1

Third Party Risk Analyst Jobs in Kentucky (NOW HIRING)

$140 - $180/hr

Third Party Risk Management Lead Professional US 2 days ago Requisition ID: 1286 Salary: $160,000 ... Support development of Business Impact Analysis (BIA) across critical functions * Partner with ...

$237 - $296/hr

Department Overview The Senior Director of Cyber Third-Party Risk Management (TPRM) is accountable for leading and modernizing McDonald's global third-party cyber risk management capability across a ...

$104 - $166/hr

Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement -- policy, control testing, and POA&M management ...

$90 - $130/hr

Basic understanding of vendor risk assessment methodologies and third-party risk management practices. * Strong analytical, research, and technical writing skills, with the ability to translate ...

$90 - $140/hr

Familiarity with global regulations including import/export, third-party risk, ESG, sanctions, and ... Proficient in analyzing global regulations and delivering compliance reports to stakeholders.

$150 - $210/hr

As part of FRM, we contribute to OpenAI's overall financial risk posture by supporting audit readiness, third-party risk considerations, operational risk governance, systems oversight, and ongoing ...

$90 - $130/hr

Select how often (in days) to receive an alert: Senior IT Compliance and Risk Analyst Date: Aug 21 ... NextEra Energy does not accept any unsolicited resumes or referrals from any third-party recruiting ...

$180 - $260/hr

As part of FRM, we contribute to OpenAI's overall financial risk posture by supporting audit readiness, third-party risk considerations, operational risk governance, systems oversight, and ongoing ...

$152 - $272/hr

... Third-Party Risk Management as well as senior risk professionals. Trust Risk at Autodesk is an ... Strong analytical and problem-solving skills* Ability to think strategically and execute ...

$120 - $180/hr

Investigate misuse and exfiltration risk across source code, Google, AWS, Azure, third party apps ... Working knowledge of SIEM and log analysis (e.g., ELK/Elastic, Splunk) to support investigations

$110 - $150/hr

Senior Catastrophe Risk Analyst Location: Duluth, GA (Onsite/ Hybrid Schedule) Position Type: Full-time We are looking for a Senior Catastrophe Risk Analyst who will leverage expertise of catastrophe ...

... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Analyzing processes, controls, and tools to identify opportunities for ServiceNow configuration and ...

$41.75 - $55.75/hr

Support our IT risk management program to ensure both internal and third-party IT risks are ... Strong analytical skills, attention to detail, and a problem-solving mindset. Excellent ...

$125 - $135/hr

S. Critical Infrastructure, as well as supply chain risk analysis for information and communications technology and services (ICTS) transactions under Executive Order 13873. Personnel will be ...

$100 - $150/hr

... and Third-Party Risk Management to translate regulatory changes, operational/system changes, and ... Strong analytical and organizational skills with high attention to detail and accuracy and the ...

New

$189 - $219/hr

Manage day-to-day relationships with brokers, carriers, third-party administrators, consultants ... Analytical and comfortable working with claims data, insurance information, spreadsheets, reports ...

$110 - $170/hr

... and third-party or vendor risk to assess the control impact of change. * Experience leveraging data analytics, automation, or AI-enabled tools to improve compliance monitoring, reporting, or ...

next page

Showing results 1-20

Third Party Risk Analyst information

See Kentucky salary details

$13

$35

$57

How much do third party risk analyst jobs pay per hour?

As of Aug 28, 2026, the average hourly pay for third party risk analyst in Kentucky is $35.16, according to ZipRecruiter salary data. Most workers in this role earn between $25.87 and $42.79 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.

How does a third party risk analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

How much does a third party risk analyst make?

A third party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries. The role often requires strong analytical skills and knowledge of risk management tools.

Is third party risk analyst a good career?

A third party risk analyst evaluates and manages risks associated with external vendors and partners, often requiring knowledge of compliance, cybersecurity, and risk management tools. The role offers opportunities in industries such as finance, healthcare, and technology, with a growing demand due to increasing regulatory requirements and supply chain complexities.

What does a third party risk analyst do?

A third party risk analyst evaluates the risks associated with an organization's external vendors, suppliers, and partners. They assess compliance, security, and operational risks using tools like risk management frameworks and may conduct audits or reviews to ensure third-party adherence to company standards.

What are the most commonly searched types of Third Party Risk Analyst jobs in Kentucky?

The most popular types of Third Party Risk Analyst jobs in Kentucky are:

What are popular job titles related to Third Party Risk Analyst jobs in Kentucky?

For Third Party Risk Analyst jobs in Kentucky, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Analyst jobs in Kentucky look for?

The top searched job categories for Third Party Risk Analyst jobs in Kentucky are:

Infographic showing various Third Party Risk Analyst job openings in Kentucky as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 6% Part Time, 7% Temporary, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $73,138 per year, or $35.2 per hour.

Third Party Risk Management Lead

On-site

$140 - $180/hr

Other

Posted 7 days ago


Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Third Party Risk Management Lead

Professional US

2 days ago Requisition ID: 1286

Salary: $160,000.00 Annually

Third Party Risk Management Lead

About Sungrow:

Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America is known for its commitment to innovation, high-quality standards, and exceptional customer service, aiming to provide sustainable and reliable energy solutions to meet the growing demand for clean power.

The Position:

Sungrow Americas is seeking a Third Party Risk Management (TPRM) Lead to establish and operate a scalable program for managing vendor, supplier, and third-party risk across the organization.

This role is responsible for ensuring that third-party relationships are assessed, governed, and continuously monitored in alignment with regulatory expectations and customer requirements.

In parallel, this role will support the development of business continuity and resilience capabilities, including Business Impact Analysis (BIA) and foundational BCDR program elements.

This is a program leadership role requiring strong execution, cross-functional influence, and the ability to operate in a regulated, critical infrastructure environment

Key Responsibilities
  • Build and operate the TPRM program lifecycle, including:
    • Vendor intake and risk tiering
    • Security assessments and due diligence
    • Ongoing monitoring and reassessment
  • Define and enforce minimum security requirements for vendors and suppliers
  • Partner with legal and procurement to embed security and risk clauses into contracts
  • Establish processes for exception management and risk acceptance
  • Lead execution of third-party security reviews, including:
    • Questionnaires and evidence validation
    • Review of SOC 2, ISO certifications, and supporting artifacts
  • Identify and communicate material risks and required mitigations
  • Ensure alignment to frameworks (NIST, ISO 27001, SOC 2, NERC CIP where applicable)
  • Implement ongoing monitoring capabilities for vendor risk posture
  • Track and drive remediation of identified third-party risks
  • Maintain visibility into fourth-party and supply chain dependencies where relevant
Business Continuity & Resilience (BCDR/BIA Support)
  • Support development of Business Impact Analysis (BIA) across critical functions
  • Partner with business and IT stakeholders to define:
    • Critical processes
    • Recovery time objectives (RTO) / recovery point objectives (RPO)
  • Contribute to the development of BCDR plans and testing frameworks
  • Ensure third-party dependencies are integrated into continuity planning
Governance, Reporting & Audit Readiness
  • Develop and track TPRM KPIs and risk metrics
  • Provide executive-level reporting on third-party risk posture
  • Maintain documentation and evidence to support:
    • Audits
    • Customer security reviews
    • Regulatory inquiries
  • Ensure program is defensible and repeatable
Cross-Functional Collaboration
  • Partner with:
    • Procurement (vendor onboarding)
    • Legal (contractual protections)
    • IT and engineering (technical validation)
  • Act as the central point of coordination for third-party risk decisions
Requirements
  • 7–10+ years of experience in third-party risk management, GRC, or vendor risk programs
  • Proven experience building or leading a TPRM program in a regulated or enterprise environment
  • Strong understanding of:
    • Vendor risk assessment methodologies
    • Security frameworks (NIST, ISO 27001, SOC 2)
  • Experience reviewing:
    • Security documentation (policies, controls, audit reports)
    • Third-party attestations (SOC 2, ISO certifications)
  • Working knowledge of business continuity and resilience concepts (BIA, BCDR)
  • Ability to drive cross-functional alignment and accountability
Preferred
  • Experience in energy, industrial, or critical infrastructure sectors
  • Familiarity with NERC CIP requirements
  • Experience implementing or operating TPRM platforms/tools
  • Certifications such as CRISC, CISM, CISSP, or CTPRP
  • Program Builder: Can stand up and mature TPRM from structure to scale
  • Risk Translator: Converts vendor risk into business and contractual impact
  • Governance-Oriented: Ensures decisions are documented and defensible
  • Cross-Functional Operator: Effective with procurement, legal, IT, and engineering
  • Pragmatic Enforcer: Balances risk reduction with business enablement
Strategic Fit
  • Establishes control over external risk exposure
  • Strengthens customer trust and regulatory alignment
  • Enables defensible procurement and vendor onboarding decisions
  • Builds foundation for enterprise resilience and continuity planning
Travel

Up to 10%

Work Location and Status:
  • Remote

Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only contact candidates who best meet the requirements. Thank you for your interest in Sungrow.

#J-18808-Ljbffr