1

Internship Vendor Risk Analyst Jobs in Cottage Grove, WI

Security Analyst

Madison, WI · On-site

$78 - $85/mo

ISS is responsible for • Identifying and continuously assessing risk • Developing ... DMS and its vendors • Foster transparency, accountability, and timely resolution of ...

ISS is responsible for * Identifying and continuously assessing risk * Developing ... response, vendors, technical teams, and other program stakeholders. · In partnership with ISS ...

... security compliance, risk assessment, documentation, and stakeholder communication . Key ... Partner with security teams, business groups, vendors, and technical teams. * Support software ...

Senior IT Security Analyst

Madison, WI · On-site +1

$90K - $115K/yr

Can conduct risk assessments, control evaluations, and gap analyses mapped to NIST CSF to support ... Have assessed and monitored third-party vendors to ensure compliance with company security policies ...

Showing results 21-40

Internship Vendor Risk Analyst information

See Cottage Grove, WI salary details

$61.6K

$102.6K

$137.8K

How much do internship vendor risk analyst jobs pay per year?

As of Aug 30, 2026, the average yearly pay for internship vendor risk analyst in Cottage Grove, WI is $102,603.00, according to ZipRecruiter salary data. Most workers in this role earn between $75,800.00 and $124,100.00 per year, depending on experience, location, and employer.

What is an internship vendor risk analyst?

An Internship Vendor Risk Analyst is an entry-level position, often designed for students or recent graduates, that focuses on assessing and managing the risks associated with third-party vendors. Interns in this role help organizations evaluate the security, compliance, and reliability of vendors by analyzing documentation, conducting risk assessments, and supporting ongoing risk monitoring activities. They work under the guidance of senior analysts to ensure vendors meet company standards and regulatory requirements, gaining hands-on experience in risk management and vendor oversight.

What are the key skills and qualifications needed to thrive as an internship vendor risk analyst, and why are they important?

To thrive as an Internship Vendor Risk Analyst, you need a solid understanding of risk assessment, vendor management principles, and basic knowledge of compliance frameworks, often supported by coursework in finance, business, or information security. Familiarity with tools like Excel, risk management software, and platforms such as SAP Ariba or RSA Archer is typically expected. Attention to detail, analytical thinking, and effective communication are standout soft skills for gathering data and collaborating with internal stakeholders. These skills are crucial for identifying potential vendor risks, ensuring regulatory compliance, and supporting organizational decision-making.

What are some common challenges internship vendor risk analysts face when assessing third-party vendors?

Internship Vendor Risk Analysts often encounter challenges such as limited access to comprehensive vendor data, navigating complex regulatory requirements, and balancing multiple stakeholder interests. Interns must learn to evaluate risk with incomplete information and communicate findings clearly to both internal teams and vendors. Building strong analytical and communication skills, as well as understanding the organization's risk appetite, are key to overcoming these challenges and making meaningful contributions during the internship.

What is the difference between Internship Vendor Risk Analyst vs Vendor Risk Analyst?

AspectInternship Vendor Risk AnalystVendor Risk Analyst
CredentialsTypically pursuing or recent graduate, some certifications optionalUsually requires professional certifications like CRISC or CTP
Work EnvironmentInternship setting, entry-level tasks, learning-focusedFull-time role, responsible for ongoing risk assessments
Industry UsageCommon in finance, consulting, and tech companies for trainingEstablished position in risk management departments across industries

The Internship Vendor Risk Analyst is an entry-level role designed for students or recent graduates gaining experience in vendor risk management. In contrast, the Vendor Risk Analyst is a full-time professional responsible for ongoing risk assessments and mitigation strategies. While both roles involve evaluating vendor risks, the internship focuses on learning and support, whereas the analyst role involves independent decision-making and expertise.

What are the most commonly searched types of Vendor Risk Analyst jobs in Cottage Grove, WI?

The most popular types of Vendor Risk Analyst jobs in Cottage Grove, WI are:

What cities near Cottage Grove, WI are hiring for Internship Vendor Risk Analyst jobs?

Cities near Cottage Grove, WI with the most Internship Vendor Risk Analyst job openings:

Infographic showing various Internship Vendor Risk Analyst job openings in Cottage Grove, WI as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 9% Part Time, and 4% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution, with an average salary of $102,603 per year, or $49.3 per hour.

Security Analyst

Novalink Solutions LLC

Madison, WI • On-site

$78 - $85/mo

Full-time

Posted 4 days ago


Job description

Job Description: The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol and other drug abuse prevention services, mental health, public health, and long-term care. The Information Security Section (ISS) serves the Department by creating an information security culture and enabling the business. We are metrics minded, employee focused, and view security as a service. ISS is responsible for • Identifying and continuously assessing risk • Developing, institutionalizing, and improving strategies to mitigate risk • Limiting the potential effects of information security events • The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan. The Information Security Section (ISS) is functionally organized into Security Awareness and Governance, Compliance, Architecture, and Portfolio Management. Cross-team collaboration is essential to our success. The DHS Liaison serves the Division of Medicaid Services and is the champion for security initiatives integrating information security into program operations. This work is completed by engaging other security staff, communicating risk, and developing strategies to reduce risk. To successfully do this work, one must possess strong communication and interpersonal skills capable of presenting to diverse audiences including executive and non-technical individuals. A federally recognized (ANSI) information security certification must be obtained within 6 months of the start date and maintained for this position. The Department of Defense (DOD) 8570 Baseline Certifications defined by Defense Information Systems Agency (DISA) is the baseline to consider when reviewing the relevance of the certification. Goals and Worker Activities 1. Integrate security into program operations • Partner with organizational leaders to incorporate information security best-practices into technical and operational development. • Provide recommendations on how to improve the information security posture of programs and reduce risk. • Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact. • Draft security requirements to be included into charters, scope documents, procurements. • Document and communicate analysis. Answer clarifying questions. • Escalate to ISS leadership if an acceptable level of risk cannot be achieved 2. Act as a liaison between the program area and the Information Security Section • Be a solutions-focused advocate. • Intake projects and other program initiatives and champion them through the appropriate ISS workstream • Gather information as needed so that security team can perform thorough analysis • Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, follow-up on any clarifications. • Coordinate across ISS meeting their security-focused needs • Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome Department of Health Services (DHS) Contractor Job Description – DHS Liaison Jennifer Mueller Information Security Section DHS CISO Updated 07-21-2026 Office: 608-267-7231 Email: jennifer.mueller@dhs.wisonsin.gov Page 2 of 2 3. Support audit, assessment, incident response, and other regulatory activities • Responsibility and authority will vary based on the use case and customer need. • Request and/or gather artifacts demonstrating compliance. • Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders. • In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone. • Provide oversight to the resolution, test for compliance, and request authority to close. • Respond to regulatory inquiry and draft documents as needed 4. Participate and support Program Integration related activities • Back-up other security liaison roles • Draft and deliver status reports • Establish and maintain positive working relationships with stakeholders • Establish and documents standard operations for job-related activities. 5. Support Vulnerability Management related to DMS and its vendors • Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors • Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management • Draft and monitor plans of action and milestones for non-compliance 6. Support DHS’s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE) • In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS’s transition from MARS-E to ARC-AMPE • Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current • Draft and monitor plans of action and milestones for non-compliance 7. Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews 8. Other duties as assigned • Back-up other security staff • Write concept papers, proposals and briefs, and other documentation Knowledge, Skills, and Abilities • Well qualified candidate will have broad knowledge of information security and experience application development, technical architecture, contracting, audit, or vendor management. • Be familiar with NIST or another recognized framework • Demonstrated ability to solve complex problems, convey both oral and written instruction, and handle multiple task interruptions while providing services in a professional and courteous manner. • Demonstrated attention to detail and organizational skills. • Demonstrated ability to work effectively with customers to solve business challenges while balancing the need for confidentiality, integrity, and availability. • Demonstrated commitment to fostering a diverse working environment. • Demonstrated ability to work independently, as part of a team of peers, and also to support and contribute to a multidiscipline team environment Requirements Position Summary The Department of Health Services (DHS) is one of the largest and most diverse state agencies in Wisconsin. DHS employs more than 7,000 staff spanning ten divisions and offices and seven 24/7 institutions located throughout Wisconsin. Programs and services administered by DHS include Medicaid and other human service programs, alcohol and other drug abuse prevention services, mental health, public health, and long-term care. The Information Security Section (ISS) serves the Department by creating an information security culture and enabling the business. We are metrics minded, employee focused, and view security as a service. ISS is responsible for • Identifying and continuously assessing risk • Developing, institutionalizing, and improving strategies to mitigate risk • Limiting the potential effects of information security events • The selection, assessment, authorization, and monitoring of security controls while contributing to the overall information security plan. The Information Security Section (ISS) is functionally organized into Security Awareness and Governance, Compliance, Architecture, and Portfolio Management. Cross-team collaboration is essential to our success. The DHS Liaison serves the Division of Medicaid Services and is the champion for security initiatives integrating information security into program operations. This work is completed by engaging other security staff, communicating risk, and developing strategies to reduce risk. To successfully do this work, one must possess strong communication and interpersonal skills capable of presenting to diverse audiences including executive and non-technical individuals. A federally recognized (ANSI) information security certification must be obtained within 6 months of the start date and maintained for this position. The Department of Defense (DOD) 8570 Baseline Certifications defined by Defense Information Systems Agency (DISA) is the baseline to consider when reviewing the relevance of the certification. Goals and Worker Activities 1. Integrate security into program operations • Partner with organizational leaders to incorporate information security best-practices into technical and operational development. • Provide recommendations on how to improve the information security posture of programs and reduce risk. • Communicate risks in simple and comprehensible terms. Provide options to mitigate risk considering business impact. • Draft security requirements to be included into charters, scope documents, procurements. • Document and communicate analysis. Answer clarifying questions. • Escalate to ISS leadership if an acceptable level of risk cannot be achieved 2. Act as a liaison between the program area and the Information Security Section • Be a solutions-focused advocate. • Intake projects and other program initiatives and champion them through the appropriate ISS workstream • Gather information as needed so that security team can perform thorough analysis • Communicate workstream deliverables to the customer. Verify that the deliverable meets the customer need, follow-up on any clarifications. • Coordinate across ISS meeting their security-focused needs • Coordinate with other BITS staff, Office of Legal Counsel, Bureau of Procurement and Contracting, and other program staff as needed in order to arrive to an outcome 3. Support audit, assessment, incident response, and other regulatory activities • Responsibility and authority will vary based on the use case and customer need. • Request and/or gather artifacts demonstrating compliance. • Schedule/facilitate communications between auditor/incident response, vendors, technical teams, and other program stakeholders. • In partnership with ISS, assess audit results and develop corrective action plans/plans of action and milestone. • Provide oversight to the resolution, test for compliance, and request authority to close. • Respond to regulatory inquiry and draft documents as needed 4. Participate and support Program Integration related activities • Back-up other security liaison roles • Draft and deliver status reports • Establish and maintain positive working relationships with stakeholders • Establish and documents standard operations for job-related activities. 5. Support Vulnerability Management related to DMS and its vendors • Foster transparency, accountability, and timely resolution of vulnerabilities with DMS and its vendors • Support DMS and its vendors in adhering to state and federal regulations and Policies, Procedures, Standards and Guidelines (PPSGs) related to vulnerability management • Draft and monitor plans of action and milestones for non-compliance 6. Support DHS’s transition from the Center for Medicare and Medicaid Services (CMS) compliance requirements known as the Minimum Acceptable Risk Standards for Exchanges (MARS-E) to the new requirements known as Acceptable Risk Controls for ACA, Medicaid, and Partner Entities (ARC-AMPE) • In partnership with Deloitte, DET, and ISS conduct GAP analysis to support transition, implementation, and maturation of DHS’s • Draft the ARC-AMPE System Security and Privacy Plan (SSPP) and keep it current • Draft and monitor plans of action and milestones for non-compliance 7. Support DHS in completing software reviews, cloud brokerage reviews, and AI Use Case reviews 8. Other duties as assigned •Back-up other security staff •Write concept papers, proposals and briefs, and other documentation