The Principal Risk Analyst will lead risk business operations, special projects, investigations ... Ability to carry out audits, assessments and investigations; and Ability to use relevant compliance ...
The Principal Risk Analyst will lead risk business operations, special projects, investigations ... Ability to carry out audits, assessments and investigations; and Ability to use relevant compliance ...
Execute end-to-end third party diligence activities, including identity verification and customer ... Conduct engagement-level risk assessments to identify risks associated with selling products and ...
Execute end-to-end third party diligence activities, including identity verification and customer ... Conduct engagement-level risk assessments to identify risks associated with selling products and ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... Manage the internal sales process, including proposal development, competitive assessments, multi ...
... third-party risk, cloud security, incident response, and managed security leaders to identify ... Manage the internal sales process, including proposal development, competitive assessments, multi ...
Execute end-to-end third party diligence activities, including identity verification and customer ... Conduct engagement-level risk assessments to identify risks associated with selling products and ...
Execute end-to-end third party diligence activities, including identity verification and customer ... Conduct engagement-level risk assessments to identify risks associated with selling products and ...
Ethics & Compliance Manager
$103K - $144K/yr
This role oversees key compliance initiatives, monitors regulatory requirements, develops and delivers training, conducts compliance risk assessments, manages third-party compliance processes, and ...
Ethics & Compliance Manager
$103K - $144K/yr
This role oversees key compliance initiatives, monitors regulatory requirements, develops and delivers training, conducts compliance risk assessments, manages third-party compliance processes, and ...
Ethics & Compliance Manager
Austin, MN · On-site
$103K - $144K/yr
This role oversees key compliance initiatives, monitors regulatory requirements, develops and delivers training, conducts compliance risk assessments, manages third-party compliance processes, and ...
Ethics & Compliance Manager
Austin, MN · On-site
$103K - $144K/yr
This role oversees key compliance initiatives, monitors regulatory requirements, develops and delivers training, conducts compliance risk assessments, manages third-party compliance processes, and ...
Ethics & Compliance Manager
$103K - $144K/yr
This role oversees key compliance initiatives, monitors regulatory requirements, develops and delivers training, conducts compliance risk assessments, manages third-party compliance processes, and ...
Ethics & Compliance Manager
$103K - $144K/yr
This role oversees key compliance initiatives, monitors regulatory requirements, develops and delivers training, conducts compliance risk assessments, manages third-party compliance processes, and ...
Security Engineer
Minneapolis, MN · On-site +1
$83.33 - $106.06/hr
Experience supporting Third Party Risk Management (TPRM) programs. * Knowledge of vendor security assessments and vendor risk concepts. * Experience reviewing and documenting vendor network ...
Security Engineer
Minneapolis, MN · On-site +1
$83.33 - $106.06/hr
Experience supporting Third Party Risk Management (TPRM) programs. * Knowledge of vendor security assessments and vendor risk concepts. * Experience reviewing and documenting vendor network ...
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Drive product related policy management, issue management, change management, risk assessment, third-party risk management, and training. * Build standards for the product team, such as documentation ...
Drive product related policy management, issue management, change management, risk assessment, third-party risk management, and training. * Build standards for the product team, such as documentation ...
Manager - ServiceNow
Minneapolis, MN · On-site +1
... Third-Party Risk Management workstreams in partnership with architects and product owners ... It includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Manager - ServiceNow
Minneapolis, MN · On-site +1
... Third-Party Risk Management workstreams in partnership with architects and product owners ... It includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Senior GRC Information Security Systems Analyst - Direct Hire
Minneapolis, MN · On-site
$110K - $140K/yr
Perform third-party vendor technology risk assessments. * Evaluate security and privacy controls for vendors and SaaS platforms. * Support ongoing vendor security monitoring activities. Identity ...
New
Quick apply
Senior GRC Information Security Systems Analyst - Direct Hire
Minneapolis, MN · On-site
$110K - $140K/yr
Perform third-party vendor technology risk assessments. * Evaluate security and privacy controls for vendors and SaaS platforms. * Support ongoing vendor security monitoring activities. Identity ...
New
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Procurement Contract Services Negotiator / Senior Contract Analyst
Minneapolis, MN · Hybrid
$72K - $87K/yr
The individual partners closely with Business Lines and Third-Party Vendors and facilitates contract reviews through key stakeholders including Procurement, Risk, Legal, and Finance. This position ...
Procurement Contract Services Negotiator / Senior Contract Analyst
Minneapolis, MN · Hybrid
$72K - $87K/yr
The individual partners closely with Business Lines and Third-Party Vendors and facilitates contract reviews through key stakeholders including Procurement, Risk, Legal, and Finance. This position ...
Procurement Contract Services Negotiator / Senior Contract Analyst
Minneapolis, MN · On-site
$72K - $87K/yr
The individual partners closely with Business Lines and Third-Party Vendors and facilitates contract reviews through key stakeholders including Procurement, Risk, Legal, and Finance. This position ...
Procurement Contract Services Negotiator / Senior Contract Analyst
Minneapolis, MN · On-site
$72K - $87K/yr
The individual partners closely with Business Lines and Third-Party Vendors and facilitates contract reviews through key stakeholders including Procurement, Risk, Legal, and Finance. This position ...
Compliance Specialist
Golden Valley, MN · On-site
$71K - $131K/yr
... assessments, audits, and practices. * Establish, maintain, and evolve software tools related to ... Optimize the third-party risk management processes, including facilitating compliance portal ...
Compliance Specialist
Golden Valley, MN · On-site
$71K - $131K/yr
... assessments, audits, and practices. * Establish, maintain, and evolve software tools related to ... Optimize the third-party risk management processes, including facilitating compliance portal ...
Director - Technology Risk Consulting - Artificial Intelligence and Emerging Technology
Minneapolis, MN · On-site
Assess enterprise-wide AI impacts across cybersecurity, privacy, model risk management (MRM), third-party risk, and compliance-producing actionable remediation plans and control implementation ...
Director - Technology Risk Consulting - Artificial Intelligence and Emerging Technology
Minneapolis, MN · On-site
Assess enterprise-wide AI impacts across cybersecurity, privacy, model risk management (MRM), third-party risk, and compliance-producing actionable remediation plans and control implementation ...
RISK ANALYST (SUBCONTRACTOR PREQUALIFICATION) The Subcontractor Prequalification Risk Analyst is responsible for managing McGough's corporate risk assessment process for third-party partners ...
RISK ANALYST (SUBCONTRACTOR PREQUALIFICATION) The Subcontractor Prequalification Risk Analyst is responsible for managing McGough's corporate risk assessment process for third-party partners ...
RISK ANALYST (SUBCONTRACTOR PREQUALIFICATION) The Subcontractor Prequalification Risk Analyst is responsible for managing McGough's corporate risk assessment process for third-party partners ...
RISK ANALYST (SUBCONTRACTOR PREQUALIFICATION) The Subcontractor Prequalification Risk Analyst is responsible for managing McGough's corporate risk assessment process for third-party partners ...
Third Party Risk Assessment information
See Minnesota salary details
$43.6K - $50.7K
9% of jobs
$56.9K is the 25th percentile. Wages below this are outliers.
$50.7K - $57.8K
18% of jobs
$57.8K - $65K
0% of jobs
$65K - $72.1K
6% of jobs
$72.1K - $79.2K
2% of jobs
$79.2K - $86.3K
4% of jobs
$86.3K - $93.4K
2% of jobs
The median wage is $94.5K / yr.
$93.4K - $100.6K
52% of jobs
$100.6K - $107.7K
6% of jobs
$107.7K - $114.8K
0% of jobs
$114.8K - $121.9K
0% of jobs
$43.6K
$84.9K
$121.9K
How much do third party risk assessment jobs pay per year?
What are some challenges commonly faced in a third party risk assessment role?
Professionals in Third Party Risk Assessment often face the challenge of managing a large and diverse portfolio of third-party vendors, each with unique risk factors and compliance requirements. Balancing thorough risk analysis with tight project deadlines can require strong organizational and prioritization skills. Additionally, staying current with evolving regulatory standards and ensuring consistent communication with both internal stakeholders and external vendors can be demanding. However, these challenges also provide opportunities to develop critical expertise in risk management, improve cross-functional collaboration, and contribute significantly to organizational resilience and reputation.
What is a third party risk assessment?
A Third Party Risk Assessment job involves evaluating the security, compliance, and operational risks associated with external vendors, suppliers, or partners. Professionals in this role assess third-party practices to ensure they meet regulatory and organizational standards. They analyze potential risks such as data breaches, financial instability, and operational disruptions. The job typically involves conducting risk assessments, reviewing contracts, and working with internal stakeholders to mitigate risks.
What are the key skills and qualifications needed to thrive in the third party risk assessment position, and why are they important?
To thrive in Third Party Risk Assessment, you need a solid understanding of risk management frameworks, vendor due diligence processes, and regulatory compliance, typically supported by a degree in business, IT, or a related field. Familiarity with GRC (Governance, Risk, and Compliance) platforms, risk assessment tools, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) or Certified Risk Manager (CRM) is highly desirable. Excellent communication, analytical thinking, and problem-solving abilities set top candidates apart, as do project management skills. These skills are vital to effectively identify, evaluate, and mitigate risks posed by third-party vendors, ensuring the organization's overall security and compliance.

Full-time
Medical, Dental, Vision, Retirement
Posted 9 days ago
Mayo Clinic rating
7.8
Based on 697 frontline employees who took The Breakroom Quiz
131st of 887 rated healthcare providers
Job description
The Principal Risk Analyst will lead risk business operations, special projects, investigations, legal litigation, mitigation development, non-employee access and end user awareness/education. Incumbent will provide guidance to the RD unit for day-to-day operational support, including project management. Incumbent will demonstrate leadership and represent the RD on project teams, committees, strike teams and workgroups.
Job Duties and Responsibilities: Supports and develops RD initiatives. Responsible for the design of enterprise business operations, including operational growth and development. Leads multi-disciplinary workgroups and projects. Responsible for development of policies and procedures to support the organization's risk tolerance. Gathers and organizes information from a cross-functional investigative team. Works directly with Legal and Human Resources on high risk internal and external investigations. Works directly with Legal and External Counsel on policy, regulatory and/or litigation matters (using eDiscovery protocols). Completes documentation to support findings including legal reports, SBARs, and executive summaries. Responsible for peer review of work unit documentation. Develops and presents Risk training(s) geared towards Mayo Clinic leadership. Has extensive experience in regulatory compliance and investigations that includes:
Deep subject matter expertise in relevant compliance laws and regulations such as privacy compliance, investigations, revenue cycle compliance, device manufacturing compliance, general compliance, conflict of interest;
Understanding of and ability to apply the Seven Elements of an Effective Compliance Program;
Ability to carry out audits, assessments and investigations; and
Ability to use relevant compliance tools including GRC software, monitoring tools, and issue management software,
Ability to follow and apply legal holds and execute proper preservation of evidence and chain of custody protocols. Depending on role this may include the ability to follow proper computer forensic evidence handling, advanced knowledge of data preservation, acquisition of computing and storage devices either fixed or mobile and more technical forensic investigations.
Must have technical and nontechnical communication skills (verbal and written), analytical aptitude and project management skills. Demonstrates high level integrity and ability to use discretion and maintain confidential information. Other functions and projects as assigned. Some travel may be required to other Mayo Clinic sites and/or training conferences.
Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM.
Mayo Clinic is top-ranked in more specialties than any other care provider according to U.S. News & World Report. As we work together to put the needs of the patient first, we are also dedicated to our employees, investing in competitive compensation and comprehensive benefit plans - to take care of you and your family, now and in the future. And with continuing education and advancement opportunities at every turn, you can build a long, successful career with Mayo Clinic.
- Medical: Multiple plan options.
- Dental: Delta Dental or reimbursement account for flexible coverage.
- Vision: Affordable plan with national network.
- Pre-Tax Savings: HSA and FSAs for eligible expenses.
- Retirement: Competitive retirement package to secure your future.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, protected veteran status or disability status. Learn more about the "EOE is the Law". Mayo Clinic participates in E-Verify and may provide the Social Security Administration and, if necessary, the Department of Homeland Security with information from each new employee's Form I-9 to confirm work authorization.
Bachelor's degree and 7 years' experience in business analysis, compliance, privacy, insider threat, information security, human resources, risk management, information science, business administration, law enforcement, health or science-related fields OR Master's degree and 5 years' experience in business analysis, compliance, privacy, insider threat, information security, human resources, risk management, information science, business administration, law enforcement, health or science-related fields. Masters of Healthcare Administration, Business Administration, or Science preferred. Certified Fraud Examiner (CFE), Certification in Healthcare Compliance (CHC) or Healthcare Privacy Compliance (CHPC) preferred.
Additional Preferred Qualifications:
Demonstrates professional leadership skills. Ability to maintain highest level of confidentiality. Advanced analytical and problem-solving skills. Investigation and audit experience. Ability to work with limited management involvement. Effective training and presentation skills. Knowledge of operational risk best practices, effectiveness evaluations and resources. Demonstrated ability to set priorities and to respond to changing demands from multiple sources. Ability to follow-through, meet regulatory deadlines, anticipate requirements, and build relationships. Ability to communicate effectively with diverse groups including attorneys, physicians, patients, allied health staff, researchers, and vendors. Ability to work collaboratively in a team environment with minimal supervision. Advanced Microsoft Office skills including: Excel, Word, Visio, and Power Point. Some roles require specialized skills e.g. forensic accounting, forensic tools, insider threat, data loss prevention. Incumbent must be able to obtain government security clearances on behalf of the organization.
JD or Masters Degree preferred. or certified as CHC, CHPC, CCEP, CISSP, CISM, CITPM or relevant equivalent certification; or will obtain certification within 2 years of hire is preferred.
What Mayo Clinic employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Mayo Clinic
Sourced by ZipRecruiter
Mayo Clinic is the largest integrated, not-for-profit medical group practice in the world. We're building the future, one where the best possible care is available to everyone — and more people can heal at home. Our relentless research turns into earlier diagnoses and new cures. That's how we inspire hope in those who need it most. At Mayo Clinic, experts work together to solve the most challenging unmet needs of patients. Our history of innovation dates back almost 150 years, when brothers Will and Charlie Mayo pioneered an integrated, team-based approach to medicine. Today, that trailblazing spirit drives innovations like Mayo Clinic Platform — which powers new technologies to change how care is delivered to all.
Industry
Hospitals
Company size
10,000+ Employees
Headquarters location
Rochester, MN, US
Year founded
1919