2

Remote Vendor Risk Management Jobs in Virginia (NOW HIRING)

Sr. Analyst - SCRM

VA ยท On-site +1

$88K - $116K/yr

General information Job Posting Title Sr. Analyst - SCRM Date Thursday, May 28, 2026 City Remote ... management, third-party/vendor risk management (TPRM), federal compliance, or related risk ...

... managers, to choose smartly, buy effectively and operate efficiently. We deliver practical ... This role involves conducting on-site and remote cyber risk assessments, developing mitigation ...

POSITION TITLE Actuary, Model Risk LOCATION Richmond, VA or Remote (US Eastern or Central Time ... YOUR ROLE As an Actuary and member of the Model Risk Team, you will assess and manage model risk ...

Technology Risk Senior Specialist

Richmond, VA ยท On-site +1

$97K/yr

No full remote or relocation assistance available at this time. ESSENTIAL DUTIES AND ... Strong expertise in cloud risk management, with hands-on knowledge of AWS and its use within ...

Risk Solutions Specialist

Richmond, VA ยท On-site +1

$74K - $102K/yr

The Risk Solutions Specialist is a developmental technical position supporting loss control/risk ... Manages and maintains high quality deliverables including reviewing vendor reports for quality and ...

This role is remote. The Risk, Quality, and Performance Analyst serves as the Risk, Quality, and ... and risk management activities to ensure compliance with contract requirements and federal ...

next page

Showing results 1-20

Remote Vendor Risk Management information

What is the difference between Remote Vendor Risk Management vs Remote Vendor Compliance Specialist?

AspectRemote Vendor Risk ManagementRemote Vendor Compliance Specialist
Primary FocusAssessing and mitigating risks associated with vendorsEnsuring vendors comply with policies and regulations
Key ResponsibilitiesRisk assessments, vendor evaluations, mitigation strategiesPolicy enforcement, compliance audits, documentation
Required CredentialsCertifications like CTPRP, vendor management experienceCompliance certifications like CCEP, audit experience
Work EnvironmentRemote, cross-functional teams, vendor interactionsRemote, regulatory and policy-focused tasks

While both roles involve working with vendors remotely, Remote Vendor Risk Management primarily focuses on identifying and reducing vendor-related risks, whereas Remote Vendor Compliance Specialists concentrate on ensuring vendors adhere to policies and regulations. Both roles require similar certifications and often collaborate to maintain vendor integrity and security.

What are some common challenges faced in a remote vendor risk management role, and how can they be addressed?

In a remote vendor risk management role, one common challenge is maintaining clear and consistent communication with both internal teams and external vendors, especially when operating across different time zones. Additionally, ensuring thorough due diligence and risk assessments without in-person site visits can be difficult. These challenges can be addressed by leveraging secure collaboration platforms, setting well-defined processes for virtual assessments, and building strong relationships through regular check-ins and transparent reporting. Proactive organization and adaptability are key to managing risks effectively in a remote environment.

What are the key skills and qualifications needed to thrive in Remote Vendor Risk Management, and why are they important?

To excel in Remote Vendor Risk Management, you need expertise in risk assessment, third-party due diligence, and compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management platforms (like Archer or LogicManager), knowledge of regulatory frameworks (such as GDPR or SOC 2), and relevant certifications (e.g., CRVPM, CTPRP) are typically required. Strong analytical thinking, effective communication, and the ability to collaborate virtually are valuable soft skills for this role. These abilities ensure organizations can identify, assess, and mitigate vendor-related risks while maintaining regulatory compliance in a remote work environment.
What are the most commonly searched types of Vendor Risk Management jobs in Virginia? The most popular types of Vendor Risk Management jobs in Virginia are:
What are popular job titles related to Remote Vendor Risk Management jobs in Virginia? For Remote Vendor Risk Management jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Remote Vendor Risk Management jobs in Virginia look for? The top searched job categories for Remote Vendor Risk Management jobs in Virginia are:
What cities in Virginia are hiring for Remote Vendor Risk Management jobs? Cities in Virginia with the most Remote Vendor Risk Management job openings:
Cybersecurity Supply Chain Risk Management Subject Matter Expert (Anticipated Position)

Cybersecurity Supply Chain Risk Management Subject Matter Expert (Anticipated Position)

Navanti Group

Arlington, VA โ€ข Remote

Other

Posted yesterday


Job description

Location:
Remote / virtual support, aligned to Eastern Time core hours

Clearance Required:
Active Top Secret clearance with SCI eligibility

Position Summary:
The C-SCRM Subject Matter Expert will support GSA FAS/ASD in maturing its Cybersecurity Supply Chain Risk Management program from a compliance-focused model to a proactive, risk-informed enterprise capability. The SME will assess current C-SCRM practices, improve documentation and risk assessment processes, support strategy development, recommend scoring methodologies, develop practical C-SCRM guides, and advise stakeholders on cybersecurity, supplier risk, acquisition risk, and emerging technology considerations.

Key Responsibilities:
  • Lead assessment of current C-SCRM documentation practices and recommend standardized templates, naming conventions, version control practices, and collaboration processes
  • Review current vendor risk assessment processes covering supplier ownership, foreign influence, cybersecurity posture, product or service criticality, supply chain dependencies, and prohibited source risks
  • Develop recommendations for improving consistency, repeatability, accuracy, and usefulness of C-SCRM risk assessments
  • Review existing C-SCRM questionnaires and recommend improvements to question clarity, evidence collection, applicability, scoring, and risk-informed decision support
  • Develop or support development of a standardized C-SCRM Risk Assessment Framework
  • Support development of a C-SCRM Strategy and Implementation Plan, including priorities, governance approach, maturity objectives, roadmap, milestones, dependencies, and responsible parties
  • Assist with planning, coordination, tracking, and execution of C-SCRM projects
  • Develop C-SCRM guides, standard operating procedures, frameworks, briefings, and other written deliverables as requested
  • Support integration of C-SCRM into acquisition processes and stakeholder workflows
  • Provide expert analysis related to NIST SP 800-161, cybersecurity risk management, enterprise risk management, acquisition assurance, supplier risk, and emerging cybersecurity requirements
  • Support monthly status reporting, technical meetings, deliverable reviews, and Government stakeholder engagement
  • Work with minimal direction and produce executive-ready written products
Required Qualifications:
  • Minimum 3 years of experience establishing or supporting risk management programs, including C-SCRM
  • Demonstrated experience across the PWS task areas, including C-SCRM documentation, vendor risk assessment, questionnaire/scoring methodology, strategy development, and guide development
  • High-level cybersecurity or risk management certification, such as CISSP, CISM, or CRISC
  • Active Top Secret clearance with SCI eligibility
  • Strong knowledge of NIST SP 800-161, cybersecurity supply chain risk management, federal acquisition risk, and cyber risk frameworks
  • Strong written and oral communication skills
  • Ability to work independently with senior Government stakeholders
Preferred Qualifications:
  • Experience supporting GSA, DHS, DoD, IC, or other federal cybersecurity or acquisition programs
  • Experience with Section 889, FASCSA, supplier risk, foreign ownership/control/influence concerns, prohibited source analysis, or acquisition assurance
  • Experience developing federal SOPs, implementation plans, risk frameworks, scoring rubrics, stakeholder guides, and executive briefings
  • Familiarity with AI-enabled risk management, automation, post-quantum cryptography planning, continuous monitoring, and enterprise C-SCRM maturity models