1

Third Party Risk Analyst Jobs in Virginia (NOW HIRING)

Showing results 21-40

Third Party Risk Analyst information

See Virginia salary details

$15

$40

$65

How much do third party risk analyst jobs pay per hour?

As of Sep 6, 2026, the average hourly pay for third party risk analyst in Virginia is $40.14, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.85 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.

How does a third party risk analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

How much does a third party risk analyst make?

A third party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries. The role often requires strong analytical skills and knowledge of risk management tools.

Is third party risk analyst a good career?

A third party risk analyst evaluates and manages risks associated with external vendors and partners, often requiring knowledge of compliance, cybersecurity, and risk management tools. The role offers opportunities in industries such as finance, healthcare, and technology, with a growing demand due to increasing regulatory requirements and supply chain complexities.

What does a third party risk analyst do?

A third party risk analyst evaluates the risks associated with an organization's external vendors, suppliers, and partners. They assess compliance, security, and operational risks using tools like risk management frameworks and may conduct audits or reviews to ensure third-party adherence to company standards.

What are the most commonly searched types of Third Party Risk Analyst jobs in Virginia?

The most popular types of Third Party Risk Analyst jobs in Virginia are:

What are popular job titles related to Third Party Risk Analyst jobs in Virginia?

For Third Party Risk Analyst jobs in Virginia, the most frequently searched job titles are:

What cities in Virginia are hiring for Third Party Risk Analyst jobs?

Cities in Virginia with the most Third Party Risk Analyst job openings:

Infographic showing various Third Party Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 87% Physical, 4% Hybrid, and 9% Remote job distribution, with an average salary of $83,487 per year, or $40.1 per hour.

Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager

Capital One

Mclean, VA • On-site

Full-time

Re-posted 28 days ago


Capital One rating

7.8

Company rating: 7.8 out of 10

Based on 148 frontline employees who took The Breakroom Quiz

89th of 175 rated banks


Job description

Cyber Third Party Risk Reduction (CTPRR) Senior Manager, Operations Manager
The Cyber Third Party Risk Reduction (CTPRR) program defines the framework for the management of information security risks with third party engagements, supports contracting, conducts assessments, and ongoing finding remediation of third parties supporting Capital One.
We are seeking a highly organized, analytical, and proactive CTRPP Operations Lead to oversee the day-to-day execution and continuous improvement of our third-party risk management lifecycle. In this role, you will bridge the gap between risk strategy and operational execution. You will lead the team responsible for the identification, documentation, reporting, and mitigation of realized cybersecurity risk through contracting, ongoing monitoring and risk remediation, ensuring that third-party relationships comply with internal policies and external regulatory requirements.
The ideal candidate thrives on optimizing workflows, translating complex data into actionable metrics, and collaborating with cross-functional stakeholders across legal, procurement, information security, and business units.
You will:
  • Manage the end-to-end CTRPP operational lifecycle, including vendor inherent risk rating, due diligence assessments and ongoing monitoring.
  • Serve as the primary escalation point for complex risk assessments, vendor disputes, or critical remediation issues.
  • Supervise and mentor a team of risk analysts, ensuring data accuracy, consistency in risk evaluations, and adherence to established Service Level Agreements (SLAs).
  • Design, generate, and maintain operational dashboards, Key Performance Indicators (KPIs), and Key Risk Indicators (KRIs) for executive leadership.
  • Monitor third-party compliance with remediation plans, tracking open findings to resolution and escalating past-due risks.
  • Support internal and external audits, examinations, and regulatory inquiries by providing necessary CTRPP documentation and evidence.
  • Partner closely with Procurement, Legal, InfoSec, and Privacy teams to ensure a seamless and unified approach to third-party oversight.
  • Provide guidance and training to internal business owners on their responsibilities regarding third-party risk and compliance.

Responsibilities may also include:
  • Participating in on site assessments of third parties during more focused reviews
  • Participate or lead ad hoc requests of the program
  • Participate with broader program enhancements and ongoing development activity
  • Willing to jump in to support any of the program functions when needs arise

Basic Qualifications:
  • High School Diploma, GED, or equivalent certification
  • At least 6 years of experience in Third-Party Risk Management, Vendor Management, or Operational Risk Management
  • At least 3 years of experience in IT Operations Management

Preferred Qualifications:
  • Bachelor's Degree
  • CTPRP, CISSP, CISA, or CRISC certification
  • 5+ years of experience in IT Operations Management
  • 5+ years of experience at a Financial Institution

At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer)
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
McLean, VA: $200,700 - $229,100 for Sr. Manager, Cyber Risk & Analysis
Richmond, VA: $182,500 - $208,300 for Sr. Manager, Cyber Risk & Analysis
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.
No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

What Capital One employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom