1

Third Party Vendor Risk Jobs in Virginia (NOW HIRING)

Payroll Manager

Richmond, VA · On-site

$45 - $60/hr

... emphasis on risk, compliance, and executive compensation (including RSUs/PSUs ). Key ... Manage third-party vendor relationships, including SLAs , performance monitoring, and ensuring ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$97K - $132K/yr

Lead third-party vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations. * Direct the security ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

... third-party vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations. • Direct the security ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

... third-party vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations. • Direct the security ...

GRC Lead

Fairfax, VA · On-site

$95K - $120K/yr

Own third-party and vendor risk assessments across our tooling and supply chain. * Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and ...

... third-party vendor relationships. The Director of Benefits Operations will drive operational excellence, best practices, organizational effectiveness, technology optimization, and risk management ...

Showing results 41-60

Third Party Vendor Risk information

What is third party vendor risk?

Third party vendor risk refers to the potential threats and vulnerabilities that arise when an organization outsources services or shares sensitive information with external vendors, suppliers, or partners. These risks can include data breaches, compliance violations, operational disruptions, and reputational damage resulting from a vendor’s actions or failures. Assessing and managing third party vendor risk is crucial for organizations to ensure that their vendors maintain adequate security controls and comply with regulatory requirements.

What are some common challenges faced in a third party vendor risk role, and how can they be managed effectively?

Professionals in Third Party Vendor Risk often face challenges such as staying updated with evolving regulations, managing a large portfolio of vendors, and ensuring effective communication across internal stakeholders. Balancing thorough risk assessments with operational deadlines can also be demanding. To manage these challenges, it's important to establish standardized evaluation processes, leverage automation tools for tracking and monitoring, and foster strong collaboration with procurement, legal, and IT teams to ensure all risks are identified and mitigated in a timely manner.

What are the key skills and qualifications needed to thrive as a third party vendor risk professional, and why are they important?

To thrive as a Third Party Vendor Risk professional, you need a strong understanding of risk management, compliance, and vendor due diligence, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and relevant certifications like CTPRP or CISA is highly valued. Excellent analytical skills, attention to detail, and effective communication are essential soft skills for collaborating with vendors and internal stakeholders. These competencies are critical for identifying, mitigating, and monitoring risks to protect organizational assets and ensure regulatory compliance.

What is the difference between Third Party Vendor Risk vs Vendor Management Specialist?

AspectThird Party Vendor RiskVendor Management Specialist
Primary FocusAssessing and mitigating risks associated with third-party vendorsManaging vendor relationships and performance
CertificationsCertifications like Certified Third Party Risk Professional (CTPRP) often preferredCertifications like Certified Vendor Management Professional (CVMP) may be relevant
Work EnvironmentRisk assessment, compliance, and audit settingsContract negotiations, relationship management, and performance tracking
Industry UsageCommon in finance, healthcare, and technology sectorsUsed across various industries for vendor oversight

While both roles involve working with vendors, Third Party Vendor Risk focuses on identifying and mitigating risks posed by third-party vendors, ensuring compliance and security. Vendor Management Specialists concentrate on maintaining vendor relationships, contract management, and performance optimization. Understanding these distinctions helps organizations assign the right responsibilities and ensure effective vendor oversight.

Infographic showing various Third Party Vendor Risk job openings in Virginia as of August 2026, with employment types broken down into 75% Full Time, and 25% Contract. Highlights an 100% In-person job distribution.

Senior Business Analyst - Third Party Risk Management (TPRM)

Mclean, VA • On-site

Capital One
Funds, Trusts and Financial Programs • 10K+ employees

Full-time

Posted 19 days ago


Capital One rating

7.8

Company rating: 7.8 out of 10

Based on 148 frontline employees who took The Breakroom Quiz


Job description

Senior Business Analyst - Third Party Risk Management (TPRM)
About the Role:
Capital One is seeking a highly motivated, strategic and analytically adept Senior Business Analyst to join our Third Party Risk Management (TPRM) team. Sitting within the Operational Risk Management (ORM) second line of defense, our team provides value-add, independent stewardship of Capital One's Third Party Risk Management (TPRM) Program.
As a self-starter who thrives on autonomy, you will balance day-to-day business-as-usual (BAU) responsibilities with high-impact, long-term strategic initiatives. You are someone who excels at solving problems, collaborating with cross-functional stakeholders, and translating data into actionable risk insights.
Key Responsibilities:
Data Management & Reporting
  • Data Leverage: Build and maintain sophisticated reports using platforms like Snowflake, Databricks, QuickSight,Google Sheets, and Microsoft Excel.
  • Technical Execution: Utilize SQL, advanced formulas, and data manipulation techniques to extract and analyze risk data.
  • Insight Generation: Analyze data sets to proactively identify emerging risks, trends, and gaps, translating data into meaningful business intelligence.

Collaboration & Stakeholder Influence
  • Cross-Functional Synergy: Foster seamless, integrated risk experiences by bridging gaps between various internal risk teams and business partners.
  • Project Coordination: Manage simultaneous projects, leveraging and influencing stakeholders across the enterprise to drive risk informed decisions.
  • Relationship Building: Develop strong, trusted relationships with key partners to foster a collaborative culture of proactive risk management.

Basic Qualifications:
  • At least 2 years of professional experience performing analysis
  • Currently has, or is in the process of obtaining one of the following with an expectation that the required degree will be obtained on or before the scheduled start date:
    • A Bachelor's Degree in a quantitative field (Business, Finance, Accounting, Statistics, Economics, Operations Research, Analytics, Mathematics, Computer Science, Computer engineering, Software engineering, Mechanical engineering, Information Systems or a related quantitative field)
    • A Master's Degree in a quantitative field (Business, Finance, Accounting, Statistics, Economics, Operations Research, Analytics, Mathematics, Computer Science, Computer Engineering, Software Engineering, Mechanical engineering, Information Systems or a related quantitative field) or an MBA with a quantitative concentration

Preferred Qualifications:
  • Master's Degree in Business or quantitative field such as Finance, Economics, Physical Sciences, Math, Statistics, Engineering
  • 1+ years of experience in Statistical model building
  • 1+ years of experience in market research
  • 1+ years of experience in SQL querying
  • 2+ years of experience in business analysis
  • 1+ years of experience in consulting

Capital One will consider sponsoring a new qualified applicant for employment authorization for this position.
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Chicago, IL: $101,100 - $115,400 for Sr. Business Analyst
McLean, VA: $111,200 - $126,900 for Sr. Business Analyst
Richmond, VA: $101,100 - $115,400 for Sr. Business Analyst
Riverwoods, IL: $101,100 - $115,400 for Sr. Business Analyst
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.
No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1-800-304-9102 or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to Careers@capitalone.com
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).

What Capital One employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom