1

Senior Third Party Risk Analyst Jobs in Kentucky

$140 - $180/hr

Third Party Risk Management Lead Professional US 2 days ago Requisition ID: 1286 Salary: $160,000 ... Support development of Business Impact Analysis (BIA) across critical functions * Partner with ...

Posted today

$104 - $166/hr

Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement -- policy, control testing, and POA&M management ...

New

$90 - $140/hr

Familiarity with global regulations including import/export, third-party risk, ESG, sanctions, and ... Proficient in analyzing global regulations and delivering compliance reports to stakeholders.

New

$180 - $260/hr

... third-party dependencies, systems, and other high-risk workflows. We work closely with ... About the Role We're seeking a Senior Manager, Financial Risk Management to help shape and scale ...

New

$152 - $272/hr

... Third-Party Risk Management as well as senior risk professionals. Trust Risk at Autodesk is an ... Strong analytical and problem-solving skills* Ability to think strategically and execute ...

New

$120 - $180/hr

Your Role As Senior Insider & Data Risk Analyst, you will own insider risk investigations and help ... Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third party apps ...

New

$110 - $150/hr

Senior Catastrophe Risk Analyst Location: Duluth, GA (Onsite/ Hybrid Schedule) Position Type: Full-time We are looking for a Senior Catastrophe Risk Analyst who will leverage expertise of catastrophe ...

Posted today

$125 - $170/hr

Senior Financial Risk Analyst As a Senior Financial Risk Analyst located in Chicago, you will be part of a team of high-performing professionals that evaluates and manages financial risk (i.e ...

New

$90 - $140/hr

... third parties. This position is an integral part of the Corporate Risk Management Department in ... Duties may include claims reporting and analysis, data analysis and collection, contract reviews ...

Posted today

$100 - $125/hr

SOC 2 audit coordination, privacy rights fulfillment, policy governance, third-party risk ... Analyst and supports their professional development. Both roles report directly to the Senior ...

New

next page

Showing results 1-20

Senior Third Party Risk Analyst information

What is a senior third party risk analyst?

A Senior Third Party Risk Analyst is a professional responsible for evaluating and monitoring the risks associated with a company’s external vendors, suppliers, and service providers. They assess potential security, financial, compliance, and operational risks that third parties may pose to the organization. This role typically involves conducting due diligence, developing risk assessment frameworks, and collaborating with internal teams to ensure regulatory compliance and protect sensitive data. Senior analysts often lead risk assessment initiatives, mentor junior analysts, and work closely with stakeholders to mitigate identified risks. Their work is crucial in safeguarding the organization from potential disruptions and reputational harm.

What are the key skills and qualifications needed to thrive as a senior third party risk analyst?

To thrive as a Senior Third Party Risk Analyst, you need expertise in risk management, vendor assessment, and regulatory compliance, often supported by a bachelor’s degree in business, finance, or a related field. Familiarity with GRC tools (such as Archer or OneTrust), risk assessment frameworks, and relevant certifications like CTPRA or CISA are typically required. Strong analytical thinking, communication skills, and stakeholder management set top performers apart in this role. These skills ensure effective identification and mitigation of third-party risks, safeguarding organizational integrity and regulatory adherence.

How does a senior third party risk analyst typically collaborate with other departments to manage vendor risks?

As a Senior Third Party Risk Analyst, you will frequently collaborate with teams such as procurement, legal, IT security, and compliance to assess and manage vendor risks. This involves coordinating risk assessments, facilitating due diligence processes, and sharing findings to inform contract negotiations and ongoing vendor management. Effective communication and cross-functional teamwork are essential, as you'll often serve as a liaison to ensure that third-party risks are properly identified, documented, and mitigated across the organization.

What is the difference between Senior Third Party Risk Analyst vs Third Party Risk Analyst?

AspectSenior Third Party Risk AnalystThird Party Risk Analyst
Required CredentialsBachelor's degree, certifications like CTPRP or CRISC, experience in risk managementBachelor's degree, certifications like CTPRP or CRISC, entry to mid-level experience
Work EnvironmentFinancial institutions, large corporations, consulting firmsFinancial services, healthcare, technology companies
Employer & Industry UsageUsed in organizations with complex third-party relationshipsCommon in industries with third-party dependencies

The Senior Third Party Risk Analyst typically has more experience and handles complex risk assessments, often leading initiatives. The Third Party Risk Analyst is usually an entry to mid-level role focused on supporting risk evaluations. Both roles require similar credentials but differ in responsibility level and scope.

What are popular job titles related to Senior Third Party Risk Analyst jobs in Kentucky?

For Senior Third Party Risk Analyst jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Senior Third Party Risk Analyst jobs in Kentucky look for?

The top searched job categories for Senior Third Party Risk Analyst jobs in Kentucky are:

What cities in Kentucky are hiring for Senior Third Party Risk Analyst jobs?

Cities in Kentucky with the most Senior Third Party Risk Analyst job openings:

Third Party Risk Management Lead

Sungrow Na

On-site

$140 - $180/hr

Other

Posted 13 hours ago

Posted today


Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Third Party Risk Management Lead

Professional US

2 days ago Requisition ID: 1286

Salary: $160,000.00 Annually

Third Party Risk Management Lead

About Sungrow:

Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America is known for its commitment to innovation, high-quality standards, and exceptional customer service, aiming to provide sustainable and reliable energy solutions to meet the growing demand for clean power.

The Position:

Sungrow Americas is seeking a Third Party Risk Management (TPRM) Lead to establish and operate a scalable program for managing vendor, supplier, and third-party risk across the organization.

This role is responsible for ensuring that third-party relationships are assessed, governed, and continuously monitored in alignment with regulatory expectations and customer requirements.

In parallel, this role will support the development of business continuity and resilience capabilities, including Business Impact Analysis (BIA) and foundational BCDR program elements.

This is a program leadership role requiring strong execution, cross-functional influence, and the ability to operate in a regulated, critical infrastructure environment

Key Responsibilities
  • Build and operate the TPRM program lifecycle, including:
    • Vendor intake and risk tiering
    • Security assessments and due diligence
    • Ongoing monitoring and reassessment
  • Define and enforce minimum security requirements for vendors and suppliers
  • Partner with legal and procurement to embed security and risk clauses into contracts
  • Establish processes for exception management and risk acceptance
  • Lead execution of third-party security reviews, including:
    • Questionnaires and evidence validation
    • Review of SOC 2, ISO certifications, and supporting artifacts
  • Identify and communicate material risks and required mitigations
  • Ensure alignment to frameworks (NIST, ISO 27001, SOC 2, NERC CIP where applicable)
  • Implement ongoing monitoring capabilities for vendor risk posture
  • Track and drive remediation of identified third-party risks
  • Maintain visibility into fourth-party and supply chain dependencies where relevant
Business Continuity & Resilience (BCDR/BIA Support)
  • Support development of Business Impact Analysis (BIA) across critical functions
  • Partner with business and IT stakeholders to define:
    • Critical processes
    • Recovery time objectives (RTO) / recovery point objectives (RPO)
  • Contribute to the development of BCDR plans and testing frameworks
  • Ensure third-party dependencies are integrated into continuity planning
Governance, Reporting & Audit Readiness
  • Develop and track TPRM KPIs and risk metrics
  • Provide executive-level reporting on third-party risk posture
  • Maintain documentation and evidence to support:
    • Audits
    • Customer security reviews
    • Regulatory inquiries
  • Ensure program is defensible and repeatable
Cross-Functional Collaboration
  • Partner with:
    • Procurement (vendor onboarding)
    • Legal (contractual protections)
    • IT and engineering (technical validation)
  • Act as the central point of coordination for third-party risk decisions
Requirements
  • 7–10+ years of experience in third-party risk management, GRC, or vendor risk programs
  • Proven experience building or leading a TPRM program in a regulated or enterprise environment
  • Strong understanding of:
    • Vendor risk assessment methodologies
    • Security frameworks (NIST, ISO 27001, SOC 2)
  • Experience reviewing:
    • Security documentation (policies, controls, audit reports)
    • Third-party attestations (SOC 2, ISO certifications)
  • Working knowledge of business continuity and resilience concepts (BIA, BCDR)
  • Ability to drive cross-functional alignment and accountability
Preferred
  • Experience in energy, industrial, or critical infrastructure sectors
  • Familiarity with NERC CIP requirements
  • Experience implementing or operating TPRM platforms/tools
  • Certifications such as CRISC, CISM, CISSP, or CTPRP
  • Program Builder: Can stand up and mature TPRM from structure to scale
  • Risk Translator: Converts vendor risk into business and contractual impact
  • Governance-Oriented: Ensures decisions are documented and defensible
  • Cross-Functional Operator: Effective with procurement, legal, IT, and engineering
  • Pragmatic Enforcer: Balances risk reduction with business enablement
Strategic Fit
  • Establishes control over external risk exposure
  • Strengthens customer trust and regulatory alignment
  • Enables defensible procurement and vendor onboarding decisions
  • Builds foundation for enterprise resilience and continuity planning
Travel

Up to 10%

Work Location and Status:
  • Remote

Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only contact candidates who best meet the requirements. Thank you for your interest in Sungrow.

#J-18808-Ljbffr