1

Third Party Risk Analyst Jobs in Iowa (NOW HIRING)

Third Party Consultant Management: Oversee and manage third-party accounting consultants ... Risk Assessment: Identify and mitigate compliance risks related to wage and labor requirements ...

Third Party Consultant Management: Oversee and manage third-party accounting consultants ... Risk Assessment: Identify and mitigate compliance risks related to wage and labor requirements ...

Collaborate with UPH Legal, the Third-Party Administrator, commercial insurance carriers and ... Create and disseminate quarterly Risk Analysis and Summary report. * Continuously research and find ...

Implementing and monitoring technology risk and control frameworks across digital audit and assurance tools, including security, privacy, confidentiality, third-party risk, and financial reporting ...

next page

Showing results 1-20

Third Party Risk Analyst information

See Iowa salary details

$14

$38

$61

How much do third party risk analyst jobs pay per hour?

As of Aug 3, 2026, the average hourly pay for third party risk analyst in Iowa is $38.03, according to ZipRecruiter salary data. Most workers in this role earn between $27.98 and $46.30 per hour, depending on experience, location, and employer.

How does a Third Party Risk Analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

Is a grc analyst a good entry-level job?

A third-party risk analyst is often considered an entry-level role in risk management and compliance, suitable for individuals with strong analytical skills and knowledge of regulations like GDPR or HIPAA. The position typically involves assessing vendor risks, using tools like GRC software, and may require certifications such as CRISC or CISA. It provides a foundation for career growth in cybersecurity, compliance, or risk management fields.

How much does a third-party risk analyst make?

A third-party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries.

Is third-party risk management a good career?

Third-party risk management is a growing field within risk analysis and compliance, focusing on assessing and mitigating risks from external vendors and partners. It requires skills in risk assessment, regulatory knowledge, and often involves using tools like risk management software. The role offers opportunities for career advancement in industries such as finance, healthcare, and technology.

What does a third-party risk analyst do?

A third-party risk analyst evaluates the risks associated with an organization’s external vendors, suppliers, and partners. They assess third-party security, compliance, and operational risks using tools like risk management software and often require knowledge of industry standards and certifications. Their goal is to ensure that external relationships do not compromise the organization’s security or compliance posture.

What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst, and why are they important?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.
What are popular job titles related to Third Party Risk Analyst jobs in Iowa? For Third Party Risk Analyst jobs in Iowa, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst jobs in Iowa look for? The top searched job categories for Third Party Risk Analyst jobs in Iowa are:
Infographic showing various Third Party Risk Analyst job openings in Iowa as of July 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $79,095 per year, or $38 per hour.

Strategic Account Manager - Cybersecurity and Risk Consulting

RSM

Des Moines, IA

Full-time

Re-posted 7 days ago


Job description

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their full potential. Our exceptional people are the key to our unrivaled, culture and talent experience and our ability to be compelling to our clients. You'll find an environment that inspires and empowers you to thrive both personally and professionally. There's no one like you and that's why there's nowhere like RSM.

RSM US LLP is seeking to add a Strategic Account Manager to our Enterprise Sales Organization to focus on growing our cybersecurity and risk consulting practice. The Strategic Account Manager is responsible for developing cyber and risk consulting accounts through the cultivation of executive client relationships, identification of cross-selling opportunities, and conversion of single-service engagements into comprehensive advisory partnerships. This position requires presenting RSM's full suite of cyber, risk, compliance, privacy, resilience, and technology risk solutions to senior leadership, coordinating specialized expertise across advisory teams, and optimizing long-term account value. Additionally, the Strategic Account Manager will concentrate on expanding the cyber and risk consulting client base by sourcing new opportunities, strengthening relationships with existing clients, and promoting adoption of RSM's cyber and risk services as integral components of broader enterprise risk and digital trust strategies.

ESSENTIAL DUTIES

Cyber & Risk Account Leadership & Planning

  • Develop and execute strategic account plans for assigned cyber and risk consulting accounts, establishing clear revenue targets, relationship milestones, and cross-sell initiatives aligned with client enterprise risk priorities, regulatory obligations, cyber maturity goals, and resilience roadmaps.
  • Conduct quarterly account reviews with internal stakeholders, including cyber strategy, technology risk, IT audit, governance risk and compliance, privacy, third-party risk, cloud security, incident response, and managed security leaders to identify expansion opportunities and design integrated risk advisory solutions.
  • Establish and maintain executive relationship mapping for each account, identifying CISOs, CIOs, CROs, CFOs, General Counsel, audit committee members, compliance leaders, privacy officers, and business unit executives to enable multi-threaded engagement around cyber risk and enterprise resilience.
  • Lead the transition of single-service cyber or risk clients into integrated advisory partnerships by connecting security, compliance, operational resilience, technology risk, privacy, and third-party risk challenges to RSM's broader cyber and risk consulting portfolio.

Revenue Growth & Service Expansion

  • Drive year-over-year organic revenue growth within assigned accounts through renewals, upsells, and cross-sells of cyber and risk services, including cyber strategy and governance, technology risk, IT audit, regulatory compliance, privacy, data protection, third-party risk management, cloud security, incident readiness, and managed risk services.
  • Identify and qualify high-value expansion opportunities by analyzing client risk maturity, cyber program effectiveness, regulatory pressure, threat exposure, control gaps, audit findings, vendor risk, and resilience needs, then connecting those priorities to RSM's integrated advisory capabilities.
  • Develop and present multi-service value propositions to CISO, CIO, CRO, CFO, General Counsel, audit committee, and board-level audiences, using risk assessments, maturity benchmarks, regulatory drivers, cyber risk quantification, business impact scenarios, and resilience roadmaps to justify investment.
  • Forecast and manage the cyber and risk consulting pipeline, including opportunity sizing, probability weighting, close forecasting, and quarterly reviews across cyber strategy, technology risk, IT audit, compliance, privacy, third-party risk, cloud security, incident response, and managed risk services.

Client Relationship & Executive Engagement

  • Serve as the primary point of contact and trusted cyber and risk advisor for assigned accounts, building relationships grounded in a deep understanding of the client's business model, threat landscape, control environment, regulatory obligations, and enterprise risk priorities.
  • Conduct QBRs and executive business reviews with CISO, CIO, CRO, CFO, General Counsel, audit committee, and C-suite leadership, presenting account performance, cyber maturity insights, risk themes, regulatory developments, control improvement opportunities, and recommendations for expanded advisory support.
  • Maintain consistent engagement through strategic calls, risk briefings, cyber trend updates, control workshops, tabletop exercises, and in-person visits focused on evolving risk priorities, program maturity, regulatory readiness, and resilience needs.
  • Build multi-threaded relationships across executive leadership, cyber and IT leadership, compliance, legal, finance, internal audit, procurement, and business unit stakeholders to reduce single-point-of-contact risk and increase strategic influence.
  • Cultivate client advocacy through cyber program success stories, risk transformation case studies, board and peer referrals, and thought leadership engagement; establish accounts as referenceable clients for RSM's cyber and risk consulting practice.

Cyber & Risk Consulting Service Integration

  • Lead the identification and launch of integrated cyber and risk initiatives that position RSM as the primary advisory partner across cyber strategy, governance, technology risk, IT audit, regulatory compliance, privacy, third-party risk, resilience, cloud security, and managed risk services.
  • Collaborate with cyber strategists, risk advisors, IT audit professionals, compliance specialists, privacy practitioners, cloud security architects, incident response leaders, and managed services teams to design and scope integrated solutions addressing clients' highest-priority cyber and enterprise risk challenges.
  • Manage the internal sales process, including proposal development, competitive assessments, multi-discipline client presentations, and unified positioning of RSM's cyber and risk advisory capabilities.
  • Track and report on service line penetration within each account, establishing adoption goals across cyber strategy, technology risk, IT audit, compliance, privacy, third-party risk, incident readiness, and managed risk services.

Client Risk Success & Account Health

  • Develop and monitor a composite account health score that incorporates relationship breadth, renewal and expansion status, cyber and risk maturity progression, delivery satisfaction, competitive positioning, regulatory urgency, and service expansion pipeline.
  • Proactively identify at-risk accounts by monitoring engagement levels, risk roadmap alignment, audit findings, cyber incidents, regulatory pressure, delivery satisfaction, competitive threats, and renewal status; design interventions to stabilize and expand relationships.
  • Work closely with delivery teams and cyber and risk practice leaders to ensure service delivery excellence, measurable risk reduction, control improvement, regulatory readiness, resilience outcomes, and realization of agreed client success criteria.
  • Manage contract renewals and expansion discussions, ensuring on-time renewal execution and leveraging renewal conversations to expand service scope, improve cyber maturity, address emerging risk needs, and capture incremental advisory revenue.

Cyber, Risk & Regulatory Intelligence

  • Develop deep industry, cyber, and risk expertise relevant to assigned accounts, staying abreast of threat trends, regulatory developments, privacy requirements, control frameworks, resilience expectations, cloud security concerns, third-party risk, and technology risk management practices.
  • Bring curated cyber threat intelligence, risk trends, regulatory updates, maturity benchmarks, control improvement insights, and board-level business impact analyses to client conversations, positioning RSM as a strategic cyber and risk advisor.
  • Identify and communicate emerging cyber and risk challenges, including ransomware exposure, cloud misconfiguration, identity and access risk, data privacy obligations, vendor risk, regulatory scrutiny, operational resilience, and audit readiness that create opportunities for expanded RSM engagement.

Metrics, Forecasting & Accountability

  • Manage account portfolio to deliver individual and team revenue targets, expansion KPIs, service breadth, net revenue retention, renewal rate, and client satisfaction metrics for cyber and risk consulting services.
  • Maintain accurate and timely account data within Salesforce, including opportunity pipeline, account plans, forecast assumptions, client interaction history, risk maturity assessments, regulatory drivers, and service adoption tracking.
  • Prepare monthly and quarterly account performance reports, including revenue trends, service adoption, renewal status, cyber and risk opportunities, account health assessments, risk themes, and forecast updates.
  • Achieve and maintain KPI targets including annual revenue growth, strong renewal performance, net revenue retention, multi-service cyber and risk engagement, adjacent service sell-through, and high client satisfaction for assigned accounts.

Required Qualifications:

  • Bachelor's degree OR direct relevant past selling experience
  • Minimum 5 years of professional services sales and/or account management
  • Minimum 2 years of professional experience representing, client serving, managing or selling services
  • Proficient in Microsoft Office suite (Word, Excel, PowerPoint)
  • CRM experience for sales and/or account management application and requirements
  • Formal sales process training (consultative selling, solution-based selling, complex sales or related consultative selling approaches)
  • Demonstrated ability to lead a comprehensive and often complex sales process involving multiple internal resources and external decision-makers. Leadership in this role is largely based on influence and subject matter expertise rather than formal leadership roles or reporting lines

Preferred Qualifications:

  • Experience within a consulting firm/accounting firm environment
  • 7+ years of account management, cyber and risk consulting account leadership, advisory sales, or strategic client relationship experience in professional services, consulting, risk advisory, cybersecurity, or technology risk environments.
  • Strong organizational and project management skills; ability to orchestrate cross-functional internal teams across cyber, risk, compliance, privacy, IT audit, incident response, managed services, and industry advisory practices.

At RSM, we offer a competitive benefits and compensation package for all our people.We offer flexibility in your schedule, empowering you to balance life's demands, while also maintaining your ability to serve clients.Learn more about our total rewards at https://rsmus.com/careers/working-at-rsm/benefits.

All applicants will receive consideration for employment as RSM does not tolerate discrimination and/or harassment based on race; color; creed; sincerely held religious beliefs, practices or observances; sex (including pregnancy or disabilities related to nursing); gender; sexual orientation; HIV Status; national origin; ancestry; familial or marital status; age; physical or mental disability; citizenship; political affiliation; medical condition (including family and medical leave); domestic violence victim status; past, current or prospective service in the US uniformed service; US Military/Veteran status; pre-disposing genetic characteristics or any other characteristic protected under applicable federal, state or local law.

Accommodation for applicants with disabilities is available upon request in connection with the recruitment process and/or employment/partnership.RSM is committed to providing equal opportunity and reasonable accommodation for people with disabilities. If you require a reasonable accommodation to complete an application, interview, or otherwise participate in the recruiting process, please call us at 800-274-3978 or send us an email at careers@rsmus.com.

RSM does not intend to hire entry level candidates who will require sponsorship now OR in the future (i.e. F-1 visa holders). If you are a recent U.S. college / university graduate possessing 1-2 years of progressive and relevant work experience in a same or similar role to the one for which you are applying, excluding internships, you may be eligible for hire as an experienced associate.

RSM will consider for employment qualified applicants with arrest or conviction records. For those living in California or applying to a position in California, please click here for additional information.

At RSM, an employee's pay at any point in their career is intended to reflect their experiences, performance, and skills for their current role. The salary range (or starting rate for interns and associates) for this role represents numerous factors considered in the hiring decisions including, but not limited to, education, skills, work experience, certifications, location, etc. As such, pay for the successful candidate(s) could fall anywhere within the stated range.

Compensation Range: $102,800 - $176,000