1

Third Party Risk Analyst Jobs in Kentucky (NOW HIRING)

Risk Analyst (Fix & Flip Real Estate) Position Overview MM Lending is seeking a highly analytical and detail-oriented Risk Analyst (Fix & Flip Real Estate) to lead and strengthen the company ...

... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

$41.75 - $55.75/hr

Support our IT risk management program to ensure both internal and third-party IT risks are ... Strong analytical skills, attention to detail, and a problem-solving mindset. Excellent ...

... Third-Party Risk Management workstreams in partnership with architects and product owners ... Experience with Performance Analytics, Predictive Intelligence, Now Assist, or generative ...

ABOUT THIS POSITION The Compliance Analyst II plays a key role in supporting and coordinating ... Familiarity with cloud environments, information security controls, and third-party risk management.

ABOUT THIS POSITION The Compliance Analyst II plays a key role in supporting and coordinating ... Familiarity with cloud environments, information security controls, and third-party risk management.

... underwriters and third-party partners to ensure adherence to investor, agency, and bank ... analytical skills - Proficient computer navigation skills, particularly word processing ...

Implementing and monitoring technology risk and control frameworks across digital audit and assurance tools, including security, privacy, confidentiality, third-party risk, and financial reporting ...

next page

Showing results 1-20

Third Party Risk Analyst information

See Kentucky salary details

$13

$35

$57

How much do third party risk analyst jobs pay per hour?

As of Jul 29, 2026, the average hourly pay for third party risk analyst in Kentucky is $35.16, according to ZipRecruiter salary data. Most workers in this role earn between $25.87 and $42.79 per hour, depending on experience, location, and employer.

How does a Third Party Risk Analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

Is a grc analyst a good entry-level job?

A third-party risk analyst is often considered an entry-level role in risk management and compliance, suitable for individuals with strong analytical skills and knowledge of regulations like GDPR or HIPAA. The position typically involves assessing vendor risks, using tools like GRC software, and may require certifications such as CRISC or CISA. It provides a foundation for career growth in cybersecurity, compliance, or risk management fields.

How much does a third-party risk analyst make?

A third-party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries.

Is third-party risk management a good career?

Third-party risk management is a growing field within risk analysis and compliance, focusing on assessing and mitigating risks from external vendors and partners. It requires skills in risk assessment, regulatory knowledge, and often involves using tools like risk management software. The role offers opportunities for career advancement in industries such as finance, healthcare, and technology.

What does a third-party risk analyst do?

A third-party risk analyst evaluates the risks associated with an organization’s external vendors, suppliers, and partners. They assess third-party security, compliance, and operational risks using tools like risk management software and often require knowledge of industry standards and certifications. Their goal is to ensure that external relationships do not compromise the organization’s security or compliance posture.

What are the key skills and qualifications needed to thrive as a Third Party Risk Analyst, and why are they important?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.
What are the most commonly searched types of Third Party Risk Analyst jobs in Kentucky? The most popular types of Third Party Risk Analyst jobs in Kentucky are:
What are popular job titles related to Third Party Risk Analyst jobs in Kentucky? For Third Party Risk Analyst jobs in Kentucky, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst jobs in Kentucky look for? The top searched job categories for Third Party Risk Analyst jobs in Kentucky are:
Infographic showing various Third Party Risk Analyst job openings in Kentucky as of July 2026, with employment types broken down into 86% Full Time, 9% Part Time, 1% Temporary, and 4% Contract. Highlights an 86% Physical, 6% Hybrid, and 8% Remote job distribution, with an average salary of $73,138 per year, or $35.2 per hour.

IT Security and Governance Analyst

Brown-Forman

Louisville, KY • On-site

$43.25 - $57.50/hr

Full-time

Re-posted 17 days ago


Brown‑Forman rating

7.7

Company rating: 7.7 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

123rd of 434 rated food and drinks producers


Job description

Job Summary:
Brown-Forman is a premium spirits company that offers a dynamic opportunity for an experienced IT Governance/Risk/Compliance Analyst. In this role, you will identify and mitigate IT risks, ensure regulatory compliance, and enhance the organization's security posture through governance frameworks and controls.
Responsibilities:
• Develop and maintain IT governance frameworks and policies that align with industry standards and regulatory requirements, which are then implemented by IT owners.
• Support our IT risk management program to ensure both internal and third-party IT risks are identified, assessed, prioritized and remediated.
• Raise awareness within the organization of IT governance, risk and compliance programs that are risk based and align with compliance requirements.
• Track and ensure compliance with internal policies and external regulations through periodic audits and assessments.
• Ensure data security and privacy compliance by providing guidance on appropriate access controls, data classification protocols, and data protection measures.
• Collaborate with key stakeholders throughout the IT organization as well as with Internal Audit, Compliance, and Legal.
• Monitor evolving regulations, compliance standards, and best practices to strengthen our IT GRC capabilities and frameworks.
Qualifications:
Required:
• 3+ years of experience focused on governance, compliance, risk, audit or similar functions.
• Knowledge of IT governance and risk management frameworks including compliance practices (e.g., PCI, NIST, GDPR, COBIT, NIS2, Operation Technology, etc.).
• Strong analytical skills, attention to detail, and a problem-solving mindset.
• Excellent collaboration, communication and influencing skills with the ability to develop effective working relationships with all levels of the company.
• Exposure to risk assessments, policy development, and internal control audits.
Preferred:
• Bachelor’s degree within a related area of study.
• Information security related training or certifications such as CISA, CRISC, PCI QSA.
• Experience working with GRC platforms and tools.
• Familiarity with third-party risk management and vendor compliance.
Company:
Brown‑Forman Corporation is a global leader in the spirits industry, responsibly building exceptional beverage alcohol brands for more than 155 years. Founded in 1870, the company is headquartered in Louisville, USA, with a team of 5001-10000 employees. The company is currently Late Stage.

What Brown‑Forman employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom