1

Third Party Risk Assessment Jobs in Virginia (NOW HIRING)

Facilitate the completion of third party risk assessments, contract review/structuring, due diligence and fourth party oversight for assigned third parties with the understanding of the business unit ...

Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate. Third-Party Risk ...

Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate. Third-Party Risk ...

Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate. Third-Party Risk ...

Identify, assess, and prioritize information security risks; drive remediation to closure against SLAs, negotiating compensating controls with stakeholders where appropriate. Third-Party Risk ...

Assessment Analyst

Leesburg, VA · On-site +1

$87K - $95K/yr

... FedRAMP Third Party Assessment Organizations (3PAO). With the addition of Kovr.AI, we have expanded our capabilities to include advanced cyber risk quantification and analytics, enabling ...

New

Showing results 21-40

Third Party Risk Assessment information

See Virginia salary details

$44.1K

$85.9K

$123.4K

How much do third party risk assessment jobs pay per year?

As of Aug 11, 2026, the average yearly pay for third party risk assessment in Virginia is $85,944.00, according to ZipRecruiter salary data. Most workers in this role earn between $56,000.00 and $99,100.00 per year, depending on experience, location, and employer.

What are some challenges commonly faced in a third party risk assessment role?

Professionals in Third Party Risk Assessment often face the challenge of managing a large and diverse portfolio of third-party vendors, each with unique risk factors and compliance requirements. Balancing thorough risk analysis with tight project deadlines can require strong organizational and prioritization skills. Additionally, staying current with evolving regulatory standards and ensuring consistent communication with both internal stakeholders and external vendors can be demanding. However, these challenges also provide opportunities to develop critical expertise in risk management, improve cross-functional collaboration, and contribute significantly to organizational resilience and reputation.

What is a third party risk assessment?

A Third Party Risk Assessment job involves evaluating the security, compliance, and operational risks associated with external vendors, suppliers, or partners. Professionals in this role assess third-party practices to ensure they meet regulatory and organizational standards. They analyze potential risks such as data breaches, financial instability, and operational disruptions. The job typically involves conducting risk assessments, reviewing contracts, and working with internal stakeholders to mitigate risks.

What are the key skills and qualifications needed to thrive in the third party risk assessment position, and why are they important?

To thrive in Third Party Risk Assessment, you need a solid understanding of risk management frameworks, vendor due diligence processes, and regulatory compliance, typically supported by a degree in business, IT, or a related field. Familiarity with GRC (Governance, Risk, and Compliance) platforms, risk assessment tools, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) or Certified Risk Manager (CRM) is highly desirable. Excellent communication, analytical thinking, and problem-solving abilities set top candidates apart, as do project management skills. These skills are vital to effectively identify, evaluate, and mitigate risks posed by third-party vendors, ensuring the organization's overall security and compliance.

What are popular job titles related to Third Party Risk Assessment jobs in Virginia? For Third Party Risk Assessment jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Third Party Risk Assessment jobs in Virginia look for? The top searched job categories for Third Party Risk Assessment jobs in Virginia are:
What cities in Virginia are hiring for Third Party Risk Assessment jobs? Cities in Virginia with the most Third Party Risk Assessment job openings:
Infographic showing various Third Party Risk Assessment job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $85,944 per year, or $41.3 per hour.

Procurement Risk & Compliance Lead

S&P Global

Centreville, VA • On-site

$155K/yr

Full-time

Re-posted 10 days ago


S&P Global rating

7.3

Company rating: 7.3 out of 10

Based on 10 frontline employees who took The Breakroom Quiz


Job description

The Role:

Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management.

Reporting to the Global Head of Procurement, the Procurement Risk & Compliance Lead, will lead a small team responsible for the operational implementation of the Company's vendor risk management process within Procurement. While Legal Risk & Compliance will design and maintain the enterprise risk framework, this role will be responsible for developing and building the third-party risk management function inside of procurement, aligning with enterprise risk domain owners (information security, HR, ethics and compliance, and finance), monitoring and mitigating supplier risk, and ensure proper governance across the procurement function.

This role serves as the operational bridge between Procurement, Legal, Risk & Compliance, and Information Security.

Responsibility and Impact:

Vendor Risk Process Operationalization

  • Translate the enterprise vendor risk framework into scalable procurement processes and policies.
  • Work with risk domain owners to define intake requirements and risk-tiering triggers for vendor engagements.
  • Monitor the TPRM process and ensure timely completeness of the risk reviews by the applicable risk domain owners.
  • Drive continuous improvement in vendor risk governance processes.
  • Maintain vendor risk attributes, classifications, and documentation repositories.
  • Partner with Finance Systems and IT to enhance automation and reporting.
  • Develop dashboards and reporting to monitor review completion, SLAs, and compliance trends.

Policy & Documentation Development

  • Draft and maintain procurement-facing vendor risk policies and SOPs.
  • Conduct training sessions for business stakeholders.

Risk Review Coordination & Enforcement

  • Monitor review timelines and escalate exceptions.
  • Maintain documentation of approvals, conditions, and remediation requirements.
  • Track and report compliance metrics to Procurement and Finance leadership.

Audit & Compliance Support

  • Maintain audit-ready documentation of vendor risk approvals and workflows.
  • Support SOX-related vendor governance controls where applicable.
  • Partner with Internal Audit on third-party risk assessments.
  • Support remediation efforts tied to vendor governance findings.
  • Promote a culture of governance and risk awareness.

What We're Looking For:

Basic Required Qualifications:

  • Bachelor's degree in Business, Supply Chain, Risk Management, Finance, or related field or equivalent relevant experience.
  • 7 to 10+ years of experience in Procurement, Third-Party Risk, Compliance, or Governance.
  • Experience in a publicly traded organization required.
  • Strong understanding of third-party risk domains, including:
    • Information security
    • Data privacy
    • Regulatory and compliance risk
    • Operational and financial risk
  • Experience developing policy documentation and process controls.
  • Strong systems and workflow configuration experience.
  • Must be a results-focused team player and adapt well to a multitasking, fast paced environment with changing priorities and challenges
  • Strong organizational, presentation and communication skills.
  • Experience working cross-functionally with Technology, Legal, Finance, and Risk teams.

Additional Preferred Qualifications:

  • Experience with LogicGate or similar TPRM tool
  • Governance-oriented with strong attention to detail.
  • Systems-minded and process-driven.
  • Confident cross-functional influencer.
  • Able to enforce controls in a collaborative but firm manner.
  • Comfortable operating in a transformation-oriented, post-spin environment.

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.


What S&P Global employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom