1

Internship Vendor Risk Analyst Jobs (NOW HIRING)

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Risk Analyst - Vendor Management Location: Remote - USA Contract role • Execute vendor onboarding and maintenance activities using predefined processes. • Work with internal business teams to ...

Senior GRC Risk Analyst

Carmel, IN · On-site

$105K - $130K/yr

Join MISO as a Senior GRC Risk Analyst , where you will play a key role in safeguarding the power ... Evaluate third-party vendors' cybersecurity controls, practices, and overall risk posture through ...

Risk Analyst / Risk Manager Position Type: Full-Time, Remote Working Hours: U.S. client business ... vendor risk, and operational resilience reviews • Ensure remediation efforts are documented ...

The role makes heavy use of AI and LLM tools to research vendors, analyze risk and spend, and prepare clear, well-organized reporting. It partners with Security, Legal, Procurement, IT, and ...

Mentor junior analysts and contribute to the professional development of the broader Risk and ... Experience conducting or leading vendor-risk assessments for enterprise-level technology providers.

... vendors, while collaborating with IT teams to address cybersecurity risks and improve risk ... analytical and critical thinking skills • Excellent presentation skills (MS PowerPoint) • ...

Risk Analyst Department: Legal/Risk Employment Type: Full Time Location: Houston, TX Reporting To ... Vendor and Subcontractor Evaluation : Ensure compliance with Cotton's insurance requirements for ...

next page

Showing results 1-20

Internship Vendor Risk Analyst information

See salary details

$65K

$108.3K

$145.5K

How much do internship vendor risk analyst jobs pay per year?

As of Jul 20, 2026, the average yearly pay for internship vendor risk analyst in the United States is $108,333.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,000.00 and $131,000.00 per year, depending on experience, location, and employer.

What is an Internship Vendor Risk Analyst?

An Internship Vendor Risk Analyst is an entry-level position, often designed for students or recent graduates, that focuses on assessing and managing the risks associated with third-party vendors. Interns in this role help organizations evaluate the security, compliance, and reliability of vendors by analyzing documentation, conducting risk assessments, and supporting ongoing risk monitoring activities. They work under the guidance of senior analysts to ensure vendors meet company standards and regulatory requirements, gaining hands-on experience in risk management and vendor oversight.

What are some common challenges Internship Vendor Risk Analysts face when assessing third-party vendors?

Internship Vendor Risk Analysts often encounter challenges such as limited access to comprehensive vendor data, navigating complex regulatory requirements, and balancing multiple stakeholder interests. Interns must learn to evaluate risk with incomplete information and communicate findings clearly to both internal teams and vendors. Building strong analytical and communication skills, as well as understanding the organization's risk appetite, are key to overcoming these challenges and making meaningful contributions during the internship.

What are the key skills and qualifications needed to thrive as an Internship Vendor Risk Analyst, and why are they important?

To thrive as an Internship Vendor Risk Analyst, you need a solid understanding of risk assessment, vendor management principles, and basic knowledge of compliance frameworks, often supported by coursework in finance, business, or information security. Familiarity with tools like Excel, risk management software, and platforms such as SAP Ariba or RSA Archer is typically expected. Attention to detail, analytical thinking, and effective communication are standout soft skills for gathering data and collaborating with internal stakeholders. These skills are crucial for identifying potential vendor risks, ensuring regulatory compliance, and supporting organizational decision-making.

What is the difference between Internship Vendor Risk Analyst vs Vendor Risk Analyst?

AspectInternship Vendor Risk AnalystVendor Risk Analyst
CredentialsTypically pursuing or recent graduate, some certifications optionalUsually requires professional certifications like CRISC or CTP
Work EnvironmentInternship setting, entry-level tasks, learning-focusedFull-time role, responsible for ongoing risk assessments
Industry UsageCommon in finance, consulting, and tech companies for trainingEstablished position in risk management departments across industries

The Internship Vendor Risk Analyst is an entry-level role designed for students or recent graduates gaining experience in vendor risk management. In contrast, the Vendor Risk Analyst is a full-time professional responsible for ongoing risk assessments and mitigation strategies. While both roles involve evaluating vendor risks, the internship focuses on learning and support, whereas the analyst role involves independent decision-making and expertise.

More about Internship Vendor Risk Analyst jobs
What cities are hiring for Internship Vendor Risk Analyst jobs? Cities with the most Internship Vendor Risk Analyst job openings:
What are the most commonly searched types of Vendor Risk Analyst jobs? The most popular types of Vendor Risk Analyst jobs are:
What states have the most Internship Vendor Risk Analyst jobs? States with the most job openings for Internship Vendor Risk Analyst jobs include:
What job categories do people searching Internship Vendor Risk Analyst jobs look for? The top searched job categories for Internship Vendor Risk Analyst jobs are:
Infographic showing various Internship Vendor Risk Analyst job openings in the United States as of July 2026, with employment types broken down into 1% Locum Tenens, 1% Internship, 86% Full Time, 6% Part Time, 1% Temporary, and 5% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution, with an average salary of $108,333 per year, or $52.1 per hour.

Vendor Risk Manager

DFO Referrals

Westport, CT • Hybrid

Other

Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


Job description

Vendor Risk Manager 

Dalio Family Office 

Dalio Family Office Overview:  

The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes OceanX, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO's culture is built around meaningful work and meaningful relationships and the family's commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi. 

Position Summary:  

The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across cybersecurity, AI, privacy, financial, and AML/CFT/sanctions domains into clear, actionable risk positions, performing structured threat modeling for high-exposure vendors.  

Day-to-day responsibilities would include a combination of the following: 

  • Own the VRM program end-to-end: strategy, policy, procedure, workflow, tooling, metrics, and executive reporting for CISO/CRO/board visibility.
  • Lead holistic vendor risk assessments across cybersecurity, AI risk, privacy, financial, AML/CFT/sanctions.
  • Document residual risk acceptances with named accountable executives and time-boxed review dates; coordinate with IT, Legal, Finance, and Compliance as appropriate. 
  • Evaluate and monitor vendor security controls based on data sensitivity and business criticality, leveraging industry frameworks and evidence such as SOC 2, ISO 27001, penetration testing, and security assessments. 
  • Conduct structured threat models (STRIDE, PASTA) for high risk vendors, and document findings as durable artifacts informing contracting, monitoring, and exit planning. 
  • Translate threat model outputs into concrete, testable control requirements drawing from OWASP (ASVS, API Security Top 10, LLM/Agentic Top 10), NIST (SP 800-53, SP 800-161, CSF 2.0, SP 800-207), and MITRE ATT&CK; scale requirements to vendor tier. 
  • Partner with Legal to translate identified risks into enforceable contractual requirements.
  • Apply FAIR or comparable quantitative methods for high-impact vendor decisions, expressing cyber risk in loss-exposure terms that resonate with senior leadership. 
  • Advise IT, Engineering and business teams on vendor integration architecture (SSO/SCIM, OAuth, conditional access, DLP, segmentation, BYOK, VPC peering) and maintain approved reference patterns.
  • Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth; produce program dashboards tracking throughput, cycle time, recertification compliance, and remediation aging. 

The ideal candidate will possess the following knowledge, skills, attributes, and values: 

  • Expert knowledge of third-party/vendor risk management  
  • Strong risk assessment and analytical skills  
  • Technical understanding of enterprise security architecture  
  • Excellent communication and stakeholder management skills  
  • Proven ability to lead and optimize vendor risk programs  

Illustrative Benefits:     

  • 100% company paid medical premiums  
  • 17 company paid holidays  
  • Friday summer hours  
  •  Monthly community happy hours  
  • Hybrid work environment  
  •  Free catered food services for in-office days  
  • Generous PTO offering   
  • Casual dress code  
  • 150% 401(k) match up to $7,500 and 100% match above $7,500 ($15k match limit)  
  • Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!  

Qualifications: 

  • Bachelor's degree in Information Security, Risk Management, Computer Science, Cybersecurity, or a related discipline. 
  • At least 7 years of progressive experience across vendor risk management, cybersecurity architecture, security engineering, GRC, audit, or related fields.  
  • Experience managing the full third-party/vendor risk lifecycle, including vendor onboarding, due diligence, risk assessments, continuous monitoring, recertification, remediation tracking, and vendor exit planning, with at least 2 years owning an end-to-end TPRM program.  
  • Strong technical knowledge of cybersecurity frameworks, standards, and methodologies including NIST, ISO 27001/27002, OWASP, MITRE ATT&CK, Shared Assessments, threat modeling approaches (STRIDE/PASTA), and risk management practices.  
  • Hands-on experience evaluating enterprise security controls, cloud and integration architectures, SOC 2 Type II reports, ISO certifications, penetration testing results, data protection requirements, and third-party security risks across complex technology environments.  
  • Ability to communicate complex technical and risk concepts to executive stakeholders, collaborate effectively across business functions
  • 10% travel as required based on business needs. 

Compensation: 

Compensation for the role includes a competitive salary in the range from $175,000 -$260,000 (inclusive of a merit-based bonus, dependent on years of experience, level of education obtained, as well as applicable skillset) and an excellent benefits package, including paid time off ranging from 15 to 25 days based on years of service, paid sick and safe leave, dental, vision, life and disability insurance, paid parental time off, birth mother recovery pay, sick family member pay, parental ramp back up program, gym reimbursement and generous employer match for 401k. 

Please note we are unable to provide immigration sponsorship for this position. 

At the DFO, we believe our biggest asset is our people. We are proud to be an equal opportunity employer, hiring and developing individuals from diverse backgrounds and experiences to add to our collaborative culture. The DFO treats all candidates and employees with respect and does not discriminate in our recruiting, hiring, and promoting processes and general treatment during employment, including on the basis of actual or perceived race, creed, color, religion, sex, age, sexual orientation, gender identity and/or expression, alienage or national origin, ancestry, citizenship status, marital status, veteran status, or disability.