2

Third Party Risk Analyst Remote Jobs (NOW HIRING)

Risk Specialist

Saint Louis, MO · On-site +1

$100K - $130K/yr

Analyze vulnerability assessments and third-party security reviews, considering environmental, procedural, and business risk factors-not just technical severity scores. * Partner with Infrastructure ...

Experience in Third-Party Risk Management (TPRM) and related interagency guidance (e.g., OCC, FDIC ... Strong critical thinking traits, including analytical, problem-solving, and decision-making ...

Partner with analytics teams to build dashboards and actionable insights * Use data to drive ... third-party risk across the enterprise. The Product Manager enables the shift from fragmented ...

Manage and optimize existing strategies effectively controlling risks due to first party and third ... Coordinate the Risk Analytics team's tasks and ensure adherence to established turnaround times and ...

Manage and optimize existing strategies effectively controlling risks due to first party and third ... Coordinate the Risk Analytics team's tasks and ensure adherence to established turnaround times and ...

LRS Consulting is on the hunt for an IT Audit & Risk Analyst to support third party risk management, ITGC testing, vendor assessments, and audit readiness. This role blends IT auditing, process ...

New

$117K - $185K/yr

Gong is seeking an experienced Third Party Risk Manager to join our Governance, Risk, and ... Work from home stipend to help you succeed in a remote environment. The annual salary hiring range ...

Showing results 41-60

Third Party Risk Analyst Remote information

See salary details

$15

$40

$65

How much do third party risk analyst remote jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for third party risk analyst remote in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What does a third party risk analyst do?

A Third Party Risk Analyst is responsible for assessing and managing the risks associated with an organization’s external vendors or partners. They evaluate third parties to ensure they meet security, compliance, and operational standards. This role often involves conducting risk assessments, monitoring vendor performance, and recommending risk mitigation strategies. Working remotely, these analysts use digital tools to collaborate with internal teams and communicate with vendors.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst (Remote), you need a solid understanding of risk management frameworks, vendor due diligence, and compliance regulations, typically supported by a bachelor's degree in a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) platforms, and certifications such as CTPRA or CISA are often required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills for evaluating and managing third-party risks collaboratively. These skills ensure organizations can identify, assess, and mitigate risks posed by external partners, maintaining regulatory compliance and protecting business interests.

How does a third party risk analyst collaborate with other departments in a remote work setting?

As a remote Third Party Risk Analyst, collaboration with departments such as procurement, legal, IT security, and compliance is typically achieved through regular virtual meetings and shared documentation platforms. You’ll often coordinate with these teams to assess vendor risks, review contracts, and ensure compliance with company policies. Clear communication and proactive follow-ups are key, as you may be managing multiple projects and stakeholders simultaneously. Building strong remote relationships helps streamline risk assessment processes and ensures effective risk mitigation strategies.

What is the difference between Third Party Risk Analyst Remote vs Vendor Risk Analyst?

AspectThird Party Risk Analyst RemoteVendor Risk Analyst
CredentialsCertifications like CRISC, CISA often preferredSimilar certifications, often including CRISC, CISA
Work EnvironmentRemote, primarily online collaborationRemote or on-site, depending on company policy
Industry UsageFinancial, healthcare, technology sectorsFinancial, retail, manufacturing sectors
Job FocusAssessing third-party risks and complianceEvaluating vendor security and operational risks

The main difference is that a Third Party Risk Analyst Remote focuses on assessing risks posed by third-party entities across various industries, often working remotely. A Vendor Risk Analyst typically concentrates on evaluating specific vendors' security and operational risks, which may involve more direct vendor interactions. Both roles require similar certifications and work environments, but their scope and focus differ slightly.

More about Third Party Risk Analyst Remote jobs

What cities are hiring for Third Party Risk Analyst Remote jobs?

Cities with the most Third Party Risk Analyst Remote job openings:

What are the most commonly searched types of Third Party Risk Analyst jobs?

The most popular types of Third Party Risk Analyst jobs are:

What states have the most Third Party Risk Analyst Remote jobs?

States with the most job openings for Third Party Risk Analyst Remote jobs include:

Infographic showing various Third Party Risk Analyst Remote job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $84,210 per year, or $40.5 per hour.

Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton

Remote

$104K - $166K/yr

Full-time

Posted 22 days ago


Peraton rating

8.3

Company rating: 8.3 out of 10

Based on 56 frontline employees who took The Breakroom Quiz

52nd of 226 rated it services


Job description

Responsibilities
**Position Is Contingent Upon Award**
Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement - policy, control testing, and POA&M management - together with third-party security risk management and the data protection and insider threat program for the California health benefit exchange and the CalHEERS eligibility and enrollment system.
You will work with Covered California security leadership and privacy stakeholders, vendors and their security teams, our on-site security engineering and incident response colleagues, and the independent assessment team, for whom you are the operational-side evidence provider. The goal is that the program's compliance posture against NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075 is real, evidenced, and audit-ready on any given day rather than reconstructed once a year.
What You Will Do In This Role:
  • Own policy and control documentation. Author and maintain security policies, procedures, standards, plans, and control documentation for the environment.
  • Test controls and close POA&Ms. Perform control testing and gap analysis against NIST SP 800-53 Rev. 5, document deficiencies, and manage POA&Ms through remediation and verified closure.
  • Keep the program audit-ready. Maintain the control evidence library and GRC platform records, control mappings, and compliance reporting; support the annual independent assessment as the operational-side evidence provider, without acting as an assessor.
  • Run third-party security risk management. Conduct vendor security due diligence and assessments, contract and control reviews, continuous monitoring, and risk reporting.
  • Lead data protection. Discover and catalog confidential data, define and apply the data classification scheme, and implement protective controls including DLP, encryption, and access controls.
  • Support the insider threat program. Contribute to insider threat use cases, monitoring, and escalation procedures in coordination with privacy, HR, and legal stakeholders.
  • Carry the regulated-data obligations. Support IRS Publication 1075 and ARC-AMPE compliance activities and the privacy obligations of the contract's Privacy Addendum; participate in the on-call incident response rotation.

Qualifications
Required:
  • Bachelor's degree in information systems, cybersecurity, or business with a security concentration. In lieu of a degree, an additional 4 years of relevant experience will be considered.
  • 8+ years of experience in security governance, risk, and compliance, third-party risk management, or data protection.
  • Active CISA or CGRC certification.
  • Demonstrated experience performing control assessment and gap analysis against NIST SP 800-53 Rev. 5, and managing the POA&M lifecycle from deficiency identification through closure.
  • Demonstrated third-party and vendor security risk management experience, including questionnaire-based assessment frameworks such as SIG or CAIQ, contract and control review, and continuous monitoring.
  • Hands-on experience with data classification and data-flow mapping, and with an enterprise DLP platform such as Microsoft Purview, Netskope, or Forcepoint.
  • Precise compliance writing ability - policies, control narratives, and deficiency write-ups that withstand external review - and working knowledge of an enterprise GRC platform.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.

Desired:
  • CIPP/US certification. CRISC, CIPT, or CISM are also valued.
  • Experience with ARC-AMPE security and privacy requirements.
  • Experience with IRS Publication 1075 and FTI safeguarding, including participation in a Safeguard Review.
  • Working knowledge of HIPAA/HITECH and the California Consumer Privacy Act.
  • Experience with CMS requirements and Authority to Connect support, including Security Assessment Workbooks (SAWs), security assessment reports, and control evidence packages.
  • Experience in California state government compliance environments.
  • Experience with health benefit exchange or Medicaid eligibility systems.
  • Experience with encryption and key management concepts and with insider threat program design.

Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.
Target Salary Range
$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

What Peraton employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Peraton logo

About Peraton

Sourced by ZipRecruiter

At Peraton, we re at the forefront of delivering the next big thing every day. We re the partner of choice to help solve some of the world s most daunting challenges, delivering bold, new solutions to keep people around the world safer and more secure.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Herndon, VA, US

Year founded

2017