... highly analytical role that ensures all Human and Third-Party risk to Clayco is identified ... This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details ...
... highly analytical role that ensures all Human and Third-Party risk to Clayco is identified ... This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details ...
Senior GRC Analyst
Phoenix, AZ · On-site
Responsibilities : • Assumes operational ownership of the 3rd Party Vendor Risk Management ... Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk ...
Senior GRC Analyst
Phoenix, AZ · On-site
Responsibilities : • Assumes operational ownership of the 3rd Party Vendor Risk Management ... Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk ...
Perform security and risk assessments for third-party SaaS providers . * Evaluate security evidence and conduct technical interviews with vendor engineering teams . * Assess control design and ...
Perform security and risk assessments for third-party SaaS providers . * Evaluate security evidence and conduct technical interviews with vendor engineering teams . * Assess control design and ...
... third-party risk management, and training. * Build standards for the product team, such as ... Principal Product Operations and Risk Analyst * 10+ years working in risk management for B2B and ...
... third-party risk management, and training. * Build standards for the product team, such as ... Principal Product Operations and Risk Analyst * 10+ years working in risk management for B2B and ...
Demonstrated experience in Third-Party Risk Management, Vendor Management, or related oversight ... Proficiency in Excel and financial / operational data analysis. * Excellent written and verbal ...
New
Demonstrated experience in Third-Party Risk Management, Vendor Management, or related oversight ... Proficiency in Excel and financial / operational data analysis. * Excellent written and verbal ...
New
The Program Lead for Third Party Risk and Resilience Management establishes and maintains a robust governance framework for all Offshore Development Centers (ODCs), bridging R&D innovation ...
The Program Lead for Third Party Risk and Resilience Management establishes and maintains a robust governance framework for all Offshore Development Centers (ODCs), bridging R&D innovation ...
The Program Lead for Third Party Risk and Resilience Management establishes and maintains a robust governance framework for all Offshore Development Centers (ODCs), bridging R&D innovation ...
The Program Lead for Third Party Risk and Resilience Management establishes and maintains a robust governance framework for all Offshore Development Centers (ODCs), bridging R&D innovation ...
IT Security Risk Analyst(32545)
Phoenix, AZ · On-site
... IT Security Risk Analyst to join our customer in Phoenix Arizona. This is an ONSITE position ... third-party applications; and other technology services within the department's Infrastructure ...
IT Security Risk Analyst(32545)
Phoenix, AZ · On-site
... IT Security Risk Analyst to join our customer in Phoenix Arizona. This is an ONSITE position ... third-party applications; and other technology services within the department's Infrastructure ...
Third-Party Procurement & Sourcing Senior Manager
$150K - $151K/yr
... Third-Party Risk & Controls, IT Business Operations, Legal, and other stakeholders to support ... Monitor and analyze market trends and stay up to date with industry trends and best practices.
Third-Party Procurement & Sourcing Senior Manager
$150K - $151K/yr
... Third-Party Risk & Controls, IT Business Operations, Legal, and other stakeholders to support ... Monitor and analyze market trends and stay up to date with industry trends and best practices.
Demonstrated experience in Third-Party Risk Management, Vendor Management, or related oversight ... Advanced data analytics skills; Power BI expertise strongly preferred (dashboard development, data ...
New
Demonstrated experience in Third-Party Risk Management, Vendor Management, or related oversight ... Advanced data analytics skills; Power BI expertise strongly preferred (dashboard development, data ...
New
Third-Party Procurement & Sourcing Senior Manager
Phoenix, AZ · On-site
$150K - $151K/yr
... Third-Party Risk & Controls, IT Business Operations, Legal, and other stakeholders to support ... Monitor and analyze market trends and stay up to date with industry trends and best practices.
Third-Party Procurement & Sourcing Senior Manager
Phoenix, AZ · On-site
$150K - $151K/yr
... Third-Party Risk & Controls, IT Business Operations, Legal, and other stakeholders to support ... Monitor and analyze market trends and stay up to date with industry trends and best practices.
Demonstrated experience in Third-Party Risk Management, Vendor Management, or related oversight ... Advanced data analytics skills; Power BI expertise strongly preferred (dashboard development, data ...
Demonstrated experience in Third-Party Risk Management, Vendor Management, or related oversight ... Advanced data analytics skills; Power BI expertise strongly preferred (dashboard development, data ...
Strong analytical and problem-solving skills with attention to detail * Ability to explain ... Third-Party Risk Management) * Familiarity with the eDiscovery lifecycle and litigation holds.
Strong analytical and problem-solving skills with attention to detail * Ability to explain ... Third-Party Risk Management) * Familiarity with the eDiscovery lifecycle and litigation holds.
Raytheon is hiring a Third-Party Logistics Lead to support the Third-Party Logistics operated ... Data Analytics experience * Six Sigma/Core, or equivalent experience, in eliminating waste and ...
Raytheon is hiring a Third-Party Logistics Lead to support the Third-Party Logistics operated ... Data Analytics experience * Six Sigma/Core, or equivalent experience, in eliminating waste and ...
Third-Party Logistics Lead
Marana, AZ · On-site
Raytheon is hiring a Third-Party Logistics Lead to support the Third-Party Logistics operated ... Data Analytics experience * Six Sigma/Core, or equivalent experience, in eliminating waste and ...
Third-Party Logistics Lead
Marana, AZ · On-site
Raytheon is hiring a Third-Party Logistics Lead to support the Third-Party Logistics operated ... Data Analytics experience * Six Sigma/Core, or equivalent experience, in eliminating waste and ...
Risk Analyst (Belgium)
Phoenix, AZ · On-site
We are seeking a skilled Risk Analyst , you will identify, assess, and manage risks across defense and infrastructure programs supporting NATO and government clients. You will help ensure informed ...
Risk Analyst (Belgium)
Phoenix, AZ · On-site
We are seeking a skilled Risk Analyst , you will identify, assess, and manage risks across defense and infrastructure programs supporting NATO and government clients. You will help ensure informed ...
Model Risk Analyst
Phoenix, AZ · On-site
Model Risk Analyst Location: CityScape What you'll do: Western Alliance Bank (WAL) is seeking a Model Risk Analyst to join its Model Risk Management Group. Being part of the Model Risk team will put ...
Model Risk Analyst
Phoenix, AZ · On-site
Model Risk Analyst Location: CityScape What you'll do: Western Alliance Bank (WAL) is seeking a Model Risk Analyst to join its Model Risk Management Group. Being part of the Model Risk team will put ...
Model Risk Analyst Location: CityScape What you'll do: Western Alliance Bank (WAL) is seeking a Model Risk Analyst to join its Model Risk Management Group. Being part of the Model Risk team will put ...
Model Risk Analyst Location: CityScape What you'll do: Western Alliance Bank (WAL) is seeking a Model Risk Analyst to join its Model Risk Management Group. Being part of the Model Risk team will put ...
Senior Consultant - ServiceNow
Tempe, AZ · Remote
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Senior Consultant - ServiceNow
Tempe, AZ · Remote
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Consultant - ServiceNow
Tempe, AZ · Remote
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Consultant - ServiceNow
Tempe, AZ · Remote
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...
Third Party Risk Analyst information
See Arizona salary details
$14.34 - $18.61
3% of jobs
$18.61 - $22.89
7% of jobs
$22.89 - $27.17
12% of jobs
$28.01 is the 25th percentile. Wages below this are outliers.
$27.17 - $31.44
15% of jobs
$31.44 - $35.72
13% of jobs
The median wage is $35.86 / hr.
$35.72 - $40
16% of jobs
$40 - $44.27
8% of jobs
$44.81 is the 75th percentile. Wages above this are outliers.
$44.27 - $48.55
11% of jobs
$48.55 - $52.83
6% of jobs
$52.83 - $57.10
6% of jobs
$57.10 - $61.38
3% of jobs
$14
$37
$61
How much do third party risk analyst jobs pay per hour?
How does a Third Party Risk Analyst typically collaborate with other departments to manage vendor risks?
What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?
| Aspect | Third Party Risk Analyst | Vendor Risk Analyst |
|---|---|---|
| Certifications | Certifications like CRISC, CISA often preferred | Similar certifications, often the same as Third Party Risk Analyst |
| Work Environment | Financial institutions, corporations managing third-party relationships | Organizations assessing vendor security, compliance, and performance |
| Industry Usage | Common in finance, healthcare, and tech sectors | Primarily in procurement, supply chain, and IT sectors |
The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.
What does a Third Party Risk Analyst do?
What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst, and why are they important?

Other
Medical, Dental, Vision, Life, Retirement, PTO
Posted 25 days ago
Job description
About Us
Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $8.1 billion in revenue for 2025, Clayco specializes in the "art and science of building," providing fast track, efficient solutions for mission critical, industrial, life sciences, power & energy, aviation, commercial, institutional, residential and sports & entertainment related building projects.
The Role We Want You For
Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a Risk focused, highly analytical role that ensures all Human and Third-Party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third-party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non-compliance with legal and regulatory requirements.. Additional contribution will be expected for internal assessments and 3rd Party audits to gather and submit discovery and transactional responses and artifacts.The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end-to-end execution of phishing simulation programs, and the technical maintenance and life-cycle management of security awareness platforms. Beyond simple training, the position focuses on Human Risk Management (HRM), using data-driven insights to identify high-risk user groups and implementing targeted interventions to proactively mitigate human-centric threats to cultivate a security-first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.
The Specifics of the Role
- Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers
- Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations
- Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues
- Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service-level agreements (SLAs), and AI governance
- Documents and communicates all relevant findings and recommendations to stakeholders
- Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress
- Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery
- Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real-world attacks
- Develops engaging, simple materials—such as infographics, newsletters, and videos—that translate complex technical risks into layman's terms
- Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client-side functionality (i.e., "Report Phish" button)
- Plans, coordinates, and executes activities for Cybersecurity month
- Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture
- Tracks Key Risk Indicators (KRI’s) such as actual phishing click-through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership
Requirements
- 6-8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields
- 3-4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management
- Bachelor's degree in Information Technology or related field, or equivalent experience
- Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third-party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role)
- Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps
- Strong knowledge of Regulations, Frameworks, and Standards such as NIST 800-171/CSF/RMF, ISO27001, CIS Critical Security Controls, etc.
- Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure
- Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation
- Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
- Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations
- Operate with strong integrity with ability to manage projects of a confidential nature
- Ability to translate technical or abstract concepts into a narrative that is easily understood
- Ability to thrive in fast-paced environment.
Some Things You Should Know.
- No other builder can offer the collaborative design-build approach that Clayco does.
- We work on creative, complex, award-winning, high-profile jobs.
- The pace is fast!
- This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing.
Why Clayco?
- 2025 Best Places to Work – St. Louis Business Journal, Los Angeles Business Journal, and Phoenix Business Journal.
- 2025 ENR Top 400 – Top Data Center Contractor (Top 3).
- 2025 ENR Top 100 Design-Build Firms – Design-Build Contractor (Top 5).
- 2025 ENR Top 100 Green Contractors – Green Contractor (Top 3).
Benefits
- Discretionary Annual Bonus: Subject to company and individual performance.
- Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation
- The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.
About Clayco
Sourced by ZipRecruiter
Industry
Construction
Company size
1,001 - 5,000 Employees
Headquarters location
Chicago, IL, US
Year founded
1984