2

Remote Vendor Risk Management Jobs in Washington, DC

Sr. Analyst - SCRM

VA ยท On-site +1

$88K - $116K/yr

General information Job Posting Title Sr. Analyst - SCRM Date Thursday, May 28, 2026 City Remote ... management, third-party/vendor risk management (TPRM), federal compliance, or related risk ...

Vendor Management Specialist

Mclean, VA ยท Remote

$23.75 - $27.50/hr

This fully remote role focuses on maintaining accurate vendor records, helping reduce a backlog of ... vendor management, or a related finance support role. โ€ข Practical knowledge of vendor setup ...

... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance). * Excellent client communication, executive presence, and stakeholder management skills. * Prior ...

... managers, to choose smartly, buy effectively and operate efficiently. We deliver practical ... This role involves conducting on-site and remote cyber risk assessments, developing mitigation ...

Launched by Management Consultants, our multidisciplinary teams bring together the talents of ... No Overtime Pay Basis Remote (within USA - W/ On-Site Meetings Expected) in The CONUS - Located In ...

... vendor risk and emerging tools (including AI) * Data Security and Privacy: Advising on data use ... Strong organizational and project management skills, with the ability to manage high-volume, time ...

The Senior AI Risk Advisor, under the direction of the Manager of Risk Operations, sits at the ... Go deep on vendor AI documentation - evaluating model cards, system cards, data processing ...

next page

Showing results 1-20

Remote Vendor Risk Management information

See Washington, DC salary details

$58.3K

$126.3K

$192.5K

How much do remote vendor risk management jobs pay per year?

As of Jun 14, 2026, the average yearly pay for remote vendor risk management in Washington, DC is $126,348.00, according to ZipRecruiter salary data. Most workers in this role earn between $101,900.00 and $146,100.00 per year, depending on experience, location, and employer.

What is the difference between Remote Vendor Risk Management vs Remote Vendor Compliance Specialist?

AspectRemote Vendor Risk ManagementRemote Vendor Compliance Specialist
Primary FocusAssessing and mitigating risks associated with vendorsEnsuring vendors comply with policies and regulations
Key ResponsibilitiesRisk assessments, vendor evaluations, mitigation strategiesPolicy enforcement, compliance audits, documentation
Required CredentialsCertifications like CTPRP, vendor management experienceCompliance certifications like CCEP, audit experience
Work EnvironmentRemote, cross-functional teams, vendor interactionsRemote, regulatory and policy-focused tasks

While both roles involve working with vendors remotely, Remote Vendor Risk Management primarily focuses on identifying and reducing vendor-related risks, whereas Remote Vendor Compliance Specialists concentrate on ensuring vendors adhere to policies and regulations. Both roles require similar certifications and often collaborate to maintain vendor integrity and security.

What are some common challenges faced in a remote vendor risk management role, and how can they be addressed?

In a remote vendor risk management role, one common challenge is maintaining clear and consistent communication with both internal teams and external vendors, especially when operating across different time zones. Additionally, ensuring thorough due diligence and risk assessments without in-person site visits can be difficult. These challenges can be addressed by leveraging secure collaboration platforms, setting well-defined processes for virtual assessments, and building strong relationships through regular check-ins and transparent reporting. Proactive organization and adaptability are key to managing risks effectively in a remote environment.

What are the key skills and qualifications needed to thrive in Remote Vendor Risk Management, and why are they important?

To excel in Remote Vendor Risk Management, you need expertise in risk assessment, third-party due diligence, and compliance, often supported by a degree in business, finance, or a related field. Familiarity with risk management platforms (like Archer or LogicManager), knowledge of regulatory frameworks (such as GDPR or SOC 2), and relevant certifications (e.g., CRVPM, CTPRP) are typically required. Strong analytical thinking, effective communication, and the ability to collaborate virtually are valuable soft skills for this role. These abilities ensure organizations can identify, assess, and mitigate vendor-related risks while maintaining regulatory compliance in a remote work environment.
What are the most commonly searched types of Vendor Risk Management jobs in Washington, DC? The most popular types of Vendor Risk Management jobs in Washington, DC are:
What are popular job titles related to Remote Vendor Risk Management jobs in Washington, DC? For Remote Vendor Risk Management jobs in Washington, DC, the most frequently searched job titles are:
What job categories do people searching Remote Vendor Risk Management jobs in Washington, DC look for? The top searched job categories for Remote Vendor Risk Management jobs in Washington, DC are:
Information Security Director (ISD)

Information Security Director (ISD)

Redgrave LLP

Chantilly, VA โ€ข On-site, Remote

Full-time

Medical, Dental, Vision, Retirement

Posted 5 days ago


Job description


Information Security Director Opportunity


JOB SUMMARY

Redgrave LLP is seeking an Information Security Director to lead, mature, and scale a comprehensive, enterprise-wide information security program. This is an executive ownership role working at the intersection of legal technology, client trust, and emerging AI adoption. The ISD serves as the Firm\'s principal authority on cybersecurity, AI governance, data protection, and enterprise risk management โ€” accountable for ensuring the confidentiality, integrity, and availability of Firm and client data across all systems, platforms, and emerging technologies.

This is a remote position with regular collaboration across time zones.

ESSENTIAL FUNCTIONS

Enterprise Security Governance

  • Define and execute a Firm-wide cybersecurity strategy aligned with NIST CSF, NIST AI RMF 1.0, ISO 27001, and SOC 2 frameworks
  • Own and continuously mature the Firm\'s Information Security Management System (ISMS)
  • Lead ISO 27001 gap analysis and establish a roadmap toward certification
  • Develop, maintain, and enforce security policies, standards, procedures, and governance structures
  • Define and track key risk indicators (KRIs), metrics, and reporting frameworks

AI Governance & Emerging Technology Risk

  • Serve as the Firm\'s executive owner of AI security and governance
  • Design and implement a scalable AI governance framework, including acceptable use standards, risk-tiering criteria, and data handling controls
  • Evaluate AI tools, platforms, plugins, and agentic workflows prior to deployment
  • Monitor evolving AI risk vectors (e.g., prompt injection, data leakage, MCP connector trust boundaries)
  • Maintain and govern the Firm\'s AI System Inventory

Vendor Risk Management

  • Own the Firm\'s vendor risk management program, including intake, risk-tiering, assessment, and continuous monitoring
  • Evaluate SOC 2 reports, DPAs, security questionnaires, and subprocessor disclosures
  • Negotiate and maintain contractual security terms and data protection obligations with vendors
  • Respond to client-driven vendor due diligence requests from regulated industries

Compliance & Audit

  • Own the Firm\'s SOC 2 Type II program, including control maintenance, evidence collection, and auditor engagement
  • Ensure alignment with ABA Formal Opinion 512, client contractual requirements, and applicable regulatory standards
  • Manage cyber insurance processes, including underwriting submissions and renewal strategy

Security Operations

  • Provide executive oversight of security architecture across Microsoft 365 and Azure
  • Oversee Defender for Endpoint, Entra ID, Microsoft Purview, Conditional Access, and Secure Score
  • Own and maintain the Firm\'s incident response program, including tabletop exercises and response coordination

Leadership & Reporting

  • Serve as the Firm\'s primary cybersecurity advisor to executive leadership and the Management Committee
  • Establish regular reporting on security posture, AI risk, vendor risk exposure, and program maturity
  • Direct and mentor the Information Security Analyst and develop organizational security capability

QUALIFICATIONS

Required:

  • 10+ years of progressive experience in information security, including leadership and program ownership roles
  • CISSP (required); CISM or equivalent considered
  • Demonstrated experience leading or scaling a security program; law firm or professional services preferred
  • Strong experience with cloud security, vendor risk, and compliance frameworks
  • Experience with SOC 2 programs and enterprise security tooling in Microsoft environments

Preferred:

  • Experience with AI governance frameworks and emerging technology risk
  • Experience leading ISO 27001 certification or gap analysis
  • Familiarity with legal industry technologies and client expectations
  • Experience in high-growth or rapidly scaling environments

PHYSICAL REQUIREMENTS

  • Occasionally lifts objects up to 20 pounds
  • Must be able to sit or stand for extended periods
  • Occasional travel for project-related work may be required
  • Work is generally performed in a home office (remotely) and in a traditional business setting
Benefits

Redgrave LLP is committed to supporting our employees and ensuring their needs are met beyond the workplace. We offer a flexible portfolio of benefits and services, including medical, dental, and vision coverage, a 401(k) plan, additional benefits to help you prepare for retirement, free access to Employee Assistance Programs, and other programs designed to help you and your family stay healthy, feel secure, and enjoy a positive work/life balance.

Redgrave LLP is an Equal Opportunity Employer.