analyst vs Vendor Risk Analyst?

AspectInternship Vendor Risk AnalystVendor Risk Analyst
CredentialsTypically pursuing or recent graduate, some certifications optionalUsually requires professional certifications like CRISC or CTP
Work EnvironmentInternship setting, entry-level tasks, learning-focusedFull-time role, responsible for ongoing risk assessments
Industry UsageCommon in finance, consulting, and tech companies for trainingEstablished position in risk management departments across industries

The Internship Vendor Risk Analyst is an entry-level role designed for students or recent graduates gaining experience in vendor risk management. In contrast, the Vendor Risk Analyst is a full-time professional responsible for ongoing risk assessments and mitigation strategies. While both roles involve evaluating vendor risks, the internship focuses on learning and support, whereas the analyst role involves independent decision-making and expertise.

What are the most commonly searched types of Vendor Risk Analyst jobs in Oregon? The most popular types of Vendor Risk Analyst jobs in Oregon are:
What are popular job titles related to Internship Vendor Risk Analyst jobs in Oregon? For Internship Vendor Risk Analyst jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Internship Vendor Risk Analyst jobs in Oregon look for? The top searched job categories for Internship Vendor Risk Analyst jobs in Oregon are:
What cities in Oregon are hiring for Internship Vendor Risk Analyst jobs? Cities in Oregon with the most Internship Vendor Risk Analyst job openings:

Third-Party Risk Management Program Officer

Heritage Bank

Hillsboro, OR

$100K - $126K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 4 days ago


Job description

Heritage Bank has an exciting opportunity to join our organization! We are seeking Third-Party Risk Management Program Officer to join our Risk and Compliance team. The third-party risk management program officer is responsible for the design, execution, and continuous improvement of the bank's third-party risk management program across the full vendor lifecycle, from onboarding through offboarding.

Operating within the Second Line of Defense (2LoD), this role provides governance and oversight to ensure operational alignment of the bank's TPRM processes across Information Security, Legal, Procurement, Business Units, and Internal Audit. This position is accountable for ensuring third-party risks, including cybersecurity, operational, compliance, reputational, and concentration risks, are appropriately identified, assessed, and monitored in alignment with regulatory expectations. The geographical location for this position is Tacoma, WA, Seattle, WA, Spokane, WA, or Portland, OR.

Base Salary Range: $100,884.00 - $126,105.00 - $151,326.00 annual The Role at a Glance: Leads and manages the Third-Party Risk Management (TPRM) Program, including development and continuous refinement of TPRM policies and procedures, risk tiering and segmentation models, risk rating methodologies, and vendor lifecycle control checkpoints. Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks. Oversees execution of inherent risk assessments, due diligence reviews, and control assessments across all third-party risk domains (cybersecurity, privacy, operational resilience, etc.).

Ensures appropriate engagement of cross-functional subject matter experts (e.g., Information Security, Legal, Compliance) and that roles and responsibilities are clearly defined within established processes. Defines and maintains program tools, templates, escalation protocols, and residual risk acceptance processes. Integrates and aligns TPRM program with related programs (e.g., Vendor Management, procurement, Business Continuity Planning, Information Security Risk Assessments, Cloud Governance, AI/Model Risk).

Establishes and tracks key risk indicators (KRIs). Provides executive-level reporting on third-party risk posture, program maturity, and systemic exposures (e.g., concentration risk, critical service dependency). Monitors and escalates open risk issues, overdue assessments, and policy exceptions.

Serves as the primary contact for regulatory exams and internal/external audits related to third-party risk. Performs continuous monitoring of Critical and High risk third parties. Maintains audit-ready documentation, evidence of program execution, and continuous improvement roadmap.

Monitors regulatory changes (e.g., OCC Bulletins, FFIEC updates, DORA, NYDFS, etc.) and updates program controls to align with evolving requirements. Core Skills and Qualifications: Bachelor’s degree in Business, Risk Management, Information Security or related field preferred. 5+ years of recent experience in a vendor risk management, third-party oversight, or enterprise risk program role within a financial services environment required.

Proven experience leading the development, implementation, and ongoing management of an enterprise-scale third-party risk management program required. Professional certifications as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or equivalent preferred. Equivalent combination of education, training, certifications, and/or relevant work experience may be considered.

Provide an exceptional level of service for internal and external customers, with the ability to build and maintain positive, professional relationships, to successfully interact with and influence all levels of management and functional and cross-functional areas across the organization. Highly effective listening, verbal, written, and telephone etiquette business communication skills, including effective questioning strategies, negotiation and presentation skills to communicate security-related concepts in a variety of settings, to a broad range of technical and non-technical staff. Ability to read, write, speak, and understand English well.

Strategic in approach to program design, problem solving, and decision-making, with demonstrated ability to quickly focus on key issues and make decisions under pressure of time constraints. Risk based mindset and strong analytical and critical thinking skills, with the ability to independently assess risk decisions and constructively challenge assumptions and conclusions. Thorough knowledge and understanding of regulatory frameworks (e.g.

FFIEC, GLBA, PCI-DSS, SOX, FFIEC, HIPAA etc.) and of NIST CSF, ISO 27001, COBIT, COSO and vendor risk management frameworks. Strong knowledge of information security assessment and auditing practices, including the ability to evaluate technical and business controls using established frameworks and methodologies, and to effectively interpret results from security tools and subject matter expert assessments. Thorough knowledge and understanding of related statutory banking compliance regulations issued by the FDIC, FinCEN, and Federal Reserve Board, with strong knowledge of privacy laws, such as GLBA and SOX.

Strong project management, planning, organizational, time management, and follow-up skills, demonstrating a strong sense of urgency and ability to execute quickly, timely and efficiently; independently ensuring that priorities are set and commitments and deadlines are met with minimal direction and oversight. Unquestionable integrity in handling sensitive and confidential information required. Proficient and advanced use and understanding of MS Office products (Word, Excel, Outlook), with the ability to adapt to and learn new technologies quickly.

Proficient use and understanding of third-party risk management software (ex. UpGuard, Tandem, Gartner, etc.). Work Environment/Conditions: Climate controlled office environment.

Work involves being able to concentrate on the matter at hand, under sometimes distracting work conditions, and frequent employee and customer contacts and interruptions during the day. Physical Demands/Effort: Work may involve the constant use of computer screens, reading of reports, and sitting throughout the day. Ability to operate a computer keyboard, multi-line telephone, photocopier, scanner and facsimile which often requires dexterity of hands and fingers with repetitive wrist and hand motion.

Typically sitting at a desk or table; intermittently standing, stooping, bending at the waist, walking, climbing, kneeling or crouching to file materials. Occasional lifting up to 20 lbs. (files, boxes, etc.).

At Heritage Bank, we work hard, but we also know how important it is to take time off to stay healthy, relax, and spend time doing what makes your heart happy! As part of our team, you’ll enjoy a total rewards package, which includes base salary based on the role, experience, and skill set, along with an exceptional benefits package (medical, dental, vision, life insurance, 401(k), community volunteer time), and generous time off policy. Full-time team members receive a minimum of 10 paid vacation days annually* and eight hours of paid sick leave per month*, while also enjoying 11 paid holidays each calendar year, and an annual float day.

*pro-rated from start date and/or hours worked.To view Benefits Summary: Apply > Current Openings > position > attachment. The above statements are intended to describe the general nature and level of work being performed and are not an exclusive list of all qualifications for this position. Heritage Bank is an Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other basis protected by applicable law.

Job applicants have certain legal rights. Please click here for information regarding these rights. If you need assistance completing the online application, please email: HBRecruiting@HeritageBankNW.com Salary Range Disclaimer The base salary range represents Heritage Bank’s current salary range for the position.

Actual salaries will vary depending on factors including, but not limited to, qualifications, experience, and job performance. The range listed is just one component of Heritage Bank’s total compensation package for full time and part time employees. Depending on position, other total compensation rewards may include, monthly, quarterly or annual incentive, and/or bonuses.

##JobCategory:Compliance / Audit## ##Street:3615 Pacific Avenue## ##City:Tacoma## ##State:WA## ##ZipCode:98418## ##Internal:false## *mon