1

Third Party Risk Jobs in Virginia (NOW HIRING)

Senior Analyst

Norfolk, VA

$85K - $112K/yr

Third Party Risk Management (TPRM) Senior Analyst is responsible for ensuring the organization effectively manages risks associated with third-party vendors and partners throughout the entire third ...

... of third-party risk identification, assessment, mitigation, and reporting across NIPRNet, SIPRNet, and JWICS environments in compliance with DoW SCRM policy, Risk Management Framework requirements ...

Management, Internal Audit, Third Party Risk Management, etc. Basic Qualifications: * Bachelor's Degree in Business Or Marketing. * 4+ years of experience in Financial Services, Marketing, Compliance ...

Management, Internal Audit, Third Party Risk Management, etc. Basic Qualifications: * Bachelor's Degree in Business Or Marketing. * 4+ years of experience in Financial Services, Marketing, Compliance ...

Management, Internal Audit, Third Party Risk Management, etc. Basic Qualifications: * Bachelor's Degree in Business Or Marketing. * 4+ years of experience in Financial Services, Marketing, Compliance ...

next page

Showing results 1-20

Third Party Risk information

See Virginia salary details

$14

$30

$73

How much do third party risk jobs pay per hour?

As of Jun 9, 2026, the average hourly pay for third party risk in Virginia is $30.08, according to ZipRecruiter salary data. Most workers in this role earn between $19.33 and $38.37 per hour, depending on experience, location, and employer.

What are some common challenges faced in a Third Party Risk role and how can they be managed?

Professionals in Third Party Risk often encounter challenges such as managing a large and diverse vendor portfolio, staying updated on regulatory requirements, and ensuring timely risk assessments. Navigating communication gaps between internal stakeholders and external vendors can also be demanding. These challenges are typically managed by implementing robust risk assessment frameworks, fostering cross-functional collaboration, and leveraging technology to streamline due diligence and monitoring processes. Continuous training and clear communication protocols further help in addressing these complexities and maintaining effective third-party risk management.

What is the difference between Third Party Risk vs Vendor Risk Management?

AspectThird Party RiskVendor Risk Management
FocusAssessing risks from all external entities, including vendors, partners, and contractorsEvaluating risks specifically associated with third-party vendors
CredentialsRisk management certifications, compliance knowledgeVendor management certifications, procurement experience
Work EnvironmentCorporate risk teams, compliance departmentsProcurement, vendor management teams
Industry UsageFinancial, healthcare, technology sectorsPrimarily in supply chain and procurement functions

Third Party Risk encompasses a broader scope, including all external entities, while Vendor Risk Management specifically focuses on vendors. Both roles require risk assessment skills and industry knowledge, but Third Party Risk roles often involve broader compliance and strategic oversight.

What are the key skills and qualifications needed to thrive as a Third Party Risk professional, and why are they important?

To thrive as a Third Party Risk professional, you need a solid understanding of risk management principles, vendor assessment processes, and relevant regulatory frameworks, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) software, and certifications such as Certified Third Party Risk Professional (CTPRP) are common requirements. Strong analytical thinking, attention to detail, and effective communication skills help you evaluate vendors and influence stakeholders. These skills are vital for identifying, mitigating, and managing risks associated with third-party relationships to protect organizational integrity and compliance.

What is Third Party Risk?

Third Party Risk refers to the potential risks and vulnerabilities an organization faces when working with external vendors, suppliers, or service providers. These risks can include data breaches, compliance violations, operational disruptions, and reputational damage resulting from the actions or failures of third parties. Managing third party risk involves identifying, assessing, monitoring, and mitigating these risks to protect the organization’s interests and ensure regulatory compliance.
What are the most commonly searched types of Third Party Risk jobs in Virginia? The most popular types of Third Party Risk jobs in Virginia are:
What job categories do people searching Third Party Risk jobs in Virginia look for? The top searched job categories for Third Party Risk jobs in Virginia are:
What cities in Virginia are hiring for Third Party Risk jobs? Cities in Virginia with the most Third Party Risk job openings:
Infographic showing various Third Party Risk job openings in Virginia as of May 2026, with employment types broken down into 2% As Needed, 78% Full Time, 16% Part Time, 2% Temporary, and 2% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution, with an average salary of $62,558 per year, or $30.1 per hour.
Senior Manager, Vendor Risk & Procurement Governance - Mobility

Senior Manager, Vendor Risk & Procurement Governance - Mobility

S&P Global

Centreville, VA • On-site

$94K - $127K/yr

Full-time

Posted 7 days ago


S&P Global rating

8.0

Company rating: 8.0 out of 10

Based on 5 frontline employees who took The Breakroom Quiz


Job description

S&P Global has recently announced the intent to separate our Mobility Segment into a standalone public company.

For more information, visit www.spglobal.com/mobility.

The Role:

Operating across 22 countries, Mobility Global is strengthening its third-party governance framework to support regulatory compliance, information security, and enterprise risk management.

Reporting to the Global Head of Procurement, the Senior Manager, Vendor Risk & Procurement Governance, will lead the operational implementation of the Company's vendor risk management process within Procurement. While Legal Risk & Compliance will design and maintain the enterprise risk framework, this role will be responsible for embedding that framework into procurement workflows, configuring system controls within Coupa, developing employee-facing policy documentation, and ensuring all required vendor risk reviews are completed prior to vendor onboarding or renewal.

This role serves as the operational bridge between Procurement, Legal, Risk & Compliance, and Information Security.

Responsibility and Impact:

Vendor Risk Process Operationalization

  • Translate the enterprise vendor risk framework into scalable procurement processes.

  • Embed vendor risk review requirements into end-to-end sourcing and purchasing workflows.

  • Define intake requirements and risk-tiering triggers for vendor engagements.

  • Establish escalation procedures for incomplete or delayed risk reviews.

  • Drive continuous improvement in vendor risk governance processes.

Coupa Workflow Design & Governance

  • Configure and maintain vendor risk workflows and approval gates within Coupa.

  • Implement system controls to prevent PO issuance without required risk approvals.

  • Maintain vendor risk attributes, classifications, and documentation repositories.

  • Partner with Finance Systems and IT to enhance automation and reporting.

  • Develop dashboards and reporting to monitor review completion, SLAs, and compliance trends.

Policy & Documentation Development

  • Draft and maintain procurement-facing vendor risk policies and SOPs.

  • Develop clear employee guidance materials explaining:

    • When vendor risk reviews are required

    • How to initiate a review

    • Required documentation

    • Approval requirements and timelines

  • Ensure alignment between procurement policy and Legal Risk standards.

  • Conduct training sessions for business stakeholders.

Risk Review Coordination & Enforcement

  • Ensure all required vendor risk reviews by:

    • Legal Risk & Compliance

    • Information Security

    • Data Privacy

    • Other applicable stakeholders
      are completed prior to vendor onboarding or contract renewal.

  • Monitor review timelines and escalate exceptions.

  • Maintain documentation of approvals, conditions, and remediation requirements.

  • Track and report compliance metrics to Procurement and Finance leadership.

Audit & Compliance Support

  • Maintain audit-ready documentation of vendor risk approvals and workflows.

  • Support SOX-related vendor governance controls where applicable.

  • Partner with Internal Audit on third-party risk assessments.

  • Support remediation efforts tied to vendor governance findings.

Cross-Functional Collaboration

  • Serve as key liaison between Procurement and:

    • Legal Risk & Compliance

    • Information Security

    • Finance & Accounting

    • Internal Audit

  • Drive accountability across business units engaging third parties.

  • Promote a culture of governance and risk awareness.

What We're Looking For:

Basic Required Qualifications:

  • Bachelor's degree in Business, Supply Chain, Risk Management, Finance, or related field or equivalent relevant experience.

  • 7 to 10+ years of experience in Procurement, Third-Party Risk, Compliance, or Governance.

  • Experience in a publicly traded or highly regulated organization preferred.

  • Direct experience implementing vendor risk workflows in Coupa strongly preferred.

  • Strong understanding of third-party risk domains, including:

    • Information security

    • Data privacy

    • Regulatory and compliance risk

    • Operational and financial risk

  • Experience developing policy documentation and process controls.

  • Strong systems and workflow configuration experience.

Additional Preferred Qualifications:

  • Governance-oriented with strong attention to detail.

  • Systems-minded and process-driven.

  • Confident cross-functional influencer.

  • Able to enforce controls in a collaborative but firm manner.

  • Comfortable operating in a transformation-oriented, post-spin environment.

Compensation/Benefits Information (US Applicants Only): Final base salary for this role will be based on the individual's geographic location, as well as experience level, skill set, training, licenses, and certifications. In addition to base compensation, this role is eligible for an annual incentive plan. This role is eligible to receive additional S&P Global benefits. For more information on the benefits that we provide to our employees, please click here.

Right to Work Requirements:

This role is limited to persons with indefinite right to work in the United States.

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!

It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.