1

Third Party Risk Analyst Jobs in New York (NOW HIRING)

Risk Specialist

New York, NY ยท On-site

$100K - $130K/yr

Analyze vulnerability assessments and third-party security reviews, considering environmental, procedural, and business risk factors-not just technical severity scores. * Partner with Infrastructure ...

Cybersecurity Risk Analyst II

New York, NY ยท On-site

$119K - $140K/yr

Own CLEAR's third-party risk management program end-to-end, including vendor security assessments ... Applying analytical and critical thinking skills to quickly understand new technologies, systems ...

Experience in Third-Party Risk Management (TPRM) and related interagency guidance (e.g., OCC, FDIC ... Strong critical thinking traits, including analytical, problem-solving, and decision-making ...

Risk Manager

New York, NY ยท Hybrid

$140K - $155K/yr

You will use AI and automation tools throughout your work to build context quickly, analyze data ... Proactively monitor risks related to third-party vendors. * Follow up on open issues to drive ...

Showing results 41-60

Third Party Risk Analyst information

See New York salary details

$16

$44

$72

How much do third party risk analyst jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for third party risk analyst in New York is $44.29, according to ZipRecruiter salary data. Most workers in this role earn between $32.60 and $53.89 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.

How does a third party risk analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

How much does a third party risk analyst make?

A third party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries. The role often requires strong analytical skills and knowledge of risk management tools.

Is third party risk analyst a good career?

A third party risk analyst evaluates and manages risks associated with external vendors and partners, often requiring knowledge of compliance, cybersecurity, and risk management tools. The role offers opportunities in industries such as finance, healthcare, and technology, with a growing demand due to increasing regulatory requirements and supply chain complexities.

What does a third party risk analyst do?

A third party risk analyst evaluates the risks associated with an organization's external vendors, suppliers, and partners. They assess compliance, security, and operational risks using tools like risk management frameworks and may conduct audits or reviews to ensure third-party adherence to company standards.

What are the most commonly searched types of Third Party Risk Analyst jobs in New York?

The most popular types of Third Party Risk Analyst jobs in New York are:

What job categories do people searching Third Party Risk Analyst jobs in New York look for?

The top searched job categories for Third Party Risk Analyst jobs in New York are:

What cities in New York are hiring for Third Party Risk Analyst jobs?

Cities in New York with the most Third Party Risk Analyst job openings:

Infographic showing various Third Party Risk Analyst job openings in New York as of August 2026, with employment types broken down into 94% Full Time, and 6% Contract. Highlights an 86% In-person, 11% Hybrid, and 3% Remote job distribution, with an average salary of $92,128 per year, or $44.3 per hour.

Risk Specialist

Focus Financial Partners

New York, NY โ€ข On-site

$100K - $130K/yr

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 11 days ago


Job description

Job Description Summary:

Focus Financial Partners is seekinga proactive and detail-orientedSeniorRisk OperationsSpecialistto support and strengthen our organization'sCybersecurity program. This role is responsible forsupporting key risk pillars: Vulnerability Management and Risk Management. A successful candidate will have knowledge of one or more of these areas and be able to assist with writing policy and process, supportingdeployment of technology andhandling incident response in a variety of environments. The candidatewill also manage and maintain cybersecurity dashboards to track key performance indicators (KPIs) across all partner firms.
This role can be based in New York, NY or St Louis. MO.

Job Description:

Primary Responsibilities

  • Analyze vulnerability assessments and third-party security reviews, considering environmental, procedural, and business risk factors-not just technical severity scores.
  • Partner with Infrastructure, Security Engineering, Enterprise Risk Management, Vendor Management, Legal, Compliance, Procurement, and business stakeholders to identify, assess, and mitigate cybersecurity risk.
  • Manage the lifecycle of vulnerabilities and third-party risks by tracking findings, driving remediation efforts, facilitating risk acceptance, and validating issue resolution.
  • Conduct cybersecurity due diligence for new and existing vendors, evaluate security controls, and recommend practical risk mitigation strategies and compensating controls.
  • Develop and maintain third-party risk management (TPRM) policies, procedures, vendor assessment questionnaires, and governance processes.
  • Drive remediation initiatives for end-of-life and unsupported technologies, vendor security gaps, and other identified cyber risks.
  • Assist in developing threat intelligence and exposure management processes to identify emerging risks affecting the organization and its third-party ecosystem.
  • Develop, track, and report cybersecurity and third-party risk metrics, including Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs), to leadership.
  • Support regulatory, audit, and compliance initiatives by ensuring cybersecurity and third-party risk practices align with applicable regulations and industry frameworks.
  • Build strong relationships with internal stakeholders and third-party partners to promote effective risk management and continuous improvement across the cybersecurity program.

Qualifications

  • 3-5 years of experience in cybersecurity risk management, vulnerability management, third-party risk management, or a related cybersecurity discipline.
  • Experience analyzing vulnerabilities, conducting vendor security assessments, and managing remediation efforts across technical and business stakeholders.
  • Knowledge of the vulnerability management lifecycle, including discovery, validation, prioritization, remediation, verification, exception management, and risk acceptance.
  • Familiarity with cybersecurity frameworks such as NIST CSF, ISO 27001, or similar industry standards.
  • Experience with vulnerability and exposure management platforms such as Rapid7, Tenable, Qualys, CrowdStrike, or similar tools.
  • Knowledge of financial services regulations and security requirements, including SEC, FINRA, Regulation S-P, GDPR, and CCPA.
  • Strong analytical, communication, and relationship management skills with the ability to influence technical and non-technical stakeholders.
  • Ability to manage multiple priorities in a fast-paced, highly collaborative environment.
  • Industry certifications such as CISSP, CISM, or GIAC certifications are preferred.
  • Prior experience in a financial services or multi-partner environment is preferred.

This position is an exempt position. The annualized base pay range for this role is expected to be between $100,000-$130,000 base salary compensation range. Actual base pay may vary based on factors including, but not limited to, experience, subject matter expertise, geographic location where work will be performed, and the applicant's skill set. The base pay is just one component of the total compensation package. Other rewards may include an annual cash bonus and a comprehensive benefits package, including but not limited to medical, dental, vision, life insurance, and 401(k). Please note that the job title is subject to change based on the selected candidate's experience and education.


Focus is a leading financial services firm comprised of integrated wealth management, family office, and business management services. Blending deep expertise and expansive resources with a boutique, client-first fiduciary philosophy, Focus helps individuals, families, and institutions navigate complex financial situations with highly personalized solutions tailored to their unique needs. To learn more about Focus, visit www.focusfinancialpartners.comor follow the company onLinkedIn.


EEO Statement: Focus is an equal opportunity employer and bases its employment decisions on the employee or candidate's skillset, and without regard to an employee or candidate's race, color, religion, sex (including pregnancy), gender identity, sexual orientation, national origin, age, disability, genetic information, veteran status, or any other characteristic protected by local, state and/or federal law.

Focus complies with federal and state disability laws and makes reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact careers@focuspartners.com


The following language is for US based roles only

For California Applicants:Information on your California privacy rights can be found here

For Indiana Applicants: It is unlawful for an employer to discriminate against a prospective employee on the basis of status as a veteran by refusing to employ an applicant on the basis that they are a veteran of the armed forces of the United States, a member of the Indiana National Guard or a member of a reserve component.

For Maryland Applicants: I UNDERSTAND THAT UNDER MARYLAND LAW, AN EMPLOYER MAY NOT REQUIRE OR DEMAND, AS A CONDITION OF EMPLOYMENT, PROSPECTIVE EMPLOYMENT OR CONTINUED EMPLOYMENT, THAT ANY INDIVIDUAL SUBMIT TO OR TAKE A POLYGRAP OR SIMILAR TEST. AN EMPLOYER WHO VIOLATES THIS LAW IS GUILTY OF A MISDEMEANOR AND SUBJECT TO A FINE NOT EXCEEDING $100.

For Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this shall be subject to criminal penalties and civil liability.

For Montana Applicants: If hired, the employment relationship is governed by the Wrongful Discharge from Employment Act. Mont. Code Ann. Section 39-2-901.

For Rhode Island Applicants: Focus is subject to Chapters 29-38 of Title 28 of the General Laws of Rhode Island and is therefore covered by the state's workers' compensation law. If you willfully provide false information about your ability to perform the essential functions of the job, with or without reasonable accommodations, you may be barred from filing a claim under the provisions of the Workers' Compensation Act of the State of Rhode Island if the false information is directly related to the personal injury that is the basis for the new claim for compensation. The Company complies fully with the Americans with Disabilities Act.