1

Third Party Risk Analyst Jobs in Arizona (NOW HIRING)

Senior GRC Analyst

Phoenix, AZ · On-site

$90 - $130/hr

The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including delivery of ... Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying ...

Credit Risk Analyst Seniors use quantitative methods to identify credit risk, develop and deliver ... Analyze internal and external scores/data for use in identifying first party fraud. * Apply ...

Not required.## About this roleThe AI Governance & Risk Analyst operates the Managed AI program for our clients on a recurring cadence. You'll own AI policy maintenance, vendor risk monitoring, DPA ...

... and third-party administrators. This role exercises independent judgment in reviewing claims ... Risk Analysis & Decision Support * Analyze claims, loss run, exposure, and insurance-related ...

... and third-party administrators. This role exercises independent judgment in reviewing claims ... Risk Analysis & Decision Support * Analyze claims, loss run, exposure, and insurance-related ...

... and third-party administrators. This role exercises independent judgment in reviewing claims ... Risk Analysis & Decision Support * Analyze claims, loss run, exposure, and insurance-related ...

Join Swift Transportation as a Leader on the Power Only Risk team for Logistics! Pay Range: $63,700 ... third-party carriers. * Proficient in data analysis, reporting, and investigative research ...

Power Only Risk Leader

Phoenix, AZ · On-site

$63K - $82K/yr

Join Swift Transportation as a Leader on the Power Only Risk team for Logistics! Pay Range: $63,700 ... third-party carriers. * Proficient in data analysis, reporting, and investigative research ...

Power Only Risk Leader

Phoenix, AZ · On-site

$63K - $82K/yr

Join Swift Transportation as a Leader on the Power Only Risk team for Logistics! Pay Range: $63,700 ... third-party carriers. * Proficient in data analysis, reporting, and investigative research ...

The successful candidate will leverage strong analytical, risk management, and communication skills ... Third-Party Technology Risk Develops methodologies, models, and frameworks to quantify technology ...

We are hiring for an exciting opportunity as a Fraud Risk Analyst within U.S. Bancorp ... This role supports rule strategy development across key areas including First Party Fraud, Third ...

You will own operational and compliance risk inherent in credit strategy. Additionally, you will ... Leads the analysis of internal and external scores/data for use in identifying first party fraud.

... and advanced analytics, this leader will help strengthen our technology risk and control ... Third-Party Risk Management, Disaster Recovery, and validation of Oracle Cloud Fusion and Risk ...

... Third-party technology dependencies AI and emerging technology risks Oversees development of risk scenarios, loss-event libraries, threat intelligence inputs, and control effectiveness analyses to ...

Showing results 21-40

Third Party Risk Analyst information

See Arizona salary details

$14

$37

$61

How much do third party risk analyst jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for third party risk analyst in Arizona is $37.73, according to ZipRecruiter salary data. Most workers in this role earn between $27.79 and $45.91 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.

How does a third party risk analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

How much does a third party risk analyst make?

A third party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries. The role often requires strong analytical skills and knowledge of risk management tools.

Is third party risk analyst a good career?

A third party risk analyst evaluates and manages risks associated with external vendors and partners, often requiring knowledge of compliance, cybersecurity, and risk management tools. The role offers opportunities in industries such as finance, healthcare, and technology, with a growing demand due to increasing regulatory requirements and supply chain complexities.

What does a third party risk analyst do?

A third party risk analyst evaluates the risks associated with an organization's external vendors, suppliers, and partners. They assess compliance, security, and operational risks using tools like risk management frameworks and may conduct audits or reviews to ensure third-party adherence to company standards.

What are popular job titles related to Third Party Risk Analyst jobs in Arizona?

For Third Party Risk Analyst jobs in Arizona, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Analyst jobs in Arizona look for?

The top searched job categories for Third Party Risk Analyst jobs in Arizona are:

Infographic showing various Third Party Risk Analyst job openings in Arizona as of August 2026, with employment types broken down into 100% Full Time. Highlights an 64% In-person, 18% Hybrid, and 18% Remote job distribution, with an average salary of $78,474 per year, or $37.7 per hour.

Senior GRC Analyst

Sky Mavis

Phoenix, AZ • On-site

$90 - $130/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 19 days ago


Key responsibilities

  • Assumes operational ownership of the Third‑Party Risk Management process to assess security practices, compliance, and potential risks of external vendors.

  • Manages the Human Risk Management program by delivering security awareness education, executing phishing simulations, and maintaining security awareness platforms.

  • Documents, communicates, and tracks findings, issues, and remediation actions related to third-party and human risk assessments.


Job description

About Us

Clayco is a full‑service, turnkey real‑estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $8.1 billion in revenue for 2025, Clayco specializes in the "art and science of building," providing fast track, efficient solutions for mission critical, industrial, life sciences, power & energy, aviation, commercial, institutional, residential and sports & entertainment related building projects.

The Role We Want You For

Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third‑Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all Human and Third‑Party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. This role will assume ownership of the Third‑Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third‑party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and 3rd Party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including delivery of comprehensive security awareness education, the end‑to‑end execution of phishing simulation programs, and the technical maintenance and life‑cycle management of security awareness platforms. Beyond simple training, the position focuses on HRM, using data‑driven insights to identify high‑risk user groups and implementing targeted interventions to proactively mitigate human‑centric threats to cultivate a security‑first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.

The Specifics of the Role
  • Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers
  • Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations
  • Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues
  • Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service‑level agreements (SLAs), and AI governance
  • Documents and communicates all relevant findings and recommendations to stakeholders
  • Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress
  • Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery
  • Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real‑world attacks
  • Develops engaging, simple materials—such as infographics, newsletters, and videos—that translate complex technical risks into layman's terms
  • Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client‑side functionality (i.e., "Report Phish" button)
  • Plans, coordinates, and executes activities for Cybersecurity month
  • Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture
  • Tracks Key Risk Indicators (KRI’s) such as actual phishing click‑through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership
Requirements
  • 6‑8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields
  • 3‑4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management
  • Bachelor's degree in Information Technology or related field, or equivalent experience
  • Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third‑party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role)
  • Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps
  • Strong knowledge of Regulations, Frameworks, and Standards such as NIST 800‑171/CSF/RMF, ISO27001, CIS Critical Security Controls, etc.
  • Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure
  • Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation
  • Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
  • Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations
  • Operate with strong integrity with ability to manage projects of a confidential nature
  • Ability to translate technical or abstract concepts into a narrative that is easily understood
  • Ability to thrive in fast‑paced environment.

This position is classified as a safety‑sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing.

Benefits
  • Discretionary Annual Bonus: Subject to company and individual performance.
  • Comprehensive Benefits Package Including: Medical, dental and vision plans, 401(k), generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation
  • The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.
#J-18808-Ljbffr