1

Third Party Risk Analyst Jobs in Virginia (NOW HIRING)

Enterprise Risk Analyst

VA · On-site

$56.52/hr

Ability to engage directly with clients, and third parties to facilitate enterprise risk analysis * Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client ...

Centralized Service Manager I

Richmond, VA · On-site

$80K - $100K/yr

Facilitate the completion of third party risk assessments, contract review/structuring, due ... analytical, problem-solving, and negotiation skills 4. Strong relationship management skills 5. ...

Senior SCRM Analyst

Mclean, VA · On-site

$89K - $117K/yr

Senior SCRM Analyst Location: Arlington, VA Work Environment: Client-site required with limited ... Knowledge of supply chain risk management frameworks, supplier risk assessment, or third-party risk ...

Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...

Third-Party Risk Program Ownership: Own and evolve the Cybersecurity third-party security risk ... Broader Risk Assessment and Analysis: Perform principal-level risk assessment activities beyond ...

Showing results 21-40

Third Party Risk Analyst information

See Virginia salary details

$15

$40

$65

How much do third party risk analyst jobs pay per hour?

As of Aug 11, 2026, the average hourly pay for third party risk analyst in Virginia is $40.14, according to ZipRecruiter salary data. Most workers in this role earn between $29.57 and $48.85 per hour, depending on experience, location, and employer.

How does a third party risk analyst typically collaborate with other departments to manage vendor risks?

A Third Party Risk Analyst works closely with departments such as procurement, legal, IT security, and compliance to assess and mitigate potential risks posed by vendors and service providers. Collaboration often involves reviewing contracts, conducting risk assessments, and ensuring vendors meet the organization's security and compliance requirements. Regular communication and joint meetings are common to align on risk standards and address any emerging concerns. This cross-functional teamwork ensures a comprehensive approach to managing third-party risks and maintaining regulatory compliance.

What is the difference between Third Party Risk Analyst vs Vendor Risk Analyst?

AspectThird Party Risk AnalystVendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSimilar certifications, often the same as Third Party Risk Analyst
Work EnvironmentFinancial institutions, corporations managing third-party relationshipsOrganizations assessing vendor security, compliance, and performance
Industry UsageCommon in finance, healthcare, and tech sectorsPrimarily in procurement, supply chain, and IT sectors

The main difference is that a Third Party Risk Analyst focuses on assessing risks associated with all third-party relationships, including vendors, partners, and service providers. A Vendor Risk Analyst specifically concentrates on evaluating risks posed by vendors and suppliers. While their roles overlap, the Third Party Risk Analyst has a broader scope, often handling multiple types of third-party relationships within various industries.

How much does a third-party risk analyst make?

A third-party risk analyst typically earns between $60,000 and $100,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced analysts with certifications like CRISC or CISSP can earn higher salaries. The role often requires strong analytical skills and knowledge of risk management tools.

What does a third-party risk analyst do?

A third-party risk analyst evaluates the risks associated with an organization’s vendors, suppliers, and partners to ensure compliance and mitigate potential threats. They review contracts, perform risk assessments, and monitor third-party performance using tools like risk management software. Strong analytical skills and knowledge of regulatory standards are essential for this role.

What are the key skills and qualifications needed to thrive as a third party risk analyst?

To thrive as a Third Party Risk Analyst, you need a solid understanding of risk management principles, vendor assessment processes, and compliance regulations, often supported by a degree in business, finance, or information security. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and certifications like CTPRA or CRISC is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set exceptional analysts apart in this field. These competencies are crucial for identifying and mitigating vendor risks, ensuring organizational compliance, and safeguarding sensitive data.
What are the most commonly searched types of Third Party Risk Analyst jobs in Virginia? The most popular types of Third Party Risk Analyst jobs in Virginia are:
What are popular job titles related to Third Party Risk Analyst jobs in Virginia? For Third Party Risk Analyst jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Analyst jobs in Virginia look for? The top searched job categories for Third Party Risk Analyst jobs in Virginia are:
What cities in Virginia are hiring for Third Party Risk Analyst jobs? Cities in Virginia with the most Third Party Risk Analyst job openings:
Infographic showing various Third Party Risk Analyst job openings in Virginia as of August 2026, with employment types broken down into 86% Full Time, and 14% Contract. Highlights an 100% In-person job distribution, with an average salary of $83,487 per year, or $40.1 per hour.

Supply Chain Risk Management (SCRM) Lead

ZTI Solutions, LLC

Falls Church, VA • On-site

$180K - $210K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 23 days ago


Job description

Supply Chain Risk Management (SCRM) Lead
Falls Church, Virginia
Full-time
Important Notice: This position is contingent upon contract award.
Summary:
SCRM Leads develop and implement supply chain risk management programs assessing and mitigating risks from third-party vendors, commercial software, and supply chain dependencies. This role coordinates vendor security assessments, establishes SCRM policies, and interfaces with contracting and acquisition teams on security requirements.
Key Responsibilities:
  • Develop comprehensive supply chain risk management program.
  • Manage 30-80 third-party vendor relationships requiring security assessment.
  • Conduct 20-40 vendor security assessments annually.
  • Review 50-150 commercial software products for supply chain risk.
  • Analyze software composition and third-party dependencies.
  • Interface with contracting and acquisition teams on security requirements.
  • Develop 5-15 SCRM policies and procedures.
  • Monitor vendor security posture for changes and incidents.

Performance Metrics:
  • Vendors Managed: 30-80 requiring assessment per network.
  • Annual Assessments: 20-40 vendor security evaluations.
  • Software Reviews: 50-150 commercial products assessed.
  • SCRM Policies: 5-15 procedures developed and maintained.
  • Quarterly Reports: SCRM metrics and risk reporting.

Requirements:
  • Clearance: Secret (NIPR), Top Secret (SIPR), or TS/SCI Eligible (JWICS) based on network assignment.
  • Education: Bachelor's Degree in Information Technology, Cybersecurity, Computer Science, or related field.
  • Experience: 10+ years cybersecurity; 3+ years supply chain risk management or third-party risk.
  • Certifications: CISSP required; CISM, CRISC, or procurement certifications desired.
  • Technical Knowledge: Understanding of supply chain security threats, vendor risk assessment methodologies, Software Composition Analysis, NIST 800-161.

About Advana:
Advana is the Department of Defense Chief Digital and Artificial Intelligence Office's (CDAO) enterprise-wide data, analytics, and AI platform. Advana provides DoD military and civilian decision makers with unprecedented access to enterprise data, tools, and capabilities in a secure environment. The platform hosts hundreds of curated applications across logistics, financial management, personnel, health, and other domains, accelerating decision advantage through accessible, actionable data and AI capabilities.
This position supports comprehensive cybersecurity operations for the Advana platform across three classified networks (NIPR, SIPR, JWICS).
Important Notes:
Position Status:
  • This position is contingent upon contract award.
  • Start date will be determined upon contract award.
  • We will maintain contact with selected candidates throughout the award process.

Work Requirements:
  • U.S. Citizen required.
  • Clearance varies by network: Secret (NIPR), Top Secret (SIPR), or TS/SCI Eligible (JWICS).
  • On-premises work required at Suffolk Building, Falls Church, VA.
  • No remote work options available.
  • Standard business hours with operational flexibility.

Benefits:
  • 4 Weeks Paid Time Off.
  • All Federal Holiday’s Paid Vacation.
  • Four Percent Matching 401K.
  • Full health/vision/dental benefits for the employee and family paid 100% by ZTI Solutions, LLC.

We thank all applicants for their interest. Only candidates selected for interviews will be contacted.