2

Remote Vendor Risk Management Jobs in California

With intelligent agreement management, Docusign unleashes business-critical data that is trapped ... Employee is not required to be in or near an office frequently and works from a designated remote ...

next page

Showing results 1-20

Remote Vendor Risk Management information

Do risk managers make a lot of money?

Risk managers, including those in vendor risk management, typically earn competitive salaries that vary by industry, experience, and location. According to industry reports, median annual salaries range from $70,000 to over $120,000, with senior roles and certifications like Certified Risk Manager (CRM) often commanding higher pay. The role requires strong analytical skills and knowledge of compliance and security frameworks.

What is the difference between Remote Vendor Risk Management vs Remote Vendor Compliance Specialist?

AspectRemote Vendor Risk ManagementRemote Vendor Compliance Specialist
Primary FocusAssessing and mitigating risks associated with vendorsEnsuring vendors comply with policies and regulations
Key ResponsibilitiesRisk assessments, vendor evaluations, mitigation strategiesPolicy enforcement, compliance audits, documentation
Required CredentialsCertifications like CTPRP, vendor management experienceCompliance certifications like CCEP, audit experience
Work EnvironmentRemote, cross-functional teams, vendor interactionsRemote, regulatory and policy-focused tasks

While both roles involve working with vendors remotely, Remote Vendor Risk Management primarily focuses on identifying and reducing vendor-related risks, whereas Remote Vendor Compliance Specialists concentrate on ensuring vendors adhere to policies and regulations. Both roles require similar certifications and often collaborate to maintain vendor integrity and security.

What are some common challenges faced in a remote vendor risk management role, and how can they be addressed?

In a remote vendor risk management role, one common challenge is maintaining clear and consistent communication with both internal teams and external vendors, especially when operating across different time zones. Additionally, ensuring thorough due diligence and risk assessments without in-person site visits can be difficult. These challenges can be addressed by leveraging secure collaboration platforms, setting well-defined processes for virtual assessments, and building strong relationships through regular check-ins and transparent reporting. Proactive organization and adaptability are key to managing risks effectively in a remote environment.

What are the key skills and qualifications needed to thrive in Remote Vendor Risk Management, and why are they important?

To excel in Remote Vendor Risk Management, you need expertise in risk assessment, third-party due diligence, and compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management platforms (like Archer or LogicManager), knowledge of regulatory frameworks (such as GDPR or SOC 2), and relevant certifications (e.g., CRVPM, CTPRP) are typically required. Strong analytical thinking, effective communication, and the ability to collaborate virtually are valuable soft skills for this role. These abilities ensure organizations can identify, assess, and mitigate vendor-related risks while maintaining regulatory compliance in a remote work environment.
What are the most commonly searched types of Vendor Risk Management jobs in California? The most popular types of Vendor Risk Management jobs in California are:
What are popular job titles related to Remote Vendor Risk Management jobs in California? For Remote Vendor Risk Management jobs in California, the most frequently searched job titles are:
What job categories do people searching Remote Vendor Risk Management jobs in California look for? The top searched job categories for Remote Vendor Risk Management jobs in California are:
What cities in California are hiring for Remote Vendor Risk Management jobs? Cities in California with the most Remote Vendor Risk Management job openings:
Security Analyst/Third-Party Risk Management (TPRM) - remote PST

Security Analyst/Third-Party Risk Management (TPRM) - remote PST

Irvine Technology Corporation (ITC)

Long Beach, CA โ€ข Remote

$60 - $70/hr

Other

Posted 28 days ago


Job description

Third-Party Risk Management (TPRM) Security Analyst

Our client is seeking a sharp and driven TPRM Security Analyst to join their Information Security GRC team in a remote capacity. This is a high-impact contract role where you will play a critical part in protecting the organization by assessing vendor cybersecurity posture, managing compliance with key regulatory frameworks, and driving continuous improvement of the vendor risk program. If you thrive in a fast-paced environment, enjoy cross-functional collaboration, and bring deep expertise in third-party risk lifecycle management, this is an opportunity to make a meaningful difference.

As part of our process after applying, you may receive an invitation from our AI Recruiter Avery for a short conversation that lets you share more about your background beyond your resume. For questions, contact .

Job Type: 6-month contract-to-hire

Location: Remote - PST Hours Required

Compensation: This job is expected to pay about $60-70/hr

No Visa Sponsorship Available for this role

What You'll Do:


  • Conduct end-to-end vendor information security assessments, reviewing questionnaires (SIG, CAIQ, custom IRQs), evaluating evidence, assigning risk levels, and tracking remediations to closure.
  • Administer and automate TPRM workflows within ServiceNow GRC, including vendor onboarding, risk scoring, dashboards, and executive reporting for the Vendor Risk Committee.
  • Perform ongoing vendor monitoring, manage vendor records in the contract lifecycle system, and analyze emerging cyber threats to strengthen supplier risk management.
  • Maintain the TPRM risk register and support preparation of materials for internal and external audits, including SOC 2, HITRUST, HIPAA, and PCI.
  • Collaborate cross-functionally with Legal, Procurement, Compliance, and Business Units to embed security requirements into RFPs, contracts, and vendor onboarding processes.

What Gets You the Job:


  • 5+ years in Information Security with 5+ years dedicated to TPRM or InfoSec GRC, including hands-on end-to-end vendor risk lifecycle management.
  • Demonstrated experience administering and automating TPRM workflows in ServiceNow GRC, including risk scoring and vendor onboarding.
  • Working knowledge of NIST CSF, HITRUST CSF, SOC 2, ISO 27001, and HIPAA Security Rule, with an understanding of PHI/ePHI handling and BAA obligations.
  • Experience with vendor security questionnaires (SIG, CAIQ) and evidence-based vendor audits, including CVSS/CCSS vulnerability scoring.
  • Strong communication and stakeholder management skills with the ability to present risk findings to leadership and collaborate across legal, procurement, and clinical teams.

Irvine Technology Corporation (ITC) connects top talent with exceptional opportunities in IT, Security, Engineering, and Design. From startups to Fortune 500s, we partner with leading companies nationwide. Our AI recruiter, Avery helps streamline the first step of your journey-so we can focus on what matters most: helping you grow. Join us. Let us ELEVATE your career!


Irvine Technology logo

About Irvine Technology

Sourced by ZipRecruiter

Since 2000, our Women owned company has been delivering what organizations truly need diverse, talented professionals who will take their business to new heights. ITC serves our clients and elevates our candidates through a distinct and unified team together we achieve unrivaled goals and live life to the fullest. With a proven record of creating a strong pipeline of talented candidates, Our team uplifts confident and capable Technology Specialists from one of a kind backgrounds for contract and full time opportunities across the nation.

Industry

Recruiting and staffing services

Company size

51 - 200 Employees

Headquarters location

Irvine, CA, US

Year founded

2000

Social media