1

Senior Vendor Risk Management Jobs in Houston, TX

Lead the development of weekly risk reporting for senior management, communicating key risks, exposures, and mitigation strategies. * Partner with the Accounting team to review monthly hedging ...

Manager, Risk Management & Insurance At KBR, We Deliver. KBR ISA (Integrated Solutions Americas ... Comfortable leading meetings and able to communicate issues and trends to senior management.

Director of Risk Management Department: Risk Management Location: Houston or Dallas (Hybrid ... vendors, and operational leaders to ensure effective communication, timely claim progression, and ...

next page

Showing results 1-20

Senior Vendor Risk Management information

See Houston, TX salary details

$21.5K

$112.9K

$200.5K

How much do senior vendor risk management jobs pay per year?

As of Sep 7, 2026, the average yearly pay for senior vendor risk management in Houston, TX is $112,933.00, according to ZipRecruiter salary data. Most workers in this role earn between $80,700.00 and $138,500.00 per year, depending on experience, location, and employer.

What does a senior vendor risk management professional do?

A Senior Vendor Risk Management professional is responsible for overseeing an organization’s third-party vendors to identify, assess, and mitigate risks that could impact business operations, data security, or regulatory compliance. They develop and implement vendor risk assessment frameworks, conduct thorough due diligence, and collaborate with other departments to ensure vendors meet company standards and legal requirements. Additionally, they monitor ongoing vendor relationships, manage risk remediation efforts, and often report findings to senior leadership or regulatory bodies.

What are the key skills and qualifications needed to thrive as a senior vendor risk management professional, and why are they important?

To thrive as a Senior Vendor Risk Management professional, you need expertise in risk assessment, third-party due diligence, and a solid understanding of regulatory compliance, often supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk management platforms, vendor management systems, and certifications like CISA or CRVPM is commonly expected. Strong analytical thinking, communication, and negotiation skills are crucial for building effective relationships and addressing vendor issues. These skills and qualifications are essential for mitigating risks, ensuring compliance, and safeguarding organizational interests in vendor relationships.

What are some common challenges faced by senior vendor risk management professionals, and how can they be addressed?

Senior Vendor Risk Management professionals often encounter challenges such as navigating complex regulatory requirements, managing relationships with a diverse range of vendors, and ensuring consistent due diligence across all third parties. Addressing these challenges typically involves staying updated on relevant regulations, implementing robust risk assessment frameworks, and fostering strong communication with both internal stakeholders and vendors. Building cross-functional collaboration with legal, compliance, and procurement teams is also crucial for effectively mitigating vendor-related risks.

What is the difference between Senior Vendor Risk Management vs Vendor Risk Analyst?

AspectSenior Vendor Risk ManagementVendor Risk Analyst
CertificationsCRISC, CISA, or similarCRISC, CISA, or similar
Work EnvironmentStrategic, leadership-focused, cross-departmentalOperational, data analysis, risk assessment
Employer & Industry UsageFinancial, healthcare, technology firmsFinancial, retail, technology sectors

Senior Vendor Risk Management roles typically involve strategic oversight and leadership in managing vendor risks, requiring advanced certifications and experience. Vendor Risk Analysts focus on data collection, risk assessment, and supporting vendor evaluations. While both roles require similar credentials, the senior role emphasizes strategy and management, whereas the analyst role is more operational and detail-oriented.

What are the most commonly searched types of Vendor Risk Management jobs in Houston, TX?

The most popular types of Vendor Risk Management jobs in Houston, TX are:

What are popular job titles related to Senior Vendor Risk Management jobs in Houston, TX?

For Senior Vendor Risk Management jobs in Houston, TX, the most frequently searched job titles are:

What job categories do people searching Senior Vendor Risk Management jobs in Houston, TX look for?

The top searched job categories for Senior Vendor Risk Management jobs in Houston, TX are:

What cities near Houston, TX are hiring for Senior Vendor Risk Management jobs?

Cities near Houston, TX with the most Senior Vendor Risk Management job openings:

Client & Vendor Risk Manager

Baker Botts Llp

Houston, TX

Full-time

Re-posted 13 hours ago


Job description

ABOUT BAKER BOTTS

Baker Botts is a leading international law firm recognized for its deep understanding of the industries it serves. With offices across major global markets, the firm delivers sophisticated legal services while cultivating a collaborative, inclusive culture where both attorneys and professional staff contribute to client success and organizational excellence.

ABOUT THE ROLE

The Information Security Client & Vendor Risk Manager leads the firm’s client due diligence program and oversees all information security vetting for third party vendors across the firm. This role requires deep expertise in security frameworks, strong riskassessment judgment, and the ability to influence senior stakeholders, including internal stakeholders, and client security teams. The Manager acts as a key liaison between the firm’s clients, internal leadership, IT Security, Procurement, and Risk Management, ensuring the firm meets the heightened expectations of our clients.

WHAT YOU'LL DO

Primary Responsibilities

  • Own and mature the firmwide client and vendor duediligence program, ensuring consistency, accuracy, and alignment with the firm’s security posture and regulatory obligations.
  • Serve as the firm’s subjectmatter expert on informationsecurity controls, certifications, and risk posture during client audits, RFPs, and reviews or client engagement terms.
  • Lead complex vendorrisk assessments for highimpact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetrationtest results, cloudsecurity controls, dataprotection, privacy, and retention practices.
  • Develop and maintain the firm’s vendorrisk management framework, including riskscoring methodologies, onboarding workflows, and continuousmonitoring processes.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts, negotiate security requirements, and recommend riskmitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection, documentation, and SME participation across multiple departments.
  • Represent the firm in clientfacing security discussions, including responding to escalated inquiries from corporate counsel, privacy officers, and client security teams.
  • Monitor emerging risks and regulatory developments relevant to the legal industry (e.g., SEC cybersecurity rules, state privacy laws, international datatransfer requirements).
  • Mentor junior analysts and contribute to the professional development of the broader Risk and Compliance team.
  • Drive continuous improvement, identifying opportunities to streamline duediligence workflows, enhance tracking and remediation of client-identified risks, and strengthen the firm’s security posture.

Additional Responsibilities

  • Provide management with periodic reports & briefings on evolving topics within their area of responsibility.
  • Other related projects and duties as assigned by the Director of Information Security.

WHAT YOU'LL BRING

Required

  • 6+ years of experience in information security, vendor risk management, compliance, or legalindustry operations, ideally within an Am Law 200 firm or similarly regulated environment.
  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendorrisk assessments for enterpriselevel technology providers.
  • Strong communication skills, including the ability to brief partners, respond to client security teams, and translate technical concepts for nontechnical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead crossfunctional initiatives in a highpressure environment.
  • Professional certifications such as CTPRA, ISO 27001 Lead Implementer or Lead Auditor and CISSP, CISM, CRISC, or CISA required.
  • Experience with legalindustry technologies (DMS, ediscovery platforms, cloudbased practicemanagement tools) is a plus.

HOW YOU'LL WORK

Extent of Contact

This position requires contact with individuals within the firms as follows:

  • Daily contact with staff from the Firm’s Information Technology, Client Development and Office of the General Counsel teams.
  • Moderate contact with Firm’s attorneys and client representatives.
  • Occasional contact with Firm Management.

This position requires contact with individuals outside the firm as follows:

  • Moderate contact with Firm vendors or potential vendors.
  • Moderate contact with Firm clients

Physical Requirements

  • Must be able to routinely lift and carry event materials and other items up to 10 pounds.
  • Must be able to work at a computer for extensive periods of time.
  • Position requires extensive telephone use.
  • Must be able to lift, squat, kneel and bend.
  • Position requires the ability to visit face-to-face and on the phone with firm lawyers.

Working Conditions and Environment

  • Position is full-time and requires a five-day work week and standard hours as outlined in the Firm policy manual. Additional hours, including weekend and evening hours may be required to perform the essential functions of the job.
  • Must be able to perform essential duties of the position with time constraints and frequent interruptions. 
  • Ability to work well in high pressure environments.
  • 24x7 communication access is required.
  • This position is fully remote. You will be required to come to the office periodically for team meetings or when there is a business or client need.
  • There is potential for travel when needed for team meetings, onsite assessments etc. when there is a business or client need.
  • When working remotely, you must have secure and reliable internet service and a safe, private workspace from which to work.

Baker Botts L.L.P. is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, gender, sex, age, religion, creed, national origin, citizenship, marital status, sexual orientation, disability, medical condition, military and veteran status, gender identity or expression, genetic information, or any other basis protected by federal, state, or local law.