2

Remote Vendor Risk Management Jobs in Virginia (NOW HIRING)

JIRA Project Manager

Arlington, VA · On-site +1

$113K - $134K/yr

This role is 100% remote and requires a candidate who is self-driven, detail-oriented, and a strong ... Security Incident Response (SIR), Vulnerability Response (VR), and Vendor Risk Management (VRM)

This role is 100% remote and requires a candidate who is self-driven, detail-oriented, and a strong ... Security Incident Response (SIR), Vulnerability Response (VR), and Vendor Risk Management (VRM)

Sr. Analyst - SCRM

VA · On-site +1

$88K - $116K/yr

General information Job Posting Title Sr. Analyst - SCRM Date Thursday, May 28, 2026 City Remote ... management, third-party/vendor risk management (TPRM), federal compliance, or related risk ...

... managers, to choose smartly, buy effectively and operate efficiently. We deliver practical ... This role involves conducting on-site and remote cyber risk assessments, developing mitigation ...

POSITION TITLE Actuary, Model Risk LOCATION Richmond, VA or Remote (US Eastern or Central Time ... YOUR ROLE As an Actuary and member of the Model Risk Team, you will assess and manage model risk ...

Actuary, Model Risk

Richmond, VA · On-site +1

$115K - $220K/yr

POSITION TITLE Actuary, Model Risk LOCATION Richmond, VA or Remote (US Eastern or Central Time ... YOUR ROLE As an Actuary and member of the Model Risk Team, you will assess and manage model risk ...

Risk Solutions Specialist

Richmond, VA · On-site +1

$74K - $102K/yr

The Risk Solutions Specialist is a developmental technical position supporting loss control/risk ... Manages and maintains high quality deliverables including reviewing vendor reports for quality and ...

next page

Showing results 1-20

Remote Vendor Risk Management information

Do risk managers make a lot of money?

Risk managers, including those in vendor risk management, typically earn competitive salaries that vary by industry, experience, and location. According to industry reports, median annual salaries range from $70,000 to over $120,000, with senior roles and certifications like Certified Risk Manager (CRM) often commanding higher pay. The role requires strong analytical skills and knowledge of compliance and security frameworks.

What is the difference between Remote Vendor Risk Management vs Remote Vendor Compliance Specialist?

AspectRemote Vendor Risk ManagementRemote Vendor Compliance Specialist
Primary FocusAssessing and mitigating risks associated with vendorsEnsuring vendors comply with policies and regulations
Key ResponsibilitiesRisk assessments, vendor evaluations, mitigation strategiesPolicy enforcement, compliance audits, documentation
Required CredentialsCertifications like CTPRP, vendor management experienceCompliance certifications like CCEP, audit experience
Work EnvironmentRemote, cross-functional teams, vendor interactionsRemote, regulatory and policy-focused tasks

While both roles involve working with vendors remotely, Remote Vendor Risk Management primarily focuses on identifying and reducing vendor-related risks, whereas Remote Vendor Compliance Specialists concentrate on ensuring vendors adhere to policies and regulations. Both roles require similar certifications and often collaborate to maintain vendor integrity and security.

What are some common challenges faced in a remote vendor risk management role, and how can they be addressed?

In a remote vendor risk management role, one common challenge is maintaining clear and consistent communication with both internal teams and external vendors, especially when operating across different time zones. Additionally, ensuring thorough due diligence and risk assessments without in-person site visits can be difficult. These challenges can be addressed by leveraging secure collaboration platforms, setting well-defined processes for virtual assessments, and building strong relationships through regular check-ins and transparent reporting. Proactive organization and adaptability are key to managing risks effectively in a remote environment.

What are the key skills and qualifications needed to thrive in Remote Vendor Risk Management, and why are they important?

To excel in Remote Vendor Risk Management, you need expertise in risk assessment, third-party due diligence, and compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management platforms (like Archer or LogicManager), knowledge of regulatory frameworks (such as GDPR or SOC 2), and relevant certifications (e.g., CRVPM, CTPRP) are typically required. Strong analytical thinking, effective communication, and the ability to collaborate virtually are valuable soft skills for this role. These abilities ensure organizations can identify, assess, and mitigate vendor-related risks while maintaining regulatory compliance in a remote work environment.
What are the most commonly searched types of Vendor Risk Management jobs in Virginia? The most popular types of Vendor Risk Management jobs in Virginia are:
What are popular job titles related to Remote Vendor Risk Management jobs in Virginia? For Remote Vendor Risk Management jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Remote Vendor Risk Management jobs in Virginia look for? The top searched job categories for Remote Vendor Risk Management jobs in Virginia are:
What cities in Virginia are hiring for Remote Vendor Risk Management jobs? Cities in Virginia with the most Remote Vendor Risk Management job openings:
Senior Analyst - Third Party Risk Management

Senior Analyst - Third Party Risk Management

Sentara Healthcare

Norfolk, VA • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 17 days ago


Sentara Health rating

6.8

Company rating: 6.8 out of 10

Based on 383 frontline employees who took The Breakroom Quiz

484th of 870 rated healthcare providers


Job description

City/State
Norfolk, VA
Work Shift
First (Days)
Overview:
Third Party Risk Management (TPRM) Senior Analyst is responsible for ensuring the organization effectively manages risks associated with third-party vendors and partners throughout the entire third-party lifecycle, including vendor selection, contract negotiation, ongoing monitoring, and termination. This involves not only identifying and evaluating risks but also collaborating with various teams, particularly Legal and Procurement, to embed risk mitigation strategies into contractual agreements.
Key responsibilities
  • Vendor Risk Assessment (VRA):
    • Conduct thorough risk assessments for potential and existing vendors, focusing on various risk types, including cybersecurity, operational, financial, and compliance risks.
    • Utilize and potentially create vendor risk assessment questionnaires to gather detailed information about vendor practices, including data security policies, internal controls, compliance posture, and business continuity plans.
    • Analyze questionnaire responses and other relevant information to identify deficiencies, areas for remediation, and categorize vendors based on risk levels.
    • Engage with stakeholders to communicate assessment results, address security concerns, and collaborate on potential remediation actions.
    • Perform periodic reviews and reassessments of existing vendors to ensure ongoing compliance and address evolving risks.
  • Contract Negotiation:
    • Partner with Legal and Procurement teams during contract negotiations to ensure security, privacy, and other relevant risk clauses are adequately addressed.
    • Provide expert guidance on acceptable and unacceptable contract terms related to risk management, service level agreements (SLAs), and data protection.
    • Work to define and include clear performance standards, due diligence requirements, and exit strategies within contracts.
  • TPRM program development and maintenance:
    • Support the development, maintenance, and enhancement of the organization's Third-Party Risk Management program and framework.
    • Develop and update TPRM procedures to ensure alignment with organizational policies and regulatory requirements.
    • Identify and implement process efficiencies within the TPRM program and perform analyses on team metrics to enhance effectiveness.
  • Stakeholder collaboration and communication:
    • Build and maintain strong relationships with internal stakeholders across departments such as Legal, Procurement, Information Security, and Business Units.
    • Provide TPRM guidance and training to Vendor Relationship Owners and business partners on risk management practices.
    • Communicate identified risks, assessment results, and mitigation strategies to stakeholders, including senior management, clearly and concisely.
  • Ongoing monitoring and remediation:
    • Track identified risks associated with third parties and ensure timely reviews are performed.
    • Monitor key supplier performance against established SLAs and regulatory requirements.
    • Track and collaborate with internal partners and vendors to remediate any risk-related issues.

Education
  • Bachelor's degree in a relevant field such as Business, Finance, Information Technology, or a related discipline (Preferred)
  • Experience in lieu of Bachelor's Degree -7+ years of relevant experience without a degree

Certification/Licensure
  • CISA, CRISC, CISM, CISSP, or other relevant certifications are preferred

Experience
  • 5+ years of relevant experience with a degree
  • Strong understanding of Third-Party Risk Management (TPRM) principles, concepts, and best practices.
  • Experience in conducting vendor risk assessments and evaluating internal controls, potentially leveraging frameworks like ISO 27001/2, NIST 800-53, NIST CSF, SOC1/SOC2, CSA CCM, and Shared Assessments SIG.
  • Working knowledge of contract management principles and practices, including contract negotiation and analysis.
  • Excellent communication skills, both written and verbal, with the ability to effectively articulate security control requirements, assessment results, and risk considerations to diverse audiences.
  • Strong analytical, critical thinking, and problem-solving skills, with the ability to digest and analyze complex information with attention to detail and accuracy.
  • Ability to work collaboratively in a cross-functional environment and build strong relationships with internal and external partners.
  • Proficiency in Microsoft Office Suite (Excel, PowerPoint, Word) and potentially GRC (Governance, Risk, and Compliance) tools like OneTrust (highly desirable), Archer, or ServiceNow

Keywords: TPRM, Third party Risk assessment
Benefits: Caring For Your Family and Your Career
Medical, Dental, Vision plans
• Adoption, Fertility and Surrogacy Reimbursement up to 10,000
• Paid Time Off and Sick Leave
• Paid Parental & Family Caregiver Leave
• Emergency Backup Care
• Long-Term, Short-Term Disability, and Critical Illness plans
• Life Insurance
• 401k/403B with Employer Match
• Tuition Assistance - 5,250/year and discounted educational opportunities through Guild Education
• Student Debt Pay Down - 10,000
• Reimbursement for certifications and free access to complete CEUs and professional development
• Pet Insurance
• Legal Resources Plan
• Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.
Sentara Health is an equal opportunity employer and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.
In support of our mission "to improve health every day," this is a tobacco-free environment.
For positions that are available as remote work, Sentara Health employs associates in the following states:
Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.

What Sentara Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom