1

Senior Vendor Risk Analyst Jobs in Houston, TX (NOW HIRING)

Senior Analyst, Risk - Houston, Texas Company Information: Alpha Generation manages and operates power generation facilities that are well positioned to provide reliable, secure, safe, and ...

Senior Analyst, Risk - Houston, Texas Company Information: Alpha Generation manages and operates power generation facilities that are well positioned to provide reliable, secure, safe, and ...

To conduct Cost / Schedule Risk Analysis Workshop sessions, facilitating workshops building bespoke models and interpreting associated outputs for communication / review. * To educate, encourage and ...

Collaborate closely with senior analysts to contribute to the refinement of risk models and offer insights into market dynamics KEY DUTIES and RESPONSIBILITIES * Execute daily risk control process ...

Senior Risk Analyst

Houston, TX · On-site

$110 - $170/hr

To educate, encourage and support managers and business in the use of decision risk analysis techniques on projects where applicable. * Present and provide training on a range or RM topics to ...

Arthur Lawrence is looking for a Sr Risk Analyst Supervisor one of our clients in San Houston, TX. Please find the below and send us your updated resume if interested: Must-Have Skills: * 7+ years of ...

Arthur Lawrence is looking for a Sr Risk Analyst Supervisor one of our clients in Houston, TX. Please find the below and send us your updated resume if interested: Must-Have Skills: * 7+ years of ...

Perform vendor risk assessments against all security domains Perform technical implementation assessments from a security perspective related to vendor integrations (i.e. API integrations, SFTP ...

POSITION OVERVIEW The Senior/Lead Analyst, Market Risk, reports directly to the Manager, Market Risk, and is responsible for developing the Risk Department's capabilities and delivering the current ...

Provide analysis of risk drivers, spread movements, optionality value, and changes in valuation or risk metrics to risk committees and senior leadership. 3) Risk Framework, Controls, and Governance

POSITION OVERVIEW The Senior/Lead Analyst, Market Risk, reports directly to theManager, Market Risk,and is responsible for developing the Risk Department's capabilities and delivering the current ...

Provide analysis of risk drivers, spread movements, optionality value, and changes in valuation or risk metrics to risk committees and senior leadership. 3) Risk Framework, Controls, and Governance

next page

Showing results 1-20

Senior Vendor Risk Analyst information

See Houston, TX salary details

$51.1K

$104.9K

$136.1K

How much do senior vendor risk analyst jobs pay per year?

As of Aug 28, 2026, the average yearly pay for senior vendor risk analyst in Houston, TX is $104,900.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,400.00 and $130,800.00 per year, depending on experience, location, and employer.

What is a senior vendor risk analyst?

A Senior Vendor Risk Analyst is a professional responsible for evaluating and managing the risks associated with third-party vendors and suppliers. They assess vendor practices, review compliance with regulations, and ensure that vendors meet an organization's security and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and collaborating with internal teams to mitigate potential threats to the business. Senior Vendor Risk Analysts typically have a strong background in risk management, information security, and regulatory compliance.

What are the key skills and qualifications needed to thrive as a senior vendor risk analyst?

To thrive as a Senior Vendor Risk Analyst, you need expertise in risk assessment, vendor management, and compliance, typically backed by a bachelor’s degree in business, finance, or a related field. Familiarity with risk management frameworks (such as ISO 27001), third-party risk assessment tools, and certifications like CISA or CRVPM are highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set candidates apart in this role. These skills are crucial to ensure organizational security, regulatory compliance, and the mitigation of risks posed by third-party vendors.

How does a senior vendor risk analyst typically collaborate with other departments in the organization?

A Senior Vendor Risk Analyst works closely with departments such as procurement, IT, legal, compliance, and business units to assess and manage third-party risks. Collaboration often involves gathering information on new and existing vendors, coordinating risk assessments, and advising on contract clauses to mitigate potential issues. Effective communication and relationship-building are crucial, as the analyst must ensure all stakeholders understand the risk landscape and their respective responsibilities. This cross-functional teamwork helps maintain a comprehensive risk management approach and supports organizational objectives.

What is the difference between Senior Vendor Risk Analyst vs Vendor Risk Analyst?

AspectSenior Vendor Risk AnalystVendor Risk Analyst
CertificationsCRISC, CISA, or similarEntry-level certifications or none
Experience5+ years in risk management or vendor assessment1-3 years in vendor risk or related fields
Work EnvironmentCorporate, financial, or technology sectorsSimilar industries, often entry-level roles
ResponsibilitiesLeading risk assessments, developing policies, mentoringConducting vendor evaluations, supporting risk processes

The main difference between a Senior Vendor Risk Analyst and a Vendor Risk Analyst lies in experience, responsibilities, and certifications. The senior role involves leadership, advanced risk assessments, and strategic planning, while the vendor risk analyst typically focuses on supporting assessments and data collection. Both roles are vital in managing third-party risks within organizations, but the senior position requires more expertise and oversight.

What are the most commonly searched types of Vendor Risk Analyst jobs in Houston, TX?

The most popular types of Vendor Risk Analyst jobs in Houston, TX are:

What are popular job titles related to Senior Vendor Risk Analyst jobs in Houston, TX?

For Senior Vendor Risk Analyst jobs in Houston, TX, the most frequently searched job titles are:

What job categories do people searching Senior Vendor Risk Analyst jobs in Houston, TX look for?

The top searched job categories for Senior Vendor Risk Analyst jobs in Houston, TX are:

What cities near Houston, TX are hiring for Senior Vendor Risk Analyst jobs?

Cities near Houston, TX with the most Senior Vendor Risk Analyst job openings:

Infographic showing various Senior Vendor Risk Analyst job openings in Houston, TX as of August 2026, with employment types broken down into 91% Full Time, and 9% Contract. Highlights an 91% In-person, and 9% Remote job distribution, with an average salary of $104,900 per year, or $50.4 per hour.

Client & Vendor Risk Manager

Houston, TX

Baker Botts Llp
Law Firms • 1 - 5K employees

Full-time

Re-posted 20 days ago


Job description

ABOUT BAKER BOTTS

Baker Botts is a leading international law firm recognized for its deep understanding of the industries it serves. With offices across major global markets, the firm delivers sophisticated legal services while cultivating a collaborative, inclusive culture where both attorneys and professional staff contribute to client success and organizational excellence.

ABOUT THE ROLE

The Information Security Client & Vendor Risk Manager leads the firm’s client due diligence program and oversees all information security vetting for third party vendors across the firm. This role requires deep expertise in security frameworks, strong riskassessment judgment, and the ability to influence senior stakeholders, including internal stakeholders, and client security teams. The Manager acts as a key liaison between the firm’s clients, internal leadership, IT Security, Procurement, and Risk Management, ensuring the firm meets the heightened expectations of our clients.

WHAT YOU'LL DO

Primary Responsibilities

  • Own and mature the firmwide client and vendor duediligence program, ensuring consistency, accuracy, and alignment with the firm’s security posture and regulatory obligations.
  • Serve as the firm’s subjectmatter expert on informationsecurity controls, certifications, and risk posture during client audits, RFPs, and reviews or client engagement terms.
  • Lead complex vendorrisk assessments for highimpact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetrationtest results, cloudsecurity controls, dataprotection, privacy, and retention practices.
  • Develop and maintain the firm’s vendorrisk management framework, including riskscoring methodologies, onboarding workflows, and continuousmonitoring processes.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts, negotiate security requirements, and recommend riskmitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection, documentation, and SME participation across multiple departments.
  • Represent the firm in clientfacing security discussions, including responding to escalated inquiries from corporate counsel, privacy officers, and client security teams.
  • Monitor emerging risks and regulatory developments relevant to the legal industry (e.g., SEC cybersecurity rules, state privacy laws, international datatransfer requirements).
  • Mentor junior analysts and contribute to the professional development of the broader Risk and Compliance team.
  • Drive continuous improvement, identifying opportunities to streamline duediligence workflows, enhance tracking and remediation of client-identified risks, and strengthen the firm’s security posture.

Additional Responsibilities

  • Provide management with periodic reports & briefings on evolving topics within their area of responsibility.
  • Other related projects and duties as assigned by the Director of Information Security.

WHAT YOU'LL BRING

Required

  • 6+ years of experience in information security, vendor risk management, compliance, or legalindustry operations, ideally within an Am Law 200 firm or similarly regulated environment.
  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendorrisk assessments for enterpriselevel technology providers.
  • Strong communication skills, including the ability to brief partners, respond to client security teams, and translate technical concepts for nontechnical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead crossfunctional initiatives in a highpressure environment.
  • Professional certifications such as CTPRA, ISO 27001 Lead Implementer or Lead Auditor and CISSP, CISM, CRISC, or CISA required.
  • Experience with legalindustry technologies (DMS, ediscovery platforms, cloudbased practicemanagement tools) is a plus.

HOW YOU'LL WORK

Extent of Contact

This position requires contact with individuals within the firms as follows:

  • Daily contact with staff from the Firm’s Information Technology, Client Development and Office of the General Counsel teams.
  • Moderate contact with Firm’s attorneys and client representatives.
  • Occasional contact with Firm Management.

This position requires contact with individuals outside the firm as follows:

  • Moderate contact with Firm vendors or potential vendors.
  • Moderate contact with Firm clients

Physical Requirements

  • Must be able to routinely lift and carry event materials and other items up to 10 pounds.
  • Must be able to work at a computer for extensive periods of time.
  • Position requires extensive telephone use.
  • Must be able to lift, squat, kneel and bend.
  • Position requires the ability to visit face-to-face and on the phone with firm lawyers.

Working Conditions and Environment

  • Position is full-time and requires a five-day work week and standard hours as outlined in the Firm policy manual. Additional hours, including weekend and evening hours may be required to perform the essential functions of the job.
  • Must be able to perform essential duties of the position with time constraints and frequent interruptions. 
  • Ability to work well in high pressure environments.
  • 24x7 communication access is required.
  • This position is fully remote. You will be required to come to the office periodically for team meetings or when there is a business or client need.
  • There is potential for travel when needed for team meetings, onsite assessments etc. when there is a business or client need.
  • When working remotely, you must have secure and reliable internet service and a safe, private workspace from which to work.

Baker Botts L.L.P. is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, gender, sex, age, religion, creed, national origin, citizenship, marital status, sexual orientation, disability, medical condition, military and veteran status, gender identity or expression, genetic information, or any other basis protected by federal, state, or local law.