2

Third Party Risk Analyst Remote Jobs in Virginia

GRC Team Lead

Richmond, VA · On-site +1

  • Medical

  • Retirement

  • PTO

Third-Party Risk Management * Own and enhance the Third-Party Risk Management (TPRM) framework ... Strong problem-solving, analytical, and critical-thinking skills, with the proven ability to set ...

Chargemaster Analyst - Remote!

Arlington, VA · On-site +1

  • Medical

  • Dental

  • Vision

  • Retirement

Position Title Chargemaster Analyst - Remote! Summary Join our team in person, hybrid schedule or ... Exhibits confidence, appropriate risk taking and achievement of high standards * Positive, can-do ...

Triage & Assessment Analyst (REMOTE)

Chantilly, VA · Remote

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The position is remote. We offer competitive compensation and an extraordinary benefits package ... Develop and maintain a documented risk register for each assessed application, clearly articulating ...

Triage & Assessment Analyst (REMOTE)

Chantilly, VA · On-site +1

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The position is remote. We offer competitive compensation and an extraordinary benefits package ... Develop and maintain a documented risk register for each assessed application, clearly articulating ...

Triage & Assessment Analyst (REMOTE)

Chantilly, VA · Remote

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The position is remote. We offer competitive compensation and an extraordinary benefits package ... Develop and maintain a documented risk register for each assessed application, clearly articulating ...

Assessment Analyst

Leesburg, VA · On-site +1

$87K - $95K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling ...

next page

Showing results 1-20

Third Party Risk Analyst Remote information

What does a third party risk analyst do?

A Third Party Risk Analyst is responsible for assessing and managing the risks associated with an organization’s external vendors or partners. They evaluate third parties to ensure they meet security, compliance, and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and recommending risk mitigation strategies. Working remotely, these analysts use digital tools to collaborate with internal teams and communicate with vendors.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst (Remote), you need a solid understanding of risk management frameworks, vendor due diligence, and compliance regulations, typically supported by a bachelor's degree in a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) platforms, and certifications such as CTPRA or CISA are often required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for evaluating and managing third-party risks collaboratively. These skills ensure organizations can identify, assess, and mitigate risks posed by external partners, maintaining regulatory compliance and protecting business interests.

How does a third party risk analyst collaborate with other departments in a remote work setting?

As a remote Third Party Risk Analyst, collaboration with departments such as procurement, legal, IT security, and compliance is typically achieved through regular virtual meetings and shared documentation platforms. You’ll often coordinate with these teams to assess vendor risks, review contracts, and ensure compliance with company policies. Clear communication and proactive follow-ups are key, as you may be managing multiple projects and stakeholders simultaneously. Building strong remote relationships helps streamline risk assessment processes and ensures effective risk mitigation strategies.

What is the difference between Third Party Risk Analyst Remote vs Vendor Risk Analyst?

AspectThird Party Risk Analyst RemoteVendor Risk Analyst
CredentialsCertifications like CRISC, CISA often preferredSimilar certifications, often including CRISC, CISA
Work EnvironmentRemote, primarily online collaborationRemote or on-site, depending on company policy
Industry UsageFinancial, healthcare, technology sectorsFinancial, retail, manufacturing sectors
Job FocusAssessing third-party risks and complianceEvaluating vendor security and operational risks

The main difference is that a Third Party Risk Analyst Remote focuses on assessing risks posed by third-party entities across various industries, often working remotely. A Vendor Risk Analyst typically concentrates on evaluating specific vendors' security and operational risks, which may involve more direct vendor interactions. Both roles require similar certifications and work environments, but their scope and focus differ slightly.

What are the most commonly searched types of Third Party Risk Analyst jobs in Virginia?

The most popular types of Third Party Risk Analyst jobs in Virginia are:

What are popular job titles related to Third Party Risk Analyst Remote jobs in Virginia?

For Third Party Risk Analyst Remote jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Analyst Remote jobs in Virginia look for?

The top searched job categories for Third Party Risk Analyst Remote jobs in Virginia are:

What cities in Virginia are hiring for Third Party Risk Analyst Remote jobs?

Cities in Virginia with the most Third Party Risk Analyst Remote job openings:

Infographic showing various Third Party Risk Analyst Remote job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 16% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Program Manager - Third Party Risk Management

Sentara Healthcare

Norfolk, VA • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

This job post has expired 1 day ago. Applications are no longer accepted.


Sentara Health rating

6.7

Company rating: 6.7 out of 10

Based on 412 frontline employees who took The Breakroom Quiz

531st of 888 rated healthcare providers


Job description

City/State
Norfolk, VA
Work Shift
First (Days)
Overview:
Overview
The Third-Party Risk Program Manager is responsible for the end-to-end management of the organization's third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle - from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding - ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness
Key Responsibilities
Program Management
  • Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle

  • Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders

  • Identify process gaps and drive continuous improvement of program workflows

  • Be a part of the team and support the execution of the program

Vendor Management
  • Serve as the primary point of contact for third-party vendors throughout the assessment and management process

  • Coordinate with vendors to gather required documentation, evidence, and remediation plans

  • Track vendor responsiveness and escalate delays or non-compliance issues appropriately

Risk Assessments (OneTrust)
  • Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion

  • Analyze assessment results to identify risk levels, gaps, and required remediation actions

  • Maintain accurate, up-to-date vendor and assessment records within OneTrust

  • Generate reports and dashboards from OneTrust to support program reporting and audits

Documentation & Compliance
  • Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current

  • Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)

  • Support internal and external audits by providing timely and accurate documentation

Cross-Functional Collaboration
  • Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage

  • Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike

  • Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward

Education
  • Bachelor Level Degree (Preferred)
  • 5+ years relevant experience may be accepted in lieu of degree

Certification/Licensure
  • Certification in risk, or compliance (e.g., CTPRP, CRISC) preferred

Experience
Required
  • Bachelor's degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry
  • 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry without a Bachelor's degree preferred.

  • Hands-on experience with OneTrust or similar GRC/risk management platforms

  • Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements

  • Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously

  • Excellent written and verbal communication skills, with experience working cross functionally

Preferred
  • Certification in risk, or compliance (e.g., CTPRP, CRISC)

  • Experience with vendor contract review or working alongside Legal/Procurement

  • Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)

We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:106,080.00-176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.
Benefits: Caring For Your Family and Your Career
Medical, Dental, Vision plans
• Adoption, Fertility and Surrogacy Reimbursement up to 10,000
• Paid Time Off and Sick Leave
• Paid Parental & Family Caregiver Leave
• Emergency Backup Care
• Long-Term, Short-Term Disability, and Critical Illness plans
• Life Insurance
• 401k/403B with Employer Match
• Tuition Assistance - 5,250/year and discounted educational opportunities through Guild Education
• Student Debt Pay Down - 10,000
• Pet Insurance
• Legal Resources Plan
• Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.
Sentara Health is an equal opportunity employer and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.
In support of our mission "to improve health every day," this is a tobacco-free environment.
For positions that are available as remote work, Sentara Health employs associates in the following states:
Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.

What Sentara Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom