1

Third Party Risk Assessor Jobs in Massachusetts (NOW HIRING)

GRC Analyst - Third Party Risk

Boston, MA · On-site

$70K - $110K/yr

Support day-to-day third-party vendor risk assessments - manage and triage GRC third-party vendor assessment intakes and accurate tracking through resolution * Perform vendor risk reviews ...

Third Party Risk Director

Boston, MA · Hybrid

$178K - $186K/yr

Key Responsibilities Design, implement, and maintain the third-party payments risk and compliance ... Assess partner policies, controls, and customer journeys to identify gaps and recommend remediation ...

Third Party Risk Director

Boston, MA · Hybrid

$178K - $186K/yr

Key Responsibilities Design, implement, and maintain the third-party payments risk and compliance ... Assess partner policies, controls, and customer journeys to identify gaps and recommend remediation ...

Third Party Risk Director

Boston, MA · Hybrid

$178K - $186K/yr

Key Responsibilities Design, implement, and maintain the third-party payments risk and compliance ... Assess partner policies, controls, and customer journeys to identify gaps and recommend remediation ...

Operational Risk Associate

Holyoke, MA · On-site

$30.77 - $32.82/hr

Collect, organize, and maintain due diligence, monitoring, contract, risk assessment, and supporting documentation for third-party and technology risk management activities. * Assist with review of ...

Execute risk assessments for new AI vendors, LLM platforms, AI APIs, and enterprise AI tools, including third-party risk scoring, control mapping, and remediation tracking * Manage the vendor risk ...

Execute risk assessments for new AI vendors, LLM platforms, AI APIs, and enterprise AI tools, including third-party risk scoring, control mapping, and remediation tracking * Manage the vendor risk ...

next page

Showing results 1-20

Third Party Risk Assessor information

See Massachusetts salary details

$21

$42

$73

How much do third party risk assessor jobs pay per hour?

As of Aug 19, 2026, the average hourly pay for third party risk assessor in Massachusetts is $42.25, according to ZipRecruiter salary data. Most workers in this role earn between $26.01 and $59.33 per hour, depending on experience, location, and employer.

What is a third party risk assessor?

Third Party Risk Assessors are professionals responsible for evaluating the risks associated with an organization’s vendors, suppliers, and other external partners. They assess potential threats such as cybersecurity vulnerabilities, compliance issues, financial instability, and operational risks that could impact the business through its third-party relationships. Their work helps ensure that organizations are protected from potential disruptions or breaches originating outside their direct control. By conducting thorough risk assessments, they support informed decision-making and help maintain regulatory compliance.

What are the key skills and qualifications needed to thrive as a third party risk assessor?

To thrive as a Third Party Risk Assessor, you need a solid understanding of risk management frameworks, vendor assessment procedures, and regulatory compliance, often supported by a degree in information security, business, or a related field. Familiarity with GRC (Governance, Risk, and Compliance) platforms, risk assessment tools, and industry certifications such as CISA or CRISC is typically required. Strong analytical thinking, attention to detail, and the ability to communicate findings clearly with stakeholders are crucial soft skills. These competencies ensure thorough evaluation of third-party vendors, effective risk mitigation, and compliance with organizational and regulatory standards.

What are some common challenges faced by third party risk assessors when evaluating vendors, and how can they be addressed?

Third Party Risk Assessors often encounter challenges such as incomplete vendor documentation, inconsistent risk assessment methodologies across departments, and rapidly changing regulatory requirements. To overcome these, assessors should establish clear communication channels with vendors, utilize standardized assessment frameworks, and stay updated on relevant compliance standards. Collaborating closely with internal stakeholders and leveraging automated risk management tools can also help streamline the evaluation process and ensure thorough risk mitigation.

What is the difference between Third Party Risk Assessor vs Vendor Risk Analyst?

AspectThird Party Risk AssessorVendor Risk Analyst
CertificationsISO 27001, CRISC, CISAISO 27001, CRISC, CISA
Work EnvironmentRisk management teams, compliance departmentsProcurement, compliance, and risk teams
Industry UsageFinancial, healthcare, technologyFinancial, healthcare, technology

The Third Party Risk Assessor and Vendor Risk Analyst roles often share similar certifications and work environments, focusing on evaluating third-party vendors' risks. While the Risk Assessor primarily conducts risk assessments and compliance reviews, the Vendor Risk Analyst may focus more on vendor performance and procurement processes. Both roles are essential in managing third-party relationships and ensuring organizational security and compliance.

What are popular job titles related to Third Party Risk Assessor jobs in Massachusetts?

For Third Party Risk Assessor jobs in Massachusetts, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Assessor jobs in Massachusetts look for?

The top searched job categories for Third Party Risk Assessor jobs in Massachusetts are:

Infographic showing various Third Party Risk Assessor job openings in Massachusetts as of August 2026, with employment types broken down into 1% As Needed, 91% Full Time, 6% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $87,872 per year, or $42.2 per hour.

Senior Director, Enterprise Third Party Risk

Vrtx

Boston, MA • Hybrid

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 6 days ago


Job description

Job Description

The Senior Director, Enterprise Third Party Risk Leader, will lead an expanded third-party risk management E2E process, including leading a Central Risk Management team and driving a holistic, effective and efficient third-party risk management approach for the enterprise. This leader will shape and maintain an integrated and enterprise view of third-party risk exposure across a holistic set of risk dimensions, collecting inputs from function and business leads and reporting to key stakeholders. The role will also maintain a comprehensive understanding of the company's business strategies, organizational structures, resources and risks, policies and procedures and have responsibility for deploying cross-functional leadership of fit-for purpose risk practices across the Vertex risk community of risk subject matter experts, business owners, and executive leadership.

The leader will work collaboratively with internal Stakeholders, develop sound third party risk strategies, utilize knowledge and expertise of processes, leverage best practices and drive risk visibility and ultimately risk management actions. The leader will partner with Business Owners and Risk SMEs to effectively and efficiently manage third party risks through actions including risk mitigation and risk acceptance, alongside a transparent enterprise governance process for managing and underwriting risks.

As a senior member of the Strategic Sourcing group, this leadership role will be expected to provide strategic input in the future direction of the function.They will possess high-level business partnering acumen and subject matter expertise in third-party risk management processes and tools.Working collaboratively with strategic sourcing teams and internal Business Stakeholders, the leader is expected to ensure their teams' activities are aligned with Business priorities and objectives.This role will communicate with senior-most Executives and be viewed as a trusted business advisor crucial to their business.The role will effectively articulate the vision and value to the business.

Key Duties & Responsibilities

  • Leadership responsibility for coordinating all aspects of a central enterprise risk management program and team, ensuring that the end-to-end (E2E) third party risk management processes are implemented and sustained, team members are fulfilling their roles and responsibilities, and reports are consistent with Corporate and risk policies

  • Oversee supplier criticality assessments for all suppliers using a unified and holistic approach deployed along the supplier life cycle, and leverage the criticality dimensions for fit for purpose risk process prioritization

  • Oversee third party risk assessment and regular updates for critical suppliers along the supplier life cycle leveraging a central risk tool, working with business leads to provide required inputs and ensuring other metrics are automated and updated

  • Maintain centralized supplier risk repository for visibility to third party risks and action plans, timelines and ownership, including creating regular reports on multi-dimensional supplier risk with the CRM team

  • Maintain and regularly update risk appetite matrix and list of risk mitigation actions, syndicating with and eliciting input from business leads as needed

  • Coordinate, support preparation of, and participate in joint reviews of mitigation actions, working with business leads and risk SMEs and escalating when necessary

  • Ensure E2E process is supported by appropriate tools and technology solutions in partnership with DTE, including standing up a centralized supplier risk register and automating risk assessment and tracking activities

  • Coordinate, support preparation of, and participate in escalation governance committees (i.e., cross-functional governance meetings, executive level governance meetings)

  • Manage and lead within a matrix of dedicated and assigned resources across a hybrid centralized and federated risk management operating model.

  • Work with HR and Communications team to coordinate and launch training and communications plan for ongoing process awareness across the enterprise

  • Collaborate with Executive leaders, function leads, and business leads to role model new processes

  • Partner with strategic sourcing and business owners to ensure understanding of supplier landscape existing and future potential and integrate into the third-party risk management strategy to drive enterprise risk visibility and actions to manage risks through actions focus on immediate mitigations, mitigation plans with future timelines, and risk acceptance strategies.

  • Own the enterprise third party risk management process, policies and procedures, and effective execution of same in partnership with risk SMEs and business owners, including effective governance, RACIs, and inherent and residual risk monitoring and reporting.

  • Partner with key stakeholders to develop relevant risk metrics and KPIs, including process KPIs and SLAs to drive to drive the right risk management behaviors and actions; Oversee reporting on impact measurements and program outcomes

  • Establish and promote best practices across the organization; Regularly review practices based on industry trends, regulatory changes, and organizational needs and address emerging challenges and opportunities; leverage best practices for continuous improvement

Required Education

  • University degree in Accounting, Finance or Risk Management

  • Certified professional certifications are preferred

Required Experience

  • 12+ years' experience in the area of risk is required.

  • Experience within a large multinational, publicly held company is highly preferred

Required Knowledge and Skills

  • Strong knowledge of risk management policies and procedures, preferably related to third parties

  • Excellent verbal and written communication skills; ability to effectively communicate with senior leadership team and third parties

  • Superior business and analytical skills, ability to focus on key issues and solve problems, bring an enterprise mindset, and effectively track and create visibility and report on risk processes and outcomes.

  • Ability to work in a collaborative, team environment; ability to cultivate and maintain effective business partner relationships through earned respect and trust; collaboration extends beyond Business Partners and suppliers to include other functional areas with risk SMEs and business owners

  • Able to lead direct and cross-functional teams in a collaborative manner to drive successful outcomes.

  • Adept at influencing and bringing new ideas and information that create tangible value to business.

  • Strong process management and demonstrated use of Continuous Improvement mindset and tools (including Pareto Charts, Flow Diagrams, etc.) to drive process improvements

  • Strong project management and organizational skills. Able to create detailed project plans, including an understanding of dependencies as well as critical path elements for larger, more involved projects. Track record of successful execution of complex, cross-functional initiatives.

  • Able to establish and maintain effective business partner relationships at highest levels within the organization; gained their respect and trust; Thoughtful and active listener; able to think quickly and effectively articulate points of view.

  • Ability to establish and lead an effective governance program that continues to elevate third party risk management and oversight for the company.

Pay Range:

$220,000 - $330,000

Disclosure Statement:

The range provided is based on what we believe is a reasonable estimate for the base salary pay range for this job at the time of posting. This role is eligible for an annual bonus and annual equity awards. Some roles may also be eligible for overtime pay, in accordance with federal and state requirements. Actual base salary pay will be based on a number of factors, including skills, competencies, experience, and other job-related factors permitted by law.

At Vertex, our Total Rewards offerings also include inclusive market-leading benefits to meet our employees wherever they are in their career, financial, family and wellbeing journey while providing flexibility and resources to support their growth and aspirations. From medical, dental and vision benefits to generous paid time off (including a week-long company shutdown in the Summer and the Winter), educational assistance programs including student loan repayment, a generous commuting subsidy, matching charitable donations, 401(k) and so much more.

Flex Designation:

Hybrid-Eligible Or On-Site Eligible

Flex Eligibility Status:

In this Hybrid-Eligible role, you can choose to be designated as:
1. Hybrid: work remotely up to two days per week; or select
2. On-Site: work five days per week on-site with ad hoc flexibility.

Note: The Flex status for this position is subject to Vertex's Policy on Flex @ Vertex Program and may be changed at any time.

#LI-Hybrid

Company Information

Vertex is a global biotechnology company that invests in scientific innovation.

Vertex is committed to equal employment opportunity and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry, ethnicity, disability, veteran status, genetic information, sexual orientation, marital status, or any characteristic protected under applicable law. Vertex is an E-Verify Employer in the United States. Vertex will make reasonable accommodations for qualified individuals with known disabilities, in accordance with applicable law.

Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should make a request to the recruiter or hiring manager, or contact Talent Acquisition at ApplicationAssistance@vrtx.com