2

Third Party Risk Analyst Remote Jobs in Spring, TX

Supplier Manager - Sr

Houston, TX · On-site +1

$145.20K - $146.10K/yr

The Senior Supplier Manager partners closely with Procurement, Third Party Risk Management (TPRM ... Analyze supplier data to inform prioritization and strategic decisions. * Contribute to continuous ...

Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ...

Cyber Manager - ServiceNow

Houston, TX · On-site +1

$106K - $143.20K/yr

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

... remote opportunity not to exceed 26 weeks.** As a Business Intelligence Analyst , you will ... Grooming and dress must be appropriate for the position and must not impose a safety risk/hazard to ...

We do not share your information with third parties without your explicit consent, except as ... analyzing resumes, or assessing responses. These tools assist our recruitment team but do not ...

Indirect Tax Senior Analyst (Remote)

Houston, TX · Remote

$110.80K - $111.30K/yr

Your work will help reduce risk, improve data accuracy, and support audits and reporting across ... Strong analytical skills with attention to detail * Proficiency in Excel and ability to work with ...

We do not share your information with third parties without your explicit consent, except as ... analyzing resumes, or assessing responses. These tools assist our recruitment team but do not ...

We do not share your information with third parties without your explicit consent, except as ... analyzing resumes, or assessing responses. These tools assist our recruitment team but do not ...

next page

Showing results 1-20

Third Party Risk Analyst Remote information

See Spring, TX salary details

$13

$36

$58

How much do third party risk analyst remote jobs pay per hour?

As of Jun 1, 2026, the average hourly pay for third party risk analyst remote in Spring, TX is $36.03, according to ZipRecruiter salary data. Most workers in this role earn between $26.54 and $43.85 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst (Remote), and why are they important?

To thrive as a Third Party Risk Analyst (Remote), you need a solid understanding of risk management frameworks, vendor due diligence, and compliance regulations, typically supported by a bachelor's degree in a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) platforms, and certifications such as CTPRA or CISA are often required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for evaluating and managing third-party risks collaboratively. These skills ensure organizations can identify, assess, and mitigate risks posed by external partners, maintaining regulatory compliance and protecting business interests.

How does a Third Party Risk Analyst collaborate with other departments in a remote work setting?

As a remote Third Party Risk Analyst, collaboration with departments such as procurement, legal, IT security, and compliance is typically achieved through regular virtual meetings and shared documentation platforms. You’ll often coordinate with these teams to assess vendor risks, review contracts, and ensure compliance with company policies. Clear communication and proactive follow-ups are key, as you may be managing multiple projects and stakeholders simultaneously. Building strong remote relationships helps streamline risk assessment processes and ensures effective risk mitigation strategies.

What does a Third Party Risk Analyst do?

A Third Party Risk Analyst is responsible for assessing and managing the risks associated with an organization’s external vendors or partners. They evaluate third parties to ensure they meet security, compliance, and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and recommending risk mitigation strategies. Working remotely, these analysts use digital tools to collaborate with internal teams and communicate with vendors.

What is the difference between Third Party Risk Analyst Remote vs Vendor Risk Analyst?

AspectThird Party Risk Analyst RemoteVendor Risk Analyst
CredentialsCertifications like CRISC, CISA often preferredSimilar certifications, often including CRISC, CISA
Work EnvironmentRemote, primarily online collaborationRemote or on-site, depending on company policy
Industry UsageFinancial, healthcare, technology sectorsFinancial, retail, manufacturing sectors
Job FocusAssessing third-party risks and complianceEvaluating vendor security and operational risks

The main difference is that a Third Party Risk Analyst Remote focuses on assessing risks posed by third-party entities across various industries, often working remotely. A Vendor Risk Analyst typically concentrates on evaluating specific vendors' security and operational risks, which may involve more direct vendor interactions. Both roles require similar certifications and work environments, but their scope and focus differ slightly.

What are popular job titles related to Third Party Risk Analyst Remote jobs in Spring, TX? For Third Party Risk Analyst Remote jobs in Spring, TX, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst Remote jobs in Spring, TX look for? The top searched job categories for Third Party Risk Analyst Remote jobs in Spring, TX are:
What cities near Spring, TX are hiring for Third Party Risk Analyst Remote jobs? Cities near Spring, TX with the most Third Party Risk Analyst Remote job openings:
CYBERSECURITY RISK ANALYST

CYBERSECURITY RISK ANALYST

CITGO Petroleum Corporation

Houston, TX • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 14 days ago


Citgo rating

6.2

Company rating: 6.2 out of 10

Based on 55 frontline employees who took The Breakroom Quiz

52nd of 74 rated oil and gas companies


Job description

CITGO PETROLEUM CORPORATION

CITGO Petroleum Corporation is a recognized leader in the refining industry and operates under the well-known CITGO brand. CITGO owns and operates three refineries located in Lake Charles, LA.; Lemont, IL.; and Corpus Christi, TX, and wholly and/or jointly owns 38 active terminals, six pipelines and three lubricants blending and packaging plants. With approximately 3,300 employees and a combined crude capacity of approximately 807,000 barrels-per-day (bpd), positions CITGO as one of the best-branded supplier companies in the industry.

At CITGO our people are our most important resource.  Our core values are Safety, Integrity, Respect, Accountability, and Care.

Job Summary

The Cybersecurity Risk Analyst is responsible for identifying, assessing, and managing cybersecurity risks across the organization's IT and OT environments. This role involves conducting comprehensive risk assessments, leading vulnerability management efforts, and ensuring compliance with industry frameworks and regulations. The analyst will work closely with cross-functional teams to design and implement effective risk mitigation strategies, evaluate third-party risks, and support incident response and post-incident evaluations. By leveraging data-driven methods and tracking key performance indicators, the Cybersecurity Risk Analyst plays a critical role in enhancing the organization’s security posture and aligning cybersecurity efforts with business objectives.

Minimum Qualifications

Degree:

  • Bachelor's Degree

The minimum number of years of job related experience required by this job is: 

  • 8 years.

List any specialized training or unique skills required / preferred:

  • In-depth understanding of cybersecurity frameworks such as NIST, ISO 27001, and FAIR.
  • Strong familiarity with IT and OT environments, including cloud platforms, IoT devices, data centers, and software applications.
  • Expertise in vulnerability management processes, penetration testing, and threat modeling.
  • Awareness of emerging technologies and their associated risks.
  • Advanced analytical and problem-solving skills for assessing and prioritizing risks.
  • Effective communication and presentation skills to translate technical risks into business impacts for stakeholders.
  • Proficiency in creating detailed documentation, including risk reports, policies, and compliance evidence.
  • Preferred CISSP, CRISC or other security certifications.
Job Duties

1. Comprehensive Infrastructure Risk Assessment

  • Perform regular risk assessments of IT and OT systems, including networks, cloud platforms, IoT devices, and software, aligned with NIST and CIS Controls.
  • Ensure compliance with security regulations (e.g., GDPR, CCPA, PCI DSS) and manage third-party risks.

2. Vulnerability Management

  • Lead vulnerability scans, penetration tests, and threat modeling.
  • Assess and address vulnerabilities, prioritize patches, and adapt to new threats in collaboration with teams.

3. Risk Reporting & Communication

  • Present risk reports to stakeholders, translating technical details into business impacts.
  • Use methods like FAIR to prioritize risks and provide updates on risks, incidents, and mitigation efforts.

4. Collaboration on Risk Mitigation

  • Partner with governance and IT teams to develop and implement risk mitigation strategies aligned with security and business goals.

5. Incident Response & Risk Evaluation

  • Act as a key incident response team member, offering expertise during security incidents.
  • Conduct post-incident evaluations, identify root causes, and participate in simulations to enhance response readiness.
Job Duties II

6. Cybersecurity Framework & Policy Development

  • Contribute to developing and refining cybersecurity policies, standards, and procedures aligned with risk management strategies.
  • Provide input on creating technical security standards supporting risk management goals.

7. Regulatory Compliance and Audit Support

  • Ensure compliance with regulatory requirements through risk assessments, vulnerability management, and mitigation efforts.
  • Support cybersecurity audits by providing documentation, reports, and evidence of remediation activities.

8. KPI Tracking & Reporting

  • Monitor KPIs to evaluate the effectiveness of risk and vulnerability management programs.
  • Leverage metrics, automated tools, and dashboards to report on security posture and provide real-time insights.

9. Emerging Technology Risk Management

  • Evaluate risks tied to adopting emerging technologies (e.g., AI, blockchain) and integrate them securely.
  • Develop strategies to address risks linked to digital transformation initiatives.

Job duties displayed above are not all-inclusive, site-specific responsibilities may be assigned. 

Here are the incentives we offer:

• Remote Work options available for eligible positions
• Options are department and/or location specific
• 9/80 Work Schedule Option (where applicable)
• Annual Vacation Incentive (40-120 hours of additional pay) for Eligible Employees
• Paid Vacation Time
• Company-Paid Holidays
• Caregiver Leave
• Excellent 401(k) Match
• Pension Plan
• Company-Paid Sick Leave and Long-Term Disability
• Medical, Dental, & Vision Plans; FSA and HSA options
• Company-Paid Life Insurance for Active Employees
• Healthy Rewards Program
• Service Awards Program
• Educational Assistance Plan
• Dependent Children Scholarships
• Reimbursement for Gym Membership
• Employee Discount Programs
• On-site Health Clinic (select locations)
• On-site Cafeteria (select locations)
• On-site Credit Union and ATM (Corporate office only)
• On-site Fitness Center (select locations)


PLEASE NOTE ALL JOBS DO NOT QUALIFY FOR ALL PERKS

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.

Requisition ID - 1129 


What Citgo employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom