1

Senior Vendor Risk Analyst Jobs in Utah (NOW HIRING)

Senior TPRM Security Lead Austin | Chicago | New York City | Salt Lake City | San Francisco Gong ... Apply a risk-based approach to vendor reviews, tiering vendors and scaling the depth of due ...

Conduct third-party vendor risk assessments and internal risk evaluations; identify, document, and ... senior team members to develop practical security solutions. * Coordinate and deliver security ...

Conduct third-party vendor risk assessments and internal risk evaluations; identify, document, and ... senior team members to develop practical security solutions. * Coordinate and deliver security ...

Showing results 21-40

Senior Vendor Risk Analyst information

What is a senior vendor risk analyst?

A Senior Vendor Risk Analyst is a professional responsible for evaluating and managing the risks associated with third-party vendors and suppliers. They assess vendor practices, review compliance with regulations, and ensure that vendors meet an organization's security and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and collaborating with internal teams to mitigate potential threats to the business. Senior Vendor Risk Analysts typically have a strong background in risk management, information security, and regulatory compliance.

What are the key skills and qualifications needed to thrive as a senior vendor risk analyst?

To thrive as a Senior Vendor Risk Analyst, you need expertise in risk assessment, vendor management, and compliance, typically backed by a bachelor’s degree in business, finance, or a related field. Familiarity with risk management frameworks (such as ISO 27001), third-party risk assessment tools, and certifications like CISA or CRVPM are highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set candidates apart in this role. These skills are crucial to ensure organizational security, regulatory compliance, and the mitigation of risks posed by third-party vendors.

How does a senior vendor risk analyst typically collaborate with other departments in the organization?

A Senior Vendor Risk Analyst works closely with departments such as procurement, IT, legal, compliance, and business units to assess and manage third-party risks. Collaboration often involves gathering information on new and existing vendors, coordinating risk assessments, and advising on contract clauses to mitigate potential issues. Effective communication and relationship-building are crucial, as the analyst must ensure all stakeholders understand the risk landscape and their respective responsibilities. This cross-functional teamwork helps maintain a comprehensive risk management approach and supports organizational objectives.

What is the difference between Senior Vendor Risk Analyst vs Vendor Risk Analyst?

AspectSenior Vendor Risk AnalystVendor Risk Analyst
CertificationsCRISC, CISA, or similarEntry-level certifications or none
Experience5+ years in risk management or vendor assessment1-3 years in vendor risk or related fields
Work EnvironmentCorporate, financial, or technology sectorsSimilar industries, often entry-level roles
ResponsibilitiesLeading risk assessments, developing policies, mentoringConducting vendor evaluations, supporting risk processes

The main difference between a Senior Vendor Risk Analyst and a Vendor Risk Analyst lies in experience, responsibilities, and certifications. The senior role involves leadership, advanced risk assessments, and strategic planning, while the vendor risk analyst typically focuses on supporting assessments and data collection. Both roles are vital in managing third-party risks within organizations, but the senior position requires more expertise and oversight.

What are the most commonly searched types of Vendor Risk Analyst jobs in Utah?

The most popular types of Vendor Risk Analyst jobs in Utah are:

What are popular job titles related to Senior Vendor Risk Analyst jobs in Utah?

For Senior Vendor Risk Analyst jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Senior Vendor Risk Analyst jobs in Utah look for?

The top searched job categories for Senior Vendor Risk Analyst jobs in Utah are:

What cities in Utah are hiring for Senior Vendor Risk Analyst jobs?

Cities in Utah with the most Senior Vendor Risk Analyst job openings:

Infographic showing various Senior Vendor Risk Analyst job openings in Utah as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 11% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus

Orem, UT • On-site, Remote

Full-time

Retirement, PTO

Posted 6 days ago


Job description

RainFocus, one of the most innovative software companies, is in search of an exceptional Senior Governance, Risk, and Compliance (GRC) Analyst.
About RainFocus
RainFocus cares about its employees, customers, and the world in which we live. Our rapidly growing team serves Fortune 500 companies like Adobe, Cisco, IBM, Oracle, VMware, and others to prepare and execute in-person, virtual, and hybrid events across the world. Those events are delivered through our industry-disrupting software platform, with groundbreaking business intelligence, to elevate the attendee experience, streamline event operations, and accelerate marketing results. We are well-funded, growing fast, and building a company that is changing the market - it will be challenging, fun, and exciting.
About the Role
We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program - maintaining our control framework, leading risk assessments, supporting audits, and driving the program's maturity forward rather than simply maintaining the status quo. You will report directly to the CISO and have significant ownership from day one.
Key Responsibilities:
Lead RainFocus's GRC program across SOC 2, ISO 27001, PCI DSS, and other client/regulatory compliance frameworks, including audit prep, evidence collection, and auditor relationships.
Manage and mature our control framework, mapping new regulations and conducting gap assessments.
Own the annual security risk assessment process (NIST SP 800-30 methodology), including stakeholder interviews, risk scoring, and residual risk tracking.
Maintain and update security policies, standards, and documentation to ensure compliance with industry best practices.
Partner with Engineering and Security to mature vulnerability management and secrets-scanning practices, moving these from reactive to proactive, pre-deployment controls.
Help build out and operationalize a Data Loss Prevention (DLP) program, including policy design and rollout across email, endpoint, and cloud storage.
Grow and mature RainFocus's security awareness training program.
Drive AI governance efforts - policy, tooling, and monitoring for approved vs. unapproved AI tool usage across the company.
Identify and help close Shadow IT / unmanaged SaaS visibility gaps in partnership with IT.
Collaborate with cross-functional teams to implement risk management practices and ensure compliance across the organization.
Respond to security and privacy inquiries from clients, partners, and employees.
Prepare and present reports on the organization's security and privacy compliance status, including program maturity and remediation progress.
Stay abreast of emerging security threats, vulnerabilities, and compliance requirements.
Qualifications:
Bachelor's degree in Technology, Cybersecurity, or a related field is highly desirable.
6+ years of proven experience in GRC, IT audit, information security compliance, or a related field.
In-depth knowledge of relevant regulations, standards, and frameworks (e.g., SOC 2, ISO 27001, PCI DSS, NIST 800-series, GDPR, and others).
Experience running or contributing heavily to formal risk assessments - not just tracking a compliance checklist.
Professional certifications such as CISA, CRISC, CISSP, CIPP, or CIPM are highly desirable.
Familiarity with modern security tooling such as Drata, OneTrust, Vanta, etc.
Strong analytical and problem-solving skills, with keen attention to detail.
Excellent communication and interpersonal skills to work effectively with technical and non-technical stakeholders.
Ability to manage multiple projects and meet deadlines in a fast-paced environment.
Experience with cloud security and compliance frameworks is a plus.
Experience with OneTrust or related GRC technologies is a plus.
Personal Characteristics:
Strong work ethic and commitment to excellence.
Ability to work independently and as part of a team.
Excellent problem-solving and analytical skills.
Strong communication and interpersonal skills.
Ability to adapt to change and learn quickly.
Passion for security and privacy.
Why work at RainFocus?
At RainFocus we delight millions of attendees at large-scale events by delivering better insights, experiences, and marketing. We were able to pivot our product and services offering in 2020 to continue growing and serving new clients and events.
As a member of the RainFocus team, you will have the opportunity to experience first-hand the impact of our platform at events around the world. Additionally, RainFocus offers competitive salaries, competitive benefits, 401k, generous PTO, and countless other team building activities.
What are you waiting for? Apply today! We need more talented, hard-working, fun-loving team members just like yourself!
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.