2

Remote Vendor Risk Analyst Jobs in Rhode Island (NOW HIRING)

Business Analyst II

Carolina, RI · On-site +1

$67K - $103K/yr

... remote role that may only be hired in North Carolina or Washington. The Business Analyst II - This role will with reside within the Business Unit (BU) working closely with First Line Business Risk ...

Business Analyst II

Carolina, RI · On-site +1

$67K - $103K/yr

... remote role that may only be hired in North Carolina or Washington. The Business Analyst II - This role will with reside within the Business Unit (BU) working closely with First Line Business Risk ...

It's why we offer flexible work arrangements that include remote and hybrid opportunities and paid ... Analyze audit results to and be able to interpret those to leadership to inform coding policies.

Commitment Desk Analyst

Carolina, RI · On-site +1

$20.50 - $28.25/hr

Overview This is a remote role that may only be hired in the following locations: North Carolina ... Analyzes pricing options and daily pipeline reports in order to reduce risk. Identifies and ...

Commitment Desk Analyst

Carolina, RI · On-site +1

$20.50 - $28.25/hr

Overview This is a remote role that may only be hired in the following locations: North Carolina ... Analyzes pricing options and daily pipeline reports in order to reduce risk. Identifies and ...

Commitment Desk Analyst

Carolina, RI · On-site +1

$20.50 - $28.25/hr

Overview This is a remote role that may only be hired in the following locations: North Carolina ... Analyzes pricing options and daily pipeline reports in order to reduce risk. Identifies and ...

Commitment Desk Analyst

Carolina, RI · On-site +1

$20.50 - $28.25/hr

Overview This is a remote role that may only be hired in the following locations: North Carolina ... Analyzes pricing options and daily pipeline reports in order to reduce risk. Identifies and ...

It's why we offer flexible work arrangements that include remote and hybrid opportunities and paid ... Manage vendor relationships to ensure programs are administered efficiently, compliantly, and in ...

next page

Showing results 1-20

Remote Vendor Risk Analyst information

Can a risk analyst work remotely?

A remote Vendor Risk Analyst can work from home or any location with internet access, depending on the employer’s policies. Many organizations in this role utilize digital tools and require strong communication skills, making remote work feasible and common in the field.

What is a vendor risk analyst?

A vendor risk analyst is a professional responsible for assessing and managing risks associated with third-party vendors and suppliers. They evaluate vendor security, compliance, and performance, often using risk management tools and frameworks to ensure organizational safety and regulatory adherence.

Is risk analyst a good career?

A risk analyst role involves identifying and assessing potential threats to an organization, often requiring strong analytical skills and knowledge of industry regulations. It is considered a stable career with opportunities for advancement, especially in finance, insurance, and cybersecurity sectors. The role may require certifications such as FRM or CRM and proficiency with data analysis tools.

Is risk analyst an entry level job?

A risk analyst role can be entry level or require several years of experience, depending on the organization. Entry-level risk analyst positions typically require a bachelor's degree in finance, business, or a related field, and may involve basic data analysis skills and familiarity with risk management tools. Advanced roles may require certifications like FRM or CRM and more extensive experience.
What are the most commonly searched types of Vendor Risk Analyst jobs in Rhode Island? The most popular types of Vendor Risk Analyst jobs in Rhode Island are:
What are popular job titles related to Remote Vendor Risk Analyst jobs in Rhode Island? For Remote Vendor Risk Analyst jobs in Rhode Island, the most frequently searched job titles are:
What job categories do people searching Remote Vendor Risk Analyst jobs in Rhode Island look for? The top searched job categories for Remote Vendor Risk Analyst jobs in Rhode Island are:
What cities in Rhode Island are hiring for Remote Vendor Risk Analyst jobs? Cities in Rhode Island with the most Remote Vendor Risk Analyst job openings:
(On-site) Information Security Vendor Management Analyst

(On-site) Information Security Vendor Management Analyst

Centreville Bank

West Warwick, RI • On-site, Remote

Full-time

Posted 9 days ago


Key responsibilities

  • Evaluate risks of new and existing vendors and conduct due diligence and ongoing monitoring activities.

  • Review contracts and amendments for information security and risk-related provisions and collaborate with Legal and Procurement to ensure alignment with bank policy.

  • Prepare reporting for management and committees, support audits and regulatory exams, and assist with development of TPRM policies and procedures.


Job description

The Vendor Management Analyst is responsible for supporting the Bank's Third-Party Risk Management (TPRM) Program within the Information Security department. This role evaluates the risk of new and existing third-party relationships, conducts and documents due diligence, supports contract reviews, and manages ongoing monitoring activities to ensure compliance with regulatory guidance (e.g., FFIEC, GLBA, FDIC). The Analyst will work closely with business owners, Risk, Compliance, Project Management, Finance, and senior leadership to ensure vendors meet the Bank's security, operational, and financial requirements.
Third-Party Risk Assessments
  • Evaluate risks presented by new and existing vendors across cybersecurity, operational, financial, compliance, business continuity, privacy, and reputational domains.
  • Determine required risk tiering and corresponding due diligence requirements.
  • Partner with business units to ensure clear articulation of vendor use cases and criticality.Due Diligence and Ongoing Vendor Monitoring
  • Gather required due diligence artifacts such as SOC 2 reports, independent audits, penetration test summaries, cybersecurity questionnaires, financial statements, insurance certificates, business continuity plans, and regulatory compliance attestations.
  • Review and assess due diligence documents for adequacy, control effectiveness, gaps, and red flags.
  • Document findings, residual risks, and recommendations within the Bank's vendor management system.
  • Request and follow up on remediation or compensating controls for identified deficiencies.
  • Maintain documentation memorializing new vendor diligence and ongoing monitoring results.

Contract Review Support
  • Review contracts and amendments for required information security and risk-related provisions, including data security requirements, confidentiality, incident reporting, business continuity, right to audit, subcontractor oversight, and termination rights.
  • Collaborate with Legal and Procurement to ensure contract terms align with bank policy.

Issue Tracking & Remediation Oversight
  • Maintain the Bank's Vendor Watchlist to track issues with vendors, vendor remediation efforts, and follow up on open issues.
  • Document evidence of corrective actions and ensure timely resolution of audit or exam findings.

Program Governance & Reporting
  • Prepare reporting for management, committees, and the Board.
  • Support internal/external audits and regulatory exams.
  • Assist with development and enhancement of TPRM policies and procedures.
  • Train business units and stakeholders on the vendor management process and program.

Requirements
  • Bachelor's degree in Information Security, Business, Risk Management, or related field.
  • 2-5 years of experience in vendor management, third-party risk, cybersecurity risk, or related banking role.
  • Prior experience in banking or financial services.
  • Ability to interpret SOC reports and cybersecurity controls.
  • Strong analytical and documentation skills.

Preferred Qualifications
  • Understanding of FFIEC, GLBA, and industry best practices.
  • Familiarity with NIST CSF, ISO 27001, SIG/AUP questionnaires.
  • Experience reviewing contracts from a security or risk perspective.
  • Exceptional candidates will have relevant certifications such as CTPRP, CRVPM, or CRISC