1

Senior Vendor Risk Analyst Jobs in Merrimac, MA (NOW HIRING)

Vendor Management Lead

Merrimack, NH · On-site

$45 - $48/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

The position will measure service levels, manage risk profiles, and support procurement activities ... Provide analysis and recommendations to resolve complex issues. * Produce recurring dashboards and ...

Senior SOC Analyst - Weekends

Nashua, NH · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... Use internal and external threat intelligence, risk insights, and adversary behavior research to ...

Senior SOC Analyst - Weekends

Lowell, MA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... Use internal and external threat intelligence, risk insights, and adversary behavior research to ...

Senior SOC Analyst - Weekends

Derry, NH · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... seeking a Senior SOC Analyst to support a weekend schedule ( Wednesday - Sunday OR Saturday ... Use internal and external threat intelligence, risk insights, and adversary behavior research to ...

... modeling vendors or reinsurers. 8. Leads efforts to enhance and optimize catastrophe modeling ... Ability to communicate complex catastrophe risk analyses to senior leadership and business partners

Senior Financial Analyst

Merrimack, NH · On-site

$87K - $109K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

At HiArc, we believe clients don't need another vendor; they need a strategic partner who gets it ... thermal control, risk management, supply chain management, performance testing, advanced ...

... modeling vendors or reinsurers. 8. Leads efforts to enhance and optimize catastrophe modeling ... Ability to communicate complex catastrophe risk analyses to senior leadership and business partners

... modeling vendors or reinsurers. 8. Leads efforts to enhance and optimize catastrophe modeling ... Ability to communicate complex catastrophe risk analyses to senior leadership and business partners

next page

Showing results 1-20

Senior Vendor Risk Analyst information

See Merrimac, MA salary details

$56.2K

$115.3K

$149.6K

How much do senior vendor risk analyst jobs pay per year?

As of Aug 18, 2026, the average yearly pay for senior vendor risk analyst in Merrimac, MA is $115,330.00, according to ZipRecruiter salary data. Most workers in this role earn between $95,000.00 and $143,800.00 per year, depending on experience, location, and employer.

What is a senior vendor risk analyst?

A Senior Vendor Risk Analyst is a professional responsible for evaluating and managing the risks associated with third-party vendors and suppliers. They assess vendor practices, review compliance with regulations, and ensure that vendors meet an organization's security and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and collaborating with internal teams to mitigate potential threats to the business. Senior Vendor Risk Analysts typically have a strong background in risk management, information security, and regulatory compliance.

What are the key skills and qualifications needed to thrive as a senior vendor risk analyst?

To thrive as a Senior Vendor Risk Analyst, you need expertise in risk assessment, vendor management, and compliance, typically backed by a bachelor’s degree in business, finance, or a related field. Familiarity with risk management frameworks (such as ISO 27001), third-party risk assessment tools, and certifications like CISA or CRVPM are highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set candidates apart in this role. These skills are crucial to ensure organizational security, regulatory compliance, and the mitigation of risks posed by third-party vendors.

How does a senior vendor risk analyst typically collaborate with other departments in the organization?

A Senior Vendor Risk Analyst works closely with departments such as procurement, IT, legal, compliance, and business units to assess and manage third-party risks. Collaboration often involves gathering information on new and existing vendors, coordinating risk assessments, and advising on contract clauses to mitigate potential issues. Effective communication and relationship-building are crucial, as the analyst must ensure all stakeholders understand the risk landscape and their respective responsibilities. This cross-functional teamwork helps maintain a comprehensive risk management approach and supports organizational objectives.

What is the difference between Senior Vendor Risk Analyst vs Vendor Risk Analyst?

AspectSenior Vendor Risk AnalystVendor Risk Analyst
CertificationsCRISC, CISA, or similarEntry-level certifications or none
Experience5+ years in risk management or vendor assessment1-3 years in vendor risk or related fields
Work EnvironmentCorporate, financial, or technology sectorsSimilar industries, often entry-level roles
ResponsibilitiesLeading risk assessments, developing policies, mentoringConducting vendor evaluations, supporting risk processes

The main difference between a Senior Vendor Risk Analyst and a Vendor Risk Analyst lies in experience, responsibilities, and certifications. The senior role involves leadership, advanced risk assessments, and strategic planning, while the vendor risk analyst typically focuses on supporting assessments and data collection. Both roles are vital in managing third-party risks within organizations, but the senior position requires more expertise and oversight.

What cities near Merrimac, MA are hiring for Senior Vendor Risk Analyst jobs?

Cities near Merrimac, MA with the most Senior Vendor Risk Analyst job openings:

Principal Technology Risk Analyst - Program & Regulatory Assurance

Fidelity Investments

Merrimack, NH • On-site

Full-time

Re-posted 13 days ago


Fidelity Investments rating

8.7

Company rating: 8.7 out of 10

Based on 272 frontline employees who took The Breakroom Quiz

16th of 150 rated financial services


Job description

Job Description:

Title: Principal Technology Risk Analyst

Note: Fidelity will not provide immigration sponsorship for this position.

The Role

The Enterprise Technology Risk group is seeking a passionate, driven and experienced professional to contribute to the Technology Risk Program and Regulatory Assurance CoE team.This role is responsible for performing regulatory and program management responsibilities, including designing and maintaining technology controls to support program and regulatory requirements. This role will require networking and relationship management skills to collaborate with the Controls Testing team, and various business units and risk teams across the enterprise. You will be working on:

  • Ensuring risk and control taxonomy aligns with enterprise standards
  • Developing and monitoring technology controls for security and compliance
  • Providing technical support and acting as liaison for technology risk management
  • Managing control updates, annual mapping, and testing requirements
  • Design, document, and maintain Risk and Control Matrices (RCMs/RACMs) across business and IT processes
  • Continuously improve and standardize control documentation and governance practices
  • Overseeing control certification process
  • Partnering with Control Testing team to track progress and remediation
  • Representing ETRA in enterprise control initiatives and special projects
  • Supporting regulatory activities, risk assessments, and examinations
  • Leading and supporting SOX 404 compliance, including control documentation
  • Reviewing SOC reports, assessing CUECs, and communicating control gaps

The Team

The Technology Risk Program and Regulatory Assurance team is responsible for managing controls to support program requirements, monitoring the results of control testing to meet program requirements, and ensuring a consistent risk and control taxonomy is leveraged in accordance with enterprise best practices. Additionally, this team supports regulatory activities such as maintaining application, server, and database inventories by entity.Technology Risk is part of the broader Legal, Risk and Compliance group and partners with Corporate Audit, Enterprise Compliance, and Security to protect the interests of our customers, our employees, and Fidelity's brand. You will also work closely with the Enterprise Technology Risk teams as well as Fidelity technology and business owners, and Operational Risk teams.

The Expertise and Skills You Bring

  • 5 -7 years' experience in information technology risk, controls, or audit roles
  • Bachelor's degree in computer science, technology, or a related field of study preferred
  • Professional technology and associated risk certifications (CISSP, CISA, CRISC, CISM), Certified risk/fraud examiners (CRE, CFE), and/or Cloud Certification(s) (CCSP, CCSK, AWS) preferred
  • Experience documenting controls for large scale financial service organizations (cloud, distributed, vendor solutions, mainframe, network environments, and AI)
  • Demonstrated technical abilities in multiple areas (e.g., technology infrastructure and application controls, cyber security, access management, network and cloud, resiliency, etc.)
  • Working knowledge of Cloud security and controls and cloud technology environments (AWS/Azure, SaaS, PaaS)
  • You have a strong knowledge of information technology processes and controls, and a comprehensive understanding of risk, quality control and assurance functions
  • Your love of solving complex problems, and comfort with ambiguous situations, and your ability to help solution innovative ways to mitigate risk using your advanced analytical and critical thinking skills
  • Your ability to build and maintain collaborative working relationships with Information Technology and Business personnel to design effective controls
  • Your process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
  • Knowledge of Industry standards, regulations, frameworks and best practices, such as NIST SP 800-53, COBIT, AICPA Trust Principles, ISO27001, SWIFT, HITRUST, and SOX404 is preferred
  • ISO9001 and/or ISO27001 certification preferred, with responsibility to support and participate in ISO peer audit reviews.
  • Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferred
  • Your excellent verbal and written communication skills enabling you to prepare and present recommendations to senior management

Note: Fidelity will not provide immigration sponsorship for this position.

Fidelity's Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:Category:Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.


What Fidelity Investments employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom