... third-party risk assessments. • Coordinate collection and review of security documentation, including SOC reports, security questionnaires, and attestations. • Monitor remediation activities ...
... third-party risk assessments. • Coordinate collection and review of security documentation, including SOC reports, security questionnaires, and attestations. • Monitor remediation activities ...
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Lead third-party and vendor security risk assessments and due diligence activities. Compliance & Security Assurance * Manage cybersecurity compliance programs aligned with frameworks and regulations.
Business Risk Specialist II
Atlanta, GA · On-site
... third-party risk, and Program risk activities for the assigned business unit. * Analyze incidents and risk trends, assess remediation effectiveness, and evaluate process weaknesses to identify risk ...
New
Business Risk Specialist II
Atlanta, GA · On-site
... third-party risk, and Program risk activities for the assigned business unit. * Analyze incidents and risk trends, assess remediation effectiveness, and evaluate process weaknesses to identify risk ...
New
IT Risk Director, Technology Risk Management Resiliency & Business Continuity
Atlanta, GA · On-site +1
Facilitate completion of Business Impact Analyses, continuity plans, and resiliency assessments ... Third-Party Risk, and other risk disciplines. Ensure compliance with applicable regulatory ...
IT Risk Director, Technology Risk Management Resiliency & Business Continuity
Atlanta, GA · On-site +1
Facilitate completion of Business Impact Analyses, continuity plans, and resiliency assessments ... Third-Party Risk, and other risk disciplines. Ensure compliance with applicable regulatory ...
They are seeking a Staff Product Manager, AI Governance & Supply Chain Integration Risk to lead product strategy and execution, focusing on reducing risk across SaaS and third-party ecosystems.
They are seeking a Staff Product Manager, AI Governance & Supply Chain Integration Risk to lead product strategy and execution, focusing on reducing risk across SaaS and third-party ecosystems.
... Third Party Vendor Risk Management, improved Business Continuity, and the overall ERM program. * Facilitate the enterprise risk assessment and related reporting including 10-K Risk Factors, key risk ...
... Third Party Vendor Risk Management, improved Business Continuity, and the overall ERM program. * Facilitate the enterprise risk assessment and related reporting including 10-K Risk Factors, key risk ...
We're looking for a PM who thinks beyond product features and focuses on the key outcomes customers care about most : reducing unknown third-party risk, understanding where AI and agentic ...
Quick apply
We're looking for a PM who thinks beyond product features and focuses on the key outcomes customers care about most : reducing unknown third-party risk, understanding where AI and agentic ...
Director, Sales Engineering
Atlanta, GA · On-site
Prior experience with threat intelligence platforms, cyber risk intelligence, or third-party risk solutions * Hands-on familiarity with CTI tools, SIEM/SOAR integrations, or security assessment ...
Director, Sales Engineering
Atlanta, GA · On-site
Prior experience with threat intelligence platforms, cyber risk intelligence, or third-party risk solutions * Hands-on familiarity with CTI tools, SIEM/SOAR integrations, or security assessment ...
... global risk assessment impacting Alora manufactured and/or distributed products. * Oversee a ... supplement third-party vendor annual product reviews; and the monitoring of due dates for ...
... global risk assessment impacting Alora manufactured and/or distributed products. * Oversee a ... supplement third-party vendor annual product reviews; and the monitoring of due dates for ...
This role will focus on ingesting and correlating data from third-party risk and security tools (e.g., Archer, SecurityScorecard, Splunk), enabling alerting for vendor-related threats, and executing ...
New
This role will focus on ingesting and correlating data from third-party risk and security tools (e.g., Archer, SecurityScorecard, Splunk), enabling alerting for vendor-related threats, and executing ...
New
Senior Associate, Cybersecurity Advisory & Risk Management
Atlanta, GA · On-site
$95K - $110K/yr
... AI risk assessments · Assessing third-party risk management programs · Identifying cybersecurity risks, control gaps, and improvement opportunities · Developing risk registers, remediation ...
Quick apply
Senior Associate, Cybersecurity Advisory & Risk Management
Atlanta, GA · On-site
$95K - $110K/yr
... AI risk assessments · Assessing third-party risk management programs · Identifying cybersecurity risks, control gaps, and improvement opportunities · Developing risk registers, remediation ...
Enterprise Risk Management Manager
Atlanta, GA · On-site +1
$92K - $153K/yr
Own Cox's risk register, risk assessment process, and emerging-risk process, ensuring risks are ... Third-Party Risk), and Internal Audit, promoting cohesive practices across the three lines of ...
Enterprise Risk Management Manager
Atlanta, GA · On-site +1
$92K - $153K/yr
Own Cox's risk register, risk assessment process, and emerging-risk process, ensuring risks are ... Third-Party Risk), and Internal Audit, promoting cohesive practices across the three lines of ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Supporting functional ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Cyber ServiceNow - Consultant
Atlanta, GA · On-site
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
Cyber ServiceNow - Consultant
Atlanta, GA · On-site
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
... Security Operations, Third-Party Risk Management, and ServiceNow AI Control Tower use cases ... Includes design of the cyber organization, governance, and risk assessments. Qualifications ...
IT Governance Analyst
Atlanta, GA · On-site
$81K - $129K/yr
The IT Governance Analyst assists in the identification, assessment, monitoring, and risk mitigation associated with third-party vendors and suppliers. This role serves as a trusted advisor to ...
IT Governance Analyst
Atlanta, GA · On-site
$81K - $129K/yr
The IT Governance Analyst assists in the identification, assessment, monitoring, and risk mitigation associated with third-party vendors and suppliers. This role serves as a trusted advisor to ...
GRC Analyst
Atlanta, GA · Remote
Perform vendor and third-party risk assessments and document risk acceptance decisions * Build and maintain the risk register and report risk posture to leadership and stakeholders * Support ...
Quick apply
GRC Analyst
Atlanta, GA · Remote
Perform vendor and third-party risk assessments and document risk acceptance decisions * Build and maintain the risk register and report risk posture to leadership and stakeholders * Support ...
Business Risk Analyst
Alpharetta, GA · On-site +1
$70K - $98K/yr
We are seeking an experienced detail-oriented and proactive Business Risk Analyst to support the ... third-party auditors and internal assessments * Maintain organized documentation for audit ...
Business Risk Analyst
Alpharetta, GA · On-site +1
$70K - $98K/yr
We are seeking an experienced detail-oriented and proactive Business Risk Analyst to support the ... third-party auditors and internal assessments * Maintain organized documentation for audit ...
Third Party Risk Assessor information
See Georgia salary details
$19.50 is the 25th percentile. Wages below this are outliers.
$16.85 - $20.50
34% of jobs
The median wage is $22.78 / hr.
$20.50 - $24.15
25% of jobs
$24.15 - $27.81
0% of jobs
$27.81 - $31.46
0% of jobs
$31.46 - $35.11
6% of jobs
$35.11 - $38.77
2% of jobs
$38.77 - $42.42
5% of jobs
$43.64 is the 75th percentile. Wages above this are outliers.
$42.42 - $46.08
6% of jobs
$46.08 - $49.73
8% of jobs
$49.73 - $53.38
10% of jobs
$53.38 - $57.04
2% of jobs
$16
$32
$57
How much do third party risk assessor jobs pay per hour?
What are the key skills and qualifications needed to thrive as a third party risk assessor?
What is the difference between Third Party Risk Assessor vs Vendor Risk Analyst?
| Aspect | Third Party Risk Assessor | Vendor Risk Analyst |
|---|---|---|
| Certifications | ISO 27001, CRISC, CISA | ISO 27001, CRISC, CISA |
| Work Environment | Risk management teams, compliance departments | Procurement, compliance, and risk teams |
| Industry Usage | Financial, healthcare, technology | Financial, healthcare, technology |
The Third Party Risk Assessor and Vendor Risk Analyst roles often share similar certifications and work environments, focusing on evaluating third-party vendors' risks. While the Risk Assessor primarily conducts risk assessments and compliance reviews, the Vendor Risk Analyst may focus more on vendor performance and procurement processes. Both roles are essential in managing third-party relationships and ensuring organizational security and compliance.
What is a third party risk assessor?
What are some common challenges faced by third party risk assessors when evaluating vendors, and how can they be addressed?

Full-time
Posted 10 days ago
Vestis rating
7.0
Based on 47 frontline employees who took The Breakroom Quiz
117th of 171 rated vehicle equipment hire
Job description
At Vestis®, we provide uniforms, workplace supplies, and professional cleaning that help businesses simplify their workday and keep their teams safe, confident, and focused on what matters most. More than a provider, we are a partner in productivity, trusted to keep you running.
Join us and build a career supporting the people who make it all work.
Vestis is seeking a highly motivated Senior Analyst, IT Risk & Governance to support the organization's technology governance, risk management, compliance, and control programs. Reporting to the Sr. Director of IT Governance, Risk and Compliance, this role is responsible for coordinating IT risk assessments, maintaining governance processes, overseeing the security operations vendor partner relationship, developing risk reporting and dashboards, and partnering with technology and business teams to strengthen the company's overall risk posture.
The Senior Analyst serves as a trusted partner to Internal Audit, Operations, and Finance by helping ensure technology risks are identified, assessed, monitored, and mitigated in a practical and business-aligned manner. This role provides analytical support for enterprise governance initiatives involving cybersecurity, cloud services, data protection, third-party risk, artificial intelligence, and regulatory compliance.
Responsibilities/Essential Functions:
• Support administration and continuous improvement of the IT Governance, Risk, and Compliance (GRC) program.
• Maintain the enterprise IT risk register, including documentation of risk owners, mitigation plans, due dates, and risk ratings.
• Facilitate periodic IT risk assessments and control reviews across infrastructure, applications, data, cloud platforms, and vendor environments.
• Assist business and technology teams in identifying emerging risks and developing risk mitigation plans.
• Coordinate governance committee meetings, risk reviews, and action item tracking.
• Support policy management processes, including policy updates, exception tracking, and annual reviews.
• Support compliance activities related to SOX, PCI DSS, privacy requirements, cybersecurity frameworks, and other regulatory obligations.
• Assist in conducting technology vendor and third-party risk assessments.
• Coordinate collection and review of security documentation, including SOC reports, security questionnaires, and attestations.
• Monitor remediation activities associated with vendor risk findings.
• Maintain vendor risk inventories and reporting.
• Develop and maintain executive dashboards and reporting using Power BI and related tools.
• Coordinate with security operations' vendor partner to gather analytics to assess trends associated with technology risks, vulnerabilities, audit findings, compliance activities, and remediation performance.
• Prepare materials for executive leadership, governance committees, and auditors.
• Produce recurring risk and compliance reports to support management decision-making.
• Partner with security operations vendor partner, infrastructure, application, and data teams to track risks identified through vulnerability management, incident response, and other security activities.
• Assist with governance related to AI, cloud services, data privacy, and emerging technologies.
• Support awareness initiatives that strengthen the organization's culture of governance and risk management.
Knowledge/Skills/Abilities:
• Build strong partnerships within and across IT, Internal Audit, Finance, Legal, Operations, and business functions.
• Communicate risk findings and recommendations in clear business terms.
• Influence stakeholders to address risks and compliance gaps through effective reporting and data-driven insights.
• Promote consistent governance and risk management practices throughout the organization.
• Working knowledge of risk management frameworks such as NIST, ISO 27001, COBIT, or similar frameworks.
• Strong analytical and problem-solving skills.
Experience/Qualifications:
• Bachelor's degree in Information Technology, Finance, Business, or related discipline.
• 10+ years' experience in IT governance, risk management, internal audit, security operations, or related disciplines.
• Experience supporting audits, compliance programs, or control assessments.
• Strong analytical and problem-solving skills.
• Experience with Microsoft Excel, Power BI, and reporting tools.
• Excellent written and verbal communication skills.
• Experience supporting SOX, PCI DSS, privacy, or security programs.
• Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, or similar tools.
• Familiarity with cloud platforms (Azure, AWS, or Google Cloud).
• Professional certifications such as: CRISC, CISA, CGRC, CDPSE, CISSP (Associate or progressing toward) desired.
Headquartered in Roswell, GA, Vestis® is the second largest provider in the industry with over 300,000 customer locations and approximately 20,000 teammates across North America. Vestis® is a leader in the B2B uniform and workplace supplies category. Vestis® provides clean and safe uniform services and workplace supplies to a broad range of North American customers from Fortune 500 companies to locally owned small businesses across a broad set of end markets. The Company's comprehensive service offering includes a full-service uniform rental program, cleanroom and other specialty garment processing, floor mats, towels, linens, managed restroom services, first aid supplies and more.
Vestis® is an equal-opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, relation, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or veteran status.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Vestis Commitment to Equal Opportunity Employment
If you are a job seeker with a disability and require a reasonable accommodation to apply for one of our jobs, you will find the contact information below to request the appropriate accommodation.
Reasonable Accommodations and the Online Application Process
Consistent with Vestis and Canadian Linen's commitment to equal employment opportunity, we provide reasonable accommodations to qualified individuals with disabilities who need assistance in applying electronically for a position with Vestis or Canadian Linen, unless doing so would impose an undue hardship. To request a reasonable accommodation for this purpose, please call 1-833-901-8823 or email us at accessibility@vestis.com.
Please note that this phone number is to be used solely to request an accommodation with respect to the online application process. Calls for any other reason will not be returned. Reasonable accommodation requests are considered on a case-by-case basis.
Thank you for your interest in an employment opportunity with Vestis, Canadian Linen and Québec Linge.
About Vestis
Sourced by ZipRecruiter
Industry
Personal services
Company size
1 - 10 Employees
Headquarters location
Roswell, GA, US