1

Senior Vendor Risk Analyst Jobs (NOW HIRING)

Engage with vendors to review controls, certifications, and risks in support of the associated ... Technical Direction of Work Report to a senior staff Cyber Risk Analyst within Business ...

Engage with vendors to review controls, certifications, and risks in support of the associated ... Technical Direction of Work Report to a senior staff Cyber Risk Analyst within Business ...

Review owner contracts, subcontracts, and vendor agreements for risk exposure * Identify ... Present risk findings and recommendations to senior management * Maintain risk policies, procedures ...

Senior Risk Analyst

Charlotte, NC · On-site

$107K - $127K/yr

A Senior Risk Analyst will independently interpret risk exposures, offer clear insights to senior stakeholders and provide critical insights regarding enhancements of the ERM reporting processes. Our ...

The Senior Technology Risk Analyst is expected to manage and mature the enterprise risk register ... Maintain strong oversight of third-party, vendor, and business-partner risks and update the risk ...

next page

Showing results 1-20

Senior Vendor Risk Analyst information

See salary details

$53.5K

$109.8K

$142.5K

How much do senior vendor risk analyst jobs pay per year?

As of Jun 18, 2026, the average yearly pay for senior vendor risk analyst in the United States is $109,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,500.00 and $137,000.00 per year, depending on experience, location, and employer.

What is a Senior Vendor Risk Analyst?

A Senior Vendor Risk Analyst is a professional responsible for evaluating and managing the risks associated with third-party vendors and suppliers. They assess vendor practices, review compliance with regulations, and ensure that vendors meet an organization's security and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and collaborating with internal teams to mitigate potential threats to the business. Senior Vendor Risk Analysts typically have a strong background in risk management, information security, and regulatory compliance.

What is the difference between Senior Vendor Risk Analyst vs Vendor Risk Analyst?

AspectSenior Vendor Risk AnalystVendor Risk Analyst
CertificationsCRISC, CISA, or similarEntry-level certifications or none
Experience5+ years in risk management or vendor assessment1-3 years in vendor risk or related fields
Work EnvironmentCorporate, financial, or technology sectorsSimilar industries, often entry-level roles
ResponsibilitiesLeading risk assessments, developing policies, mentoringConducting vendor evaluations, supporting risk processes

The main difference between a Senior Vendor Risk Analyst and a Vendor Risk Analyst lies in experience, responsibilities, and certifications. The senior role involves leadership, advanced risk assessments, and strategic planning, while the vendor risk analyst typically focuses on supporting assessments and data collection. Both roles are vital in managing third-party risks within organizations, but the senior position requires more expertise and oversight.

How does a Senior Vendor Risk Analyst typically collaborate with other departments in the organization?

A Senior Vendor Risk Analyst works closely with departments such as procurement, IT, legal, compliance, and business units to assess and manage third-party risks. Collaboration often involves gathering information on new and existing vendors, coordinating risk assessments, and advising on contract clauses to mitigate potential issues. Effective communication and relationship-building are crucial, as the analyst must ensure all stakeholders understand the risk landscape and their respective responsibilities. This cross-functional teamwork helps maintain a comprehensive risk management approach and supports organizational objectives.

What are the key skills and qualifications needed to thrive as a Senior Vendor Risk Analyst, and why are they important?

To thrive as a Senior Vendor Risk Analyst, you need expertise in risk assessment, vendor management, and compliance, typically backed by a bachelor’s degree in business, finance, or a related field. Familiarity with risk management frameworks (such as ISO 27001), third-party risk assessment tools, and certifications like CISA or CRVPM are highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set candidates apart in this role. These skills are crucial to ensure organizational security, regulatory compliance, and the mitigation of risks posed by third-party vendors.
More about Senior Vendor Risk Analyst jobs
What cities are hiring for Senior Vendor Risk Analyst jobs? Cities with the most Senior Vendor Risk Analyst job openings:
What are the most commonly searched types of Vendor Risk Analyst jobs? The most popular types of Vendor Risk Analyst jobs are:
What states have the most Senior Vendor Risk Analyst jobs? States with the most job openings for Senior Vendor Risk Analyst jobs include:
What job categories do people searching Senior Vendor Risk Analyst jobs look for? The top searched job categories for Senior Vendor Risk Analyst jobs are:
Infographic showing various Senior Vendor Risk Analyst job openings in the United States as of June 2026, with employment types broken down into 73% Full Time, 21% Part Time, 2% Temporary, and 4% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $109,846 per year, or $52.8 per hour.
Senior Analyst - Third Party Risk Management

Senior Analyst - Third Party Risk Management

Sentara

Norfolk, VA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 26 days ago


Sentara Health rating

6.8

Company rating: 6.8 out of 10

Based on 385 frontline employees who took The Breakroom Quiz

488th of 873 rated healthcare providers


Job description

City/State

Norfolk, VA

Work Shift

First (Days)

Overview:

Third Party Risk Management (TPRM) Senior Analyst is responsible for ensuring the organization effectively manages risks associated with third-party vendors and partners throughout the entire third-party lifecycle, including vendor selection, contract negotiation, ongoing monitoring, and termination. This involves not only identifying and evaluating risks but also collaborating with various teams, particularly Legal and Procurement, to embed risk mitigation strategies into contractual agreements.

Key responsibilities

  • Vendor Risk Assessment (VRA):
    • Conduct thorough risk assessments for potential and existing vendors, focusing on various risk types, including cybersecurity, operational, financial, and compliance risks.
    • Utilize and potentially create vendor risk assessment questionnaires to gather detailed information about vendor practices, including data security policies, internal controls, compliance posture, and business continuity plans.
    • Analyze questionnaire responses and other relevant information to identify deficiencies, areas for remediation, and categorize vendors based on risk levels.
    • Engage with stakeholders to communicate assessment results, address security concerns, and collaborate on potential remediation actions.
    • Perform periodic reviews and reassessments of existing vendors to ensure ongoing compliance and address evolving risks.
  • Contract Negotiation:
    • Partner with Legal and Procurement teams during contract negotiations to ensure security, privacy, and other relevant risk clauses are adequately addressed.
    • Provide expert guidance on acceptable and unacceptable contract terms related to risk management, service level agreements (SLAs), and data protection.
    • Work to define and include clear performance standards, due diligence requirements, and exit strategies within contracts.
  • TPRM program development and maintenance:
    • Support the development, maintenance, and enhancement of the organization's Third-Party Risk Management program and framework.
    • Develop and update TPRM procedures to ensure alignment with organizational policies and regulatory requirements.
    • Identify and implement process efficiencies within the TPRM program and perform analyses on team metrics to enhance effectiveness.
  • Stakeholder collaboration and communication:
    • Build and maintain strong relationships with internal stakeholders across departments such as Legal, Procurement, Information Security, and Business Units.
    • Provide TPRM guidance and training to Vendor Relationship Owners and business partners on risk management practices.
    • Communicate identified risks, assessment results, and mitigation strategies to stakeholders, including senior management, clearly and concisely.
  • Ongoing monitoring and remediation:
    • Track identified risks associated with third parties and ensure timely reviews are performed.
    • Monitor key supplier performance against established SLAs and regulatory requirements.
    • Track and collaborate with internal partners and vendors to remediate any risk-related issues.
Education
  • Bachelor's degree in a relevant field such as Business, Finance, Information Technology, or a related discipline (Preferred)
  • Experience in lieu of Bachelor's Degree -7+ years of relevant experience without a degree
Certification/Licensure
  • CISA, CRISC, CISM, CISSP, or other relevant certifications are preferred
Experience
  • 5+ years of relevant experience with a degree
  • Strong understanding of Third-Party Risk Management (TPRM) principles, concepts, and best practices.
  • Experience in conducting vendor risk assessments and evaluating internal controls, potentially leveraging frameworks like ISO 27001/2, NIST 800-53, NIST CSF, SOC1/SOC2, CSA CCM, and Shared Assessments SIG.
  • Working knowledge of contract management principles and practices, including contract negotiation and analysis.
  • Excellent communication skills, both written and verbal, with the ability to effectively articulate security control requirements, assessment results, and risk considerations to diverse audiences.
  • Strong analytical, critical thinking, and problem-solving skills, with the ability to digest and analyze complex information with attention to detail and accuracy.
  • Ability to work collaboratively in a cross-functional environment and build strong relationships with internal and external partners.
  • Proficiency in Microsoft Office Suite (Excel, PowerPoint, Word) and potentially GRC (Governance, Risk, and Compliance) tools like OneTrust (highly desirable), Archer, or ServiceNow

Keywords: TPRM, Third party Risk assessment

Benefits: Caring For Your Family and Your Career
Medical, Dental, Vision plans
Adoption, Fertility and Surrogacy Reimbursement up to 10,000
Paid Time Off and Sick Leave
Paid Parental & Family Caregiver Leave
Emergency Backup Care
Long-Term, Short-Term Disability, and Critical Illness plans
Life Insurance
401k/403B with Employer Match
Tuition Assistance - 5,250/year and discounted educational opportunities through Guild Education
Student Debt Pay Down - 10,000
Reimbursement for certifications and free access to complete CEUs and professional development
Pet Insurance
Legal Resources Plan
Colleagues have the opportunity to earn an annual discretionary bonus ifestablished system and employee eligibility criteria is met.

Sentara Health is an equal opportunity employer and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.


In support of our mission "to improve health every day," this is a tobacco-free environment.

For positions that are available as remote work, Sentara Health employs associates in the following states:

Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.


What Sentara Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom