2

Third Party Risk Analyst Remote Jobs in Boston, MA

Contribute to vendor and third-party risk management, ensuring Reco's supply chain meets our own security bar. Identity and Access Management * Partner with IT and Engineering to maintain role-based ...

Insurance Senior Analyst

Boston, MA · On-site +1

$70K - $90K/yr

Key Duties and Responsibilities Underwriting and Risk Management Collect exposure information ... Maintain insurance exposure databases, prepare analytical reports including cost of risk, assist ...

Director, Benefits

Waltham, MA · Remote

$140K - $196K/yr

... risk and cost. This position combines global strategic oversight with regional operational ... Oversee relationships with brokers, consultants, third-party administrators, carriers, and other ...

... Remote Skills / Qualifications Required: * 2 - 5 years of GIS project experience * BA/BS in GIS ... Experience with FEMA's Risk MAP and National Flood Insurance Program (strongly preferred)

Showing results 41-60

Third Party Risk Analyst Remote information

See Boston, MA salary details

$16

$43

$71

How much do third party risk analyst remote jobs pay per hour?

As of Aug 15, 2026, the average hourly pay for third party risk analyst remote in Boston, MA is $43.98, according to ZipRecruiter salary data. Most workers in this role earn between $32.40 and $53.56 per hour, depending on experience, location, and employer.

What does a third party risk analyst do?

A Third Party Risk Analyst is responsible for assessing and managing the risks associated with an organization’s external vendors or partners. They evaluate third parties to ensure they meet security, compliance, and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and recommending risk mitigation strategies. Working remotely, these analysts use digital tools to collaborate with internal teams and communicate with vendors.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst (Remote), you need a solid understanding of risk management frameworks, vendor due diligence, and compliance regulations, typically supported by a bachelor's degree in a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) platforms, and certifications such as CTPRA or CISA are often required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for evaluating and managing third-party risks collaboratively. These skills ensure organizations can identify, assess, and mitigate risks posed by external partners, maintaining regulatory compliance and protecting business interests.

How does a third party risk analyst collaborate with other departments in a remote work setting?

As a remote Third Party Risk Analyst, collaboration with departments such as procurement, legal, IT security, and compliance is typically achieved through regular virtual meetings and shared documentation platforms. You’ll often coordinate with these teams to assess vendor risks, review contracts, and ensure compliance with company policies. Clear communication and proactive follow-ups are key, as you may be managing multiple projects and stakeholders simultaneously. Building strong remote relationships helps streamline risk assessment processes and ensures effective risk mitigation strategies.

What is the difference between Third Party Risk Analyst Remote vs Vendor Risk Analyst?

AspectThird Party Risk Analyst RemoteVendor Risk Analyst
CredentialsCertifications like CRISC, CISA often preferredSimilar certifications, often including CRISC, CISA
Work EnvironmentRemote, primarily online collaborationRemote or on-site, depending on company policy
Industry UsageFinancial, healthcare, technology sectorsFinancial, retail, manufacturing sectors
Job FocusAssessing third-party risks and complianceEvaluating vendor security and operational risks

The main difference is that a Third Party Risk Analyst Remote focuses on assessing risks posed by third-party entities across various industries, often working remotely. A Vendor Risk Analyst typically concentrates on evaluating specific vendors' security and operational risks, which may involve more direct vendor interactions. Both roles require similar certifications and work environments, but their scope and focus differ slightly.

What are the most commonly searched types of Third Party Risk Analyst jobs in Boston, MA?

The most popular types of Third Party Risk Analyst jobs in Boston, MA are:

What are popular job titles related to Third Party Risk Analyst Remote jobs in Boston, MA?

For Third Party Risk Analyst Remote jobs in Boston, MA, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Analyst Remote jobs in Boston, MA look for?

The top searched job categories for Third Party Risk Analyst Remote jobs in Boston, MA are:

Infographic showing various Third Party Risk Analyst Remote job openings in Boston, MA as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 9% Part Time, and 4% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution, with an average salary of $91,485 per year, or $44 per hour.

Security & Trust Manager

Reco

Boston, MA • On-site, Remote

Full-time

Posted 9 days ago


Job description

Description
We're looking for a Security and Trust Manager to own Reco's customer-facing security and compliance program while also supporting our internal security operations. This is a high-impact individual contributor role sitting at the intersection of customer trust, GRC, enterprise security, and identity and access management.
On the external side, you'll be the face of Reco security to enterprise customers: owning security questionnaires, audits, and compliance assurance that unblock revenue and build lasting trust. On the internal side, you'll assist enterprise security programs and identity and access controls that protect Reco's own environment. This dual mandate puts you in a unique position: you'll use Reco's own platform to manage the SaaS access risks you're simultaneously explaining to customers.
Responsibilities
Customer Trust and GRC
  • Own Reco's customer trust operations end-to-end: intake, triage, prioritization, and completion of security questionnaires, vendor risk assessments, and RFIs.
  • Serve as the primary security point of contact in enterprise sales cycles; removing security blockers and accelerating deal velocity.
  • Build and maintain Reco's Trust Center and compliance artifacts: SOC 2 evidence, ISO 27001 documentation, security whitepapers, and customer-facing one-pagers.
  • Lead customer-facing security meetings, audits, and diligence calls with technical depth and credibility.
  • Manage and mature Reco's GRC program: frameworks, risk assessments, control monitoring, and audit readiness across SOC 2, ISO 27001, NIST CSF, and applicable regulations.
  • Partner with Product, Engineering, and Legal to translate customer security requirements into internal roadmap inputs.
  • Respond to questions across compliance frameworks including SOC 2, ISO 27001, HIPAA, GDPR, and sector-specific requirements.
  • Drive process improvements: build reusable response libraries, automate questionnaire workflows, and improve SLA performance.

Enterprise Security
  • Support Reco's internal enterprise security posture: endpoint security, MDM, security awareness training, and security policy management.
  • Maintain and improve Reco's internal security policies, standards, and procedures.
  • Contribute to vendor and third-party risk management, ensuring Reco's supply chain meets our own security bar.

Identity and Access Management
  • Partner with IT and Engineering to maintain role-based access controls, audit trails, and access certification processes.
  • Use Reco's own platform to discover, monitor, and remediate identity and SaaS access risks internally.

Requirements
  • 5+ years in security trust, GRC, compliance, or customer-facing security roles at SaaS or cloud companies.
  • Hands-on experience completing enterprise security questionnaires, RFIs, and leading customer security reviews.
  • Working knowledge of SOC 2, ISO 27001, HIPAA, and common compliance frameworks.
  • Familiarity with AI governance frameworks (ISO 42001, EU AI Act).
  • Experience with IAM tools and concepts: SSO (Okta, Azure AD, or equivalent), SCIM provisioning, access reviews, and privilege management.
  • Strong technical foundation: cloud security (AWS, GCP, or Azure), application security, data protection, and access controls.
  • Excellent written and verbal communication -- able to translate complex security topics for both technical and executive audiences.
  • Experience with GRC and trust automation tools (Vanta, Drata, SafeBase, Conveyor, or similar).
  • Collaborative, cross-functional mindset -- comfortable working alongside Sales, Legal, Engineering, and Product.