1

Senior Third Party Risk Analyst Jobs (NOW HIRING)

About the Role Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite. You'll be the first security risk analyst at OpenRouter, building the ...

Third Party Risk Analyst

Tampa, FL · Remote

$60K - $90K/yr

Remote (Candidate must reside in the state of FL) Position Type: Full Time The Third-Party Risk Analyst supports the Third-Party Risk Management (TPRM) program by executing risk assessments ...

As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...

As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships ...

Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...

Description As the Third Party Risk Sr Analyst , you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing ...

Risk Analyst

Woodbury, NY · On-site

$32 - $35/hr

Third-Party Risk Analyst II The Third-Party Risk Analyst II supports the Enterprise Risk Management team by assessing and monitoring risks associated with current and prospective third-party vendors.

The Third Party Risk Officer is responsible for the development, implementation, and ongoing ... Prepare and present program reports, risk insights, and metrics to senior management and the Board.

Showing results 21-40

Senior Third Party Risk Analyst information

See salary details

$53.5K

$109.8K

$142.5K

How much do senior third party risk analyst jobs pay per year?

As of Aug 31, 2026, the average yearly pay for senior third party risk analyst in the United States is $109,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,500.00 and $137,000.00 per year, depending on experience, location, and employer.

What is a senior third party risk analyst?

A Senior Third Party Risk Analyst is a professional responsible for evaluating and monitoring the risks associated with a company’s external vendors, suppliers, and service providers. They assess potential security, financial, compliance, and operational risks that third parties may pose to the organization. This role typically involves conducting due diligence, developing risk assessment frameworks, and collaborating with internal teams to ensure regulatory compliance and protect sensitive data. Senior analysts often lead risk assessment initiatives, mentor junior analysts, and work closely with stakeholders to mitigate identified risks. Their work is crucial in safeguarding the organization from potential disruptions and reputational harm.

What are the key skills and qualifications needed to thrive as a senior third party risk analyst?

To thrive as a Senior Third Party Risk Analyst, you need expertise in risk management, vendor assessment, and regulatory compliance, often supported by a bachelor’s degree in business, finance, or a related field. Familiarity with GRC tools (such as Archer or OneTrust), risk assessment frameworks, and relevant certifications like CTPRA or CISA are typically required. Strong analytical thinking, communication skills, and stakeholder management set top performers apart in this role. These skills ensure effective identification and mitigation of third-party risks, safeguarding organizational integrity and regulatory adherence.

How does a senior third party risk analyst typically collaborate with other departments to manage vendor risks?

As a Senior Third Party Risk Analyst, you will frequently collaborate with teams such as procurement, legal, IT security, and compliance to assess and manage vendor risks. This involves coordinating risk assessments, facilitating due diligence processes, and sharing findings to inform contract negotiations and ongoing vendor management. Effective communication and cross-functional teamwork are essential, as you'll often serve as a liaison to ensure that third-party risks are properly identified, documented, and mitigated across the organization.

What is the difference between Senior Third Party Risk Analyst vs Third Party Risk Analyst?

AspectSenior Third Party Risk AnalystThird Party Risk Analyst
Required CredentialsBachelor's degree, certifications like CTPRP or CRISC, experience in risk managementBachelor's degree, certifications like CTPRP or CRISC, entry to mid-level experience
Work EnvironmentFinancial institutions, large corporations, consulting firmsFinancial services, healthcare, technology companies
Employer & Industry UsageUsed in organizations with complex third-party relationshipsCommon in industries with third-party dependencies

The Senior Third Party Risk Analyst typically has more experience and handles complex risk assessments, often leading initiatives. The Third Party Risk Analyst is usually an entry to mid-level role focused on supporting risk evaluations. Both roles require similar credentials but differ in responsibility level and scope.

More about Senior Third Party Risk Analyst jobs

What cities are hiring for Senior Third Party Risk Analyst jobs?

Cities with the most Senior Third Party Risk Analyst job openings:

What are the most commonly searched types of Third Party Risk Analyst jobs?

The most popular types of Third Party Risk Analyst jobs are:

What states have the most Senior Third Party Risk Analyst jobs?

States with the most job openings for Senior Third Party Risk Analyst jobs include:

What job categories do people searching Senior Third Party Risk Analyst jobs look for?

The top searched job categories for Senior Third Party Risk Analyst jobs are:

Infographic showing various Senior Third Party Risk Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $109,846 per year, or $52.8 per hour.

Full-time

Posted 19 days ago


Job description

About OpenRouter
OpenRouter is the AI routing and infrastructure layer that AI builders, AI-native startups, and enterprises use to access, manage, and optimize their AI usage through a unified API, billing interface, and analytics platform. We route billions of tokens every month and sit at the center of how organizations operationalize LLMs across research, product, and production workloads.
We are a small team that punches above its weight. Every person here has direct impact on the product and our users.
About the Role
Most third-party risk roles hand you a mature program and ask you to keep the queue moving. This is the opposite.
You'll be the first security risk analyst at OpenRouter, building the vendor risk function from a blank page. The vendors you assess aren't the usual SaaS sprawl - they're the model providers and subprocessors sitting directly in our customers' data path. And you'll do it in a regulatory environment still being written: there's no playbook for how the EU AI Act applies to an AI routing layer and its supply chain. You'll help write ours.
If you've ever finished a vendor review and thought this should take a third as long and catch twice as much - and wanted to be the one to fix it - keep reading.
What You'll Do
  • Own end-to-end security assessments for model providers, subprocessors, and SaaS tooling - and get vendors live without becoming the bottleneck.
  • Read SOC 2 and ISO reports critically: scope, carve-outs, CUECs, exceptions, and whether the testing supports the opinion. Same for pen tests, DPAs, and subprocessor lists.
  • Turn findings into decisions - residual risk and compensating controls, not a spreadsheet of yellow cells.
  • Design and stand up the TPRM program: intake, tiering, SLAs, escalation, exceptions, and risk acceptance.
  • Pitch and implement tooling that compresses time-to-close, integrated with our GRC stack (Drata) and ticketing.
  • Build continuous monitoring for critical vendors and run annual reviews on a real cadence.
  • Map vendor risk to our SOC 2, ISO 27001, HIPAA, GDPR, and EU AI Act obligations, including flow-down to subprocessors.

What We're Looking For
  • 4+ years in third-party/vendor security risk or security assessment - real assessment reps, not just program administration.
  • Working fluency across SOC 2, ISO 27001, HIPAA, and GDPR, plus enough command of the EU AI Act to reason about it rather than recite it.
  • Technical literacy - cloud architecture, access models, encryption, data flows - enough to know when a vendor's answer doesn't hold up.
  • Comfort with DPAs, BAAs, and security exhibits, and judgment about which clauses actually matter.
  • A bias toward shipping. You'll pitch solutions and drive implementation yourself; nobody is going to manage your day.
  • Clear writing and a high tolerance for ambiguity. When the precedent doesn't exist, you write the memo.

Nice to Have
  • Experience assessing AI/ML vendors or inference infrastructure
  • ISO 42001 or NIST AI RMF
  • Scripting and automation to eliminate your own toil
  • GRC platform administration (Drata, Vanta, or similar)
  • Time at an early-stage startup where you built the function rather than joined it
  • CISSP, CISA, CRISC, or CTPRP.

If you don't think you meet all of the criteria below but still are interested in the job, please apply. Nobody checks every box, and we're looking for someone who is excited to join the team.