2

Remote Vendor Risk Management Jobs in Virginia (NOW HIRING)

Loan Review Managing Consultant

Mclean, VA ยท On-site +1

$113K - $188K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

S. Small Business Administration (SBA) Office of Credit Risk Management (OCRM) by performing ... Reviewers may support onsite or remote reviews, participate in quality assurance activities, and ...

Management Volume SME & Strategist

Reston, VA ยท On-site +1

$200K - $240K/yr

Secret Potential for Remote Work: ORA_HYBRID Description SAIC is seeking a visionary Management ... Engineer risk management frameworks with quantitative analysis, predictive modeling, and automated ...

Technical Project Manager

Reston, VA ยท On-site +1

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Hybrid or Remote Terms:Full Time Clearance:U.S. Citizenship Preferred; Ability to Obtain Public ... risk management, and release management concepts. * Ability to communicate technical issues, risks ...

Program Manager

Herndon, VA ยท On-site +1

Drive performance through clear communication, disciplined execution, and proactive risk management ... Remote candidates will not be considered due to clearance and customer interaction requirements.

Single Family Policy Lead

Reston, VA ยท On-site +1

$18.75 - $23.75/hr

  • Medical

  • Life

Develop and maintain policies that effectively balance risk management with business innovation ... vendors, and building relationship networks * Presentation skills, including leading policy ...

Showing results 41-60

Remote Vendor Risk Management information

What is the difference between Remote Vendor Risk Management vs Remote Vendor Compliance Specialist?

AspectRemote Vendor Risk ManagementRemote Vendor Compliance Specialist
Primary FocusAssessing and mitigating risks associated with vendorsEnsuring vendors comply with policies and regulations
Key ResponsibilitiesRisk assessments, vendor evaluations, mitigation strategiesPolicy enforcement, compliance audits, documentation
Required CredentialsCertifications like CTPRP, vendor management experienceCompliance certifications like CCEP, audit experience
Work EnvironmentRemote, cross-functional teams, vendor interactionsRemote, regulatory and policy-focused tasks

While both roles involve working with vendors remotely, Remote Vendor Risk Management primarily focuses on identifying and reducing vendor-related risks, whereas Remote Vendor Compliance Specialists concentrate on ensuring vendors adhere to policies and regulations. Both roles require similar certifications and often collaborate to maintain vendor integrity and security.

What are some common challenges faced in a remote vendor risk management role, and how can they be addressed?

In a remote vendor risk management role, one common challenge is maintaining clear and consistent communication with both internal teams and external vendors, especially when operating across different time zones. Additionally, ensuring thorough due diligence and risk assessments without in-person site visits can be difficult. These challenges can be addressed by leveraging secure collaboration platforms, setting well-defined processes for virtual assessments, and building strong relationships through regular check-ins and transparent reporting. Proactive organization and adaptability are key to managing risks effectively in a remote environment.

What are the key skills and qualifications needed to thrive in remote vendor risk management?

To excel in Remote Vendor Risk Management, you need expertise in risk assessment, third-party due diligence, and compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management platforms (like Archer or LogicManager), knowledge of regulatory frameworks (such as GDPR or SOC 2), and relevant certifications (e.g., CRVPM, CTPRP) are typically required. Strong analytical thinking, effective communication, and the ability to collaborate virtually are valuable soft skills for this role. These abilities ensure organizations can identify, assess, and mitigate vendor-related risks while maintaining regulatory compliance in a remote work environment.

What are the most commonly searched types of Vendor Risk Management jobs in Virginia?

The most popular types of Vendor Risk Management jobs in Virginia are:

What are popular job titles related to Remote Vendor Risk Management jobs in Virginia?

For Remote Vendor Risk Management jobs in Virginia, the most frequently searched job titles are:

What cities in Virginia are hiring for Remote Vendor Risk Management jobs?

Cities in Virginia with the most Remote Vendor Risk Management job openings:

Task Order Project Manager (59904)

Beshenich & Muir Associates

Fort Myer, VA โ€ข On-site, Remote

Full-time

Medical, Dental, Vision, Retirement

Re-posted 7 days ago


Job description

BMA is seeking a Task Order Project Manager to support the DLA Cybersecurity Web/App Vulnerability Management Support Services program. This is a fully remote position and contingent on contract award.
Job Summary
BMA is seeking a Task Order Project Manager (TOPM) to support our DLA Cybersecurity Web/App Vulnerability Management Support Services contract. The TOPM provides overall leadership, planning, and management oversight for the Cybersecurity Web/Application Vulnerability Management Support Services task order supporting DLA's J6 Information Operations Directorate. The TOPM is responsible for ensuring the successful execution of all contract requirements associated with improving the cybersecurity (CS) posture of DLA web applications, information systems, cloud environments, and operational technology (OT) platforms. Serving as the primary Government interface, the TOPM coordinates directly with the Contracting Officer (KO), Contracting Officer's Representative (COR), Program Managers, Information System Security Managers (ISSMs), Authorizing Officials (AOs), and other DLA stakeholders to ensure all technical, schedule, and performance objectives are achieved. The TOPM directs a multidisciplinary team of cybersecurity professionals including Information System Security Engineers and CS analysts who conduct vulnerability assessments, security engineering analysis, risk assessments, and CS compliance evaluations across the DLA enterprise in accordance with DoDI 8510.01 Risk Management Framework (RMF) for DoD IT, NIST SP 800-53, and applicable DoD and DLA cybersecurity policies.
Key Responsibilities include:
  • Leadership and Management.
  • Provide overall leadership and management of a large, complex cybersecurity task order supporting enterprise vulnerability management operations.
  • Serve as the primary liaison to Government leadership, including the KO, COR, and DLA J6 program management staff.
  • Assist the Program Manager (PM) in coordinating contract activities with government stakeholders, including cybersecurity leadership, program offices, and system owners.
  • Ensure contract deliverables, schedules, and technical requirements are executed in accordance with performance objectives.
  • Program Planning and Execution.
  • Develop and maintain the Task Order Management Plan outlining the technical approach, organizational resources, and management controls required to execute the Performance Work Statement (PWS).
  • Provide planning, direction, coordination, and control necessary to accomplish all contract tasks.
  • Manage the execution of project phases.
  • Verify and validate level of effort and deliverables across all assigned tasks.
  • Cybersecurity Program Oversight.
  • Oversee activities supporting the Cybersecurity Web/Application Vulnerability Management branch responsible for identifying, analyzing, and mitigating vulnerabilities across DLA IT, Cloud, and OT environments.
  • Ensure teams perform cybersecurity engineering assessments, security test and evaluation activities, and risk analysis in accordance with federal and DoD cybersecurity policies.
  • Ensure compliance with applicable cybersecurity standards and frameworks including RMF, NIST security controls, and DLA cybersecurity guidance.
  • Provide oversight of vulnerability assessment activities and cybersecurity engineering recommendations supporting enterprise risk reduction.
  • Performance Monitoring and Reporting.
  • Oversee preparation and submission of required contract reports.
  • Monitor project performance, identify risks, and implement corrective actions when necessary.
  • Conduct Integrated Project Reviews (IPRs) with stakeholders to review project status, technical progress, and operational challenges.
  • Workforce and Resource Management.
  • Lead and supervise a multidisciplinary cybersecurity workforce supporting vulnerability assessment and cybersecurity engineering activities.
  • Maintain appropriate staffing levels and skillsets required to meet contract requirements.
  • Coordinate recruitment, onboarding, and training of personnel as necessary to sustain contract performance.
  • Ensure personnel maintain required cybersecurity certifications and security clearances.
  • Quality Control and Continuous Improvement.
  • Implement program management controls to ensure the quality and timeliness of all deliverables.
  • Establish quality control processes to monitor technical performance and compliance with contract requirements.

Clearance Requirements
There is a Secret Security clearance requirement for this position.
Required Skills & Certifications
  • Project Management certification required, such as Project Management Professional (PMP) or equivalent recognized project management certification.
  • DoD Approved Baseline Certification (DoD 8570/8140) Information Assurance Management (IAM) Level III such as ISACA Certified Information Security Manager (CISM), ISC2 Certified Information Systems Security Professional (CISSP), EC-Council Certified Chief Information Security Officer (C-CISO), or GIAC or SANS GIAC Security Leadership Certification (GSLC).
  • 10+ years of relevant professional experience in information technology, cybersecurity, or consulting environments.
  • 5+ years of leadership experience managing complex programs or projects within the public or private sector.
  • Demonstrated experience managing large, complex government task orders or programs involving enterprise IT or cybersecurity services, including supervising 10 or more employees.
  • Experience with STIG compliance cycles, vulnerability management, and POA&M governance.
  • Strong technical writing skills producing RMF artifacts, policy and procedure documents, and audit-ready evidence packages.
  • Strong facilitation skills for Integrated Product Teams (IPTs), Working Group (WG) sessions, and cross-functional coordination.

Desired Skills & Certifications
  • TS with SCI eligibility.
  • Experience supporting DoD or DLA program offices.
  • Experience supporting DoD or DLA environments.
  • BS or BA in Information Technology, Cybersecurity, Computer Science, Engineering, Business Administration, or a related field.
  • One or more of the following DoD-Approved CSSP Analyst Certifications: EC-Council Certified Ethical Hacker, EC-Council CSA Certified SOC Analyst, CompTIA Cybersecurity Analyst (CySA+), GIAC or SANS GCIA GIAC Certified Intrusion Analyst, or GIAC or SANS GCIH GIAC Certified Incident Handler.
  • Current Risk Management Professional certification such as one or more of the following: PMP-RMP, ISACA Certified in Risk and Information Systems Control (CRISC), ISACA Certified Information Systems Auditor (CISA), ISACA Certified Information Security Manager (CISM), ISC2 Certified in Governance, Risk and Compliance (CGRC), or Risk and Insurance Management Society Certified Risk Management Professional (RIMS-CRMP).

Other Duties
  • Able to travel within a week's notice.
  • This job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job.
  • Duties, responsibilities, and activities may change at any time with or without notice.

Overview
BMA is an employee-owned small business headquartered in Huntsville, AL that provides superior customer service by empowering all levels of our staff to make timely decisions to produce high-quality results. BMA fosters an environment of passion, precision, and dedication in order to fulfill our commitments to our partners, government, and country.
Benefits
We believe that our employees well-being is paramount to our success so our benefits package has been crafted with that in mind. We offer multiple healthcare coverage options to include low deductible, high deductible, and plans eligible for our Health Savings Account (HSA) option. Along with medical coverage, employees have dental, vision, accident & illness, short- and long-term disability all available to them. BMA proudly maintains a 401(k) plan with an industry leading 6% match that can include profit sharing based on company performance. Lastly, being an employee-owned company means that BMA offers a 100% Employee Stock Ownership Plan (ESOP), providing eligible employees the opportunity to earn stock in BMA, subject to plan eligibility and vesting requirements.
AAP & EEO Statement
Beshenich Muir & Associates, LLC (BMA) is an Equal opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regards to race, color, religion, religious creed, gender, sexual orientation, gender identity, gender expression, transgender, pregnancy, marital status, national origin, ancestry, citizenship status, age, disability, protected Veteran Status, genetics or any other characteristics protected by applicable Federal, State, or Local Law.