1

Senior Vendor Risk Analyst Jobs in New York (NOW HIRING)

... with senior leadership. * Advise IT, Engineering and business teams on vendor integration ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

... with senior leadership. * Advise IT, Engineering and business teams on vendor integration ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

... with senior leadership. * Advise IT, Engineering and business teams on vendor integration ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

... with senior leadership. * Advise IT, Engineering and business teams on vendor integration ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Risk Analyst

Woodbury, NY · On-site

$32 - $35/hr

Third-Party Risk Analyst II The Third-Party Risk Analyst II supports the Enterprise Risk Management team by assessing and monitoring risks associated with current and prospective third-party vendors.

Senior Risk Analyst

Newark, NJ · On-site

$135 - $165/hr

Role Overview The Senior Risk Analyst role is critical in protecting the business from fraud and financial loss by proactively monitoring transaction trends, flagging suspicious behavior, and ...

The Senior Risk Analyst role is critical in protecting the business from fraud and financial loss by proactively monitoring transaction trends, flagging suspicious behavior, and contributing to the ...

Senior Fintech Risk Analyst

Manhattan, NY · On-site

$122.72 - $137.50/hr

Conduct the risk analysis and due diligence for 4th-party vendors, while building and maintaining ... for senior leadership and risk committees. * Risk Project Delivery: Successfully manage the ...

The Senior Risk Analyst role is critical in protecting the business from fraud and financial loss by proactively monitoring transaction trends, flagging suspicious behavior, and contributing to the ...

Senior Risk Analyst

Newark, NJ · On-site

$70 - $110/hr

Analyze large sets of data to identify risk trends, including chargebacks, returns, and unusual volume spikes. * Create and refine rules, alerts, and reports in risk monitoring tools to flag ...

Risk Analyst

New York, NY · On-site

$75K - $95K/yr

... senior management, regulatory authorities, Independent Process Validation Group, and Internal Audit ... Finance, Risk Analytics and Credit Risk - Perform, and participate in, regulatory and capital ...

Senior Vendor Program Analyst

New York, NY · On-site

$126K - $127K/yr

... Risk teams. This role is located in the Legal department and will focus on Enterprise tools ... It fills a need for ownership and representation on enterprise vendors that have no sole business ...

Risk Analyst

New York, NY · On-site

$75K - $95K/yr

... senior management, regulatory authorities, Independent Process Validation Group, and Internal Audit ... Finance, Risk Analytics and Credit Risk - Perform, and participate in, regulatory and capital ...

The Senior Risk Analyst will help to shape the risk management function for the U.S. Exchange business, working directly with trading, product, legal, and operations to stand up governance ...

next page

Showing results 1-20

Senior Vendor Risk Analyst information

What is a senior vendor risk analyst?

A Senior Vendor Risk Analyst is a professional responsible for evaluating and managing the risks associated with third-party vendors and suppliers. They assess vendor practices, review compliance with regulations, and ensure that vendors meet an organization's security and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and collaborating with internal teams to mitigate potential threats to the business. Senior Vendor Risk Analysts typically have a strong background in risk management, information security, and regulatory compliance.

What are the key skills and qualifications needed to thrive as a senior vendor risk analyst?

To thrive as a Senior Vendor Risk Analyst, you need expertise in risk assessment, vendor management, and compliance, typically backed by a bachelor’s degree in business, finance, or a related field. Familiarity with risk management frameworks (such as ISO 27001), third-party risk assessment tools, and certifications like CISA or CRVPM are highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set candidates apart in this role. These skills are crucial to ensure organizational security, regulatory compliance, and the mitigation of risks posed by third-party vendors.

How does a senior vendor risk analyst typically collaborate with other departments in the organization?

A Senior Vendor Risk Analyst works closely with departments such as procurement, IT, legal, compliance, and business units to assess and manage third-party risks. Collaboration often involves gathering information on new and existing vendors, coordinating risk assessments, and advising on contract clauses to mitigate potential issues. Effective communication and relationship-building are crucial, as the analyst must ensure all stakeholders understand the risk landscape and their respective responsibilities. This cross-functional teamwork helps maintain a comprehensive risk management approach and supports organizational objectives.

What is the difference between Senior Vendor Risk Analyst vs Vendor Risk Analyst?

AspectSenior Vendor Risk AnalystVendor Risk Analyst
CertificationsCRISC, CISA, or similarEntry-level certifications or none
Experience5+ years in risk management or vendor assessment1-3 years in vendor risk or related fields
Work EnvironmentCorporate, financial, or technology sectorsSimilar industries, often entry-level roles
ResponsibilitiesLeading risk assessments, developing policies, mentoringConducting vendor evaluations, supporting risk processes

The main difference between a Senior Vendor Risk Analyst and a Vendor Risk Analyst lies in experience, responsibilities, and certifications. The senior role involves leadership, advanced risk assessments, and strategic planning, while the vendor risk analyst typically focuses on supporting assessments and data collection. Both roles are vital in managing third-party risks within organizations, but the senior position requires more expertise and oversight.

What are the most commonly searched types of Vendor Risk Analyst jobs in New York?

The most popular types of Vendor Risk Analyst jobs in New York are:

What job categories do people searching Senior Vendor Risk Analyst jobs in New York look for?

The top searched job categories for Senior Vendor Risk Analyst jobs in New York are:

What cities in New York are hiring for Senior Vendor Risk Analyst jobs?

Cities in New York with the most Senior Vendor Risk Analyst job openings:

Vendor Risk Manager

Westport, CT • On-site

Full-time

Dental, Vision, Life, Retirement, PTO

Re-posted 24 days ago


Job description

Vendor Risk Manager
Dalio Family Office
Dalio Family Office Overview:
The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes OceanX, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO's culture is built around meaningful work and meaningful relationships and the family's commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi.
Position Summary:
The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across cybersecurity, AI, privacy, financial, and AML/CFT/sanctions domains into clear, actionable risk positions, performing structured threat modeling for high-exposure vendors.
Day-to-day responsibilities would include a combination of the following:
  • Own the VRM program end-to-end: strategy, policy, procedure, workflow, tooling, metrics, and executive reporting for CISO/CRO/board visibility.
  • Lead holistic vendor risk assessments across cybersecurity, AI risk, privacy, financial, AML/CFT/sanctions.
  • Document residual risk acceptances with named accountable executives and time-boxed review dates; coordinate with IT, Legal, Finance, and Compliance as appropriate.
  • Evaluate and monitor vendor security controls based on data sensitivity and business criticality, leveraging industry frameworks and evidence such as SOC 2, ISO 27001, penetration testing, and security assessments.
  • Conduct structured threat models (STRIDE, PASTA) for high risk vendors, and document findings as durable artifacts informing contracting, monitoring, and exit planning.
  • Translate threat model outputs into concrete, testable control requirements drawing from OWASP (ASVS, API Security Top 10, LLM/Agentic Top 10), NIST (SP 800-53, SP 800-161, CSF 2.0, SP 800-207), and MITRE ATT&CK; scale requirements to vendor tier.
  • Partner with Legal to translate identified risks into enforceable contractual requirements.
  • Apply FAIR or comparable quantitative methods for high-impact vendor decisions, expressing cyber risk in loss-exposure terms that resonate with senior leadership.
  • Advise IT, Engineering and business teams on vendor integration architecture (SSO/SCIM, OAuth, conditional access, DLP, segmentation, BYOK, VPC peering) and maintain approved reference patterns.
  • Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth; produce program dashboards tracking throughput, cycle time, recertification compliance, and remediation aging.

The ideal candidate will possess the following knowledge, skills, attributes, and values:
  • Expert knowledge of third-party/vendor risk management
  • Strong risk assessment and analytical skills
  • Technical understanding of enterprise security architecture
  • Excellent communication and stakeholder management skills
  • Proven ability to lead and optimize vendor risk programs

Illustrative Benefits:
  • 100% company paid medical premiums
  • 17 company paid holidays
  • Friday summer hours
  • Monthly community happy hours
  • Hybrid work environment
  • Free catered food services for in-office days
  • Generous PTO offering
  • Casual dress code
  • 150% 401(k) match up to $7,500 and 100% match above $7,500 ($15k match limit)
  • Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!

Qualifications:
  • Bachelor's degree in Information Security, Risk Management, Computer Science, Cybersecurity, or a related discipline.
  • At least 7 years of progressive experience across vendor risk management, cybersecurity architecture, security engineering, GRC, audit, or related fields.
  • Experience managing the full third-party/vendor risk lifecycle, including vendor onboarding, due diligence, risk assessments, continuous monitoring, recertification, remediation tracking, and vendor exit planning, with at least 2 years owning an end-to-end TPRM program.
  • Strong technical knowledge of cybersecurity frameworks, standards, and methodologies including NIST, ISO 27001/27002, OWASP, MITRE ATT&CK, Shared Assessments, threat modeling approaches (STRIDE/PASTA), and risk management practices.
  • Hands-on experience evaluating enterprise security controls, cloud and integration architectures, SOC 2 Type II reports, ISO certifications, penetration testing results, data protection requirements, and third-party security risks across complex technology environments.
  • Ability to communicate complex technical and risk concepts to executive stakeholders, collaborate effectively across business functions
  • 10% travel as required based on business needs.

Compensation:
Compensation for the role includes a competitive salary in the range from $175,000 -$260,000 (inclusive of a merit-based bonus, dependent on years of experience, level of education obtained, as well as applicable skillset) and an excellent benefits package, including paid time off ranging from 15 to 25 days based on years of service, paid sick and safe leave, dental, vision, life and disability insurance, paid parental time off, birth mother recovery pay, sick family member pay, parental ramp back up program, gym reimbursement and generous employer match for 401k.
Please note we are unable to provide immigration sponsorship for this position.
At the DFO, we believe our biggest asset is our people. We are proud to be an equal opportunity employer, hiring and developing individuals from diverse backgrounds and experiences to add to our collaborative culture. The DFO treats all candidates and employees with respect and does not discriminate in our recruiting, hiring, and promoting processes and general treatment during employment, including on the basis of actual or perceived race, creed, color, religion, sex, age, sexual orientation, gender identity and/or expression, alienage or national origin, ancestry, citizenship status, marital status, veteran status, or disability.