1

Vendor Risk Analyst Jobs in Massachusetts (NOW HIRING)

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program ... You will help manage third-party vendor risk reviews, and operational requests, in cross-functional ...

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program ... You will help manage third-party vendor risk reviews, and operational requests, in cross-functional ...

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program ... You will help manage third-party vendor risk reviews, and operational requests, in cross-functional ...

As a GRC Analyst, you will support the WHOOP Governance, Risk, and Compliance program ... You will help manage third-party vendor risk reviews, and operational requests, in cross-functional ...

Investment Risk Analyst

Boston, MA · On-site

$75K - $90K/yr

Investment Risk Analyst Pioneer Investments is a diversified asset management firm and a key franchise of Victory Capital Management (VCTR). Founded in 1928, Pioneer currently manages over $125 ...

Investment Risk Analyst Pioneer Investments is a diversified asset management firm and a key franchise of Victory Capital Management (VCTR). Founded in 1928, Pioneer currently manages over $125 ...

Supplier Risk Management * Quality Management Systems (QMS) * Regulatory Compliance * Vendor Qualification & Oversight * Supplier Audits * Quality Metrics & KPI Analysis * CAPA (Corrective and ...

The IT Risk Analyst's primary responsibility will be to conduct various risk assessments, including control design assessments, and control operating effectiveness testing for core IT processes, and ...

The IT Risk Analyst's primary responsibility will be to conduct various risk assessments, including control design assessments, and control operating effectiveness testing for core IT processes, and ...

Insurance & Risk Analyst

Milford, MA · On-site

$80K - $100K/yr

Director of Risk Management Supervisory Duties: No Salary Range: $80,000 - $100,000 The Insurance & Risk Analyst is a key member of the Risk Management team, supporting the identification, analysis ...

next page

Showing results 1-20

Vendor Risk Analyst information

See Massachusetts salary details

$16

$44

$71

How much do vendor risk analyst jobs pay per hour?

As of Jul 26, 2026, the average hourly pay for vendor risk analyst in Massachusetts is $44.21, according to ZipRecruiter salary data. Most workers in this role earn between $32.55 and $53.80 per hour, depending on experience, location, and employer.

Do risk analysts make a lot of money?

Risk analysts, including vendor risk analysts, typically earn a competitive salary that varies by experience, industry, and location. Entry-level positions may start around $50,000 annually, while experienced professionals can earn over $100,000, especially with certifications like CRCM or CISA. The role often requires strong analytical skills and knowledge of risk management tools.

What is an example of a vendor risk?

A vendor risk for a Vendor Risk Analyst involves the potential for a third-party supplier or service provider to cause harm to the organization, such as data breaches, non-compliance with regulations, or operational disruptions. Assessing these risks requires evaluating the vendor's security controls, financial stability, and compliance history to mitigate potential impacts on the organization.

Is risk analyst an entry level job?

A risk analyst role can be entry-level or require more experience depending on the organization. Entry-level risk analyst positions typically require a bachelor's degree in finance, economics, or a related field, and may involve basic data analysis skills and familiarity with risk management tools. Advancing in this field often involves gaining certifications like FRM or CRM and developing stronger analytical and industry-specific knowledge.

What is a Vendor Risk Analyst?

A Vendor Risk Analyst is a professional responsible for assessing and managing risks associated with third-party vendors that provide products or services to an organization. They evaluate vendor practices, security protocols, and compliance with regulations to minimize potential risks such as data breaches, financial losses, or operational disruptions. Their work helps organizations ensure that vendors meet required standards and do not pose undue risk to business operations. Vendor Risk Analysts often use questionnaires, audits, and ongoing monitoring to perform their assessments.

How does a Vendor Risk Analyst typically collaborate with other departments within an organization?

Vendor Risk Analysts work closely with various departments such as procurement, legal, IT security, and compliance to assess and manage risks associated with third-party vendors. They facilitate communication between teams to ensure vendor contracts meet security and regulatory requirements. Regularly, they coordinate risk assessments, share findings, and help develop mitigation strategies, ensuring that vendor relationships support the organization's risk tolerance and business goals.

What are the key skills and qualifications needed to thrive as a Vendor Risk Analyst, and why are they important?

To thrive as a Vendor Risk Analyst, you need strong analytical skills, knowledge of risk management frameworks, and a relevant degree in business, finance, or a related field. Familiarity with third-party risk management platforms, regulatory compliance tools, and certifications like Certified Third Party Risk Professional (CTPRP) are often required. Excellent communication, attention to detail, and problem-solving abilities help you effectively assess vendor risks and collaborate with cross-functional teams. These competencies ensure your organization can identify, mitigate, and manage risks associated with external vendors, protecting both operational integrity and regulatory compliance.

What does a vendor analyst do?

A vendor risk analyst evaluates third-party vendors to ensure they meet security, compliance, and operational standards. They review contracts, perform risk assessments, and monitor vendor performance using tools like risk management software to mitigate potential threats to the organization.
What are the most commonly searched types of Vendor Risk Analyst jobs in Massachusetts? The most popular types of Vendor Risk Analyst jobs in Massachusetts are:
What are popular job titles related to Vendor Risk Analyst jobs in Massachusetts? For Vendor Risk Analyst jobs in Massachusetts, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Analyst jobs in Massachusetts look for? The top searched job categories for Vendor Risk Analyst jobs in Massachusetts are:
Infographic showing various Vendor Risk Analyst job openings in Massachusetts as of July 2026, with employment types broken down into 87% Full Time, 8% Part Time, 2% Temporary, and 3% Contract. Highlights an 72% In-person, 17% Hybrid, and 11% Remote job distribution, with an average salary of $91,967 per year, or $44.2 per hour.
Principal/Senior Technology Risk Analyst

Principal/Senior Technology Risk Analyst

Berkshire Hathaway Specialty Insurance

Boston, MA • On-site

$160K - $180K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago


Job description

Who are we?


A strategic and trusted insurance partner, Berkshire Hathaway Specialty Insurance (BHSI), provides a broad range of commercial property, casualty and specialty insurance coverages and outstanding service to customers and brokers around the world. Part of Berkshire Hathaway’s insurance operations, we bring our solutions to market with our stellar brand name, top-rated balance sheet, and the expertise of our global team of professionals, who exude excellent capabilities and strong character.


We are a values-based organization where respect, integrity, excellence, collaboration, and passion define who we are and how we do business. We value diversity of backgrounIds, experience, and perspectives and strive to foster an inclusive environment that enables all our team members to bring their best selves to work. We are one team committed to building a culture where every teammate has the opportunity to contribute and be recognized. Want to be part of the team building the finest property, casualty and specialty lines insurance company in the world?


Learn more about our unique culture and history.


Job Opportunity:

Berkshire Hathaway Specialty Insurance (BHSI) has an exciting opportunity for a new team member to join their Boston-based Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology Senior Risk Analyst will support and mature the Technology Risk Management pillar, ensuring technology risks are proactively identified, assessed, communicated, and monitored across the enterprise. This role will build strong partnerships with Technology leadership and collaborate closely with teams across BHSI to evaluate our Technology risk posture, provide independent challenge, and recommend practical risk‑reducing actions aligned with our established risk appetite. If you're passionate about elevating enterprise Technology risk practices, driving meaningful change, and growing your career as a key contributor to our evolving global IT risk program, we’re interested in speaking with you.


Duties & Responsibilities:

  • Lead risk identification, risk assessment, and ongoing monitoring; maintain the Technology risk register and ensure risks map to business objectives and risk appetite/tolerances.
  • Drive Risk and Control Self‑Assessments (RCAs) with different risk and control owners; advise on control design for identity & access, change/release, resiliency/DR, cloud security, data protection, and vulnerability management.
  • Define and socialize KRIs/KPIs, risk dashboards, trends, and heat maps; deliver clear status to Technology leadership, and key stakeholders.
  • Partner with Vendor Risk Management Team to evaluate critical vendors (including AI‑enabled services), review SOC reports/certifications, assess control gaps, and track remediation/compensating controls through closure.
  • Track risk issues, action plans, and target dates; validate remediation and retest where needed; participate in lessons‑learned and scenario exercises.
  • Provide support to our offices from both a U.S. and global perspective (i.e., Asia, Middle East, UK, Europe, Australasia, etc.) regarding the fulfillment of Technology risk related requests and obligations.
  • Assess AI/automation use cases for explainability, privacy, security, and bias risk; ensure appropriate documentation, monitoring, and governance are in place.
  • Educate teams on risk expectations, evidence quality, and the “why” behind controls; help embed risk thinking into delivery and operations.
  • Attend/participate in e-learning training sessions to increase background knowledge of the ever-evolving Technology regulatory landscape.

Qualifications, Skills and Experience:

  • 10+ years of experience in Technology risk, Technology audit/compliance, or cyber GRC.
  • Experience running RCSAs, defining KRIs/KPIs, and presenting risk insights to senior stakeholders.
  • Strong documentation skills, including writing risk narratives, control designs, control matrices, testing procedures, and remediation plans.
  • Effective communication and partnership skills; able to challenge constructively and receive challenge professionally.
  • Experience conducting vendor risk reviews, including SOC 2 analysis, control gap identification, and remediation follow‑up.
  • Solid background knowledge of major risk and control frameworks (Technology, Cyber, Enterprise), such as NIST CSF, COSO ERM, COBIT, etc.
  • Working knowledge of U.S. Technology regulations (e.g., SOX, CCPA/CPRA, PCI, NY‑DFS) is recommended.
  • Familiarity with global regulatory frameworks (e.g., GDPR, CBI, DORA, MAS, APRA, BaFin) is preferred but not required.
  • Ability to work in a team-based environment and communicate effectively and efficiently with others domestically and globally.
  • Experience with GRC tools such as Workiva, AuditBoard, ServiceNow, Drata, Vanta, or similar platforms is a plus.
  • AI experience is a plus, including an understanding of AI risks, responsible AI concepts, or emerging AI regulatory requirements.
  • Professional certifications such as CRISC, CISA, CISM, CISSP, or ISO/IEC 27001 Lead Implementer/Lead Auditor (or equivalent) are a plus.


BHSI Offers:


  • A competitive package and exciting growth opportunities for career-oriented teammates.
  • A dynamic, action oriented, and thoughtful environment centered on always doing the right thing for our customers, teammates and our other stakeholders.
  • A purposely non-bureaucratic organization that embraces simplicity over complexity and emphasizes individual excellence in a team framework.
  • Benefits that support your life and well-being, which include:
    • Comprehensive Health, Dental and Vision benefits.
    • Disability Insurance (both short-term and long-term).
    • Life Insurance (for you and your family).
    • Accidental Death & Dismemberment Insurance (for you and your family).
    • Flexible Spending Accounts.
    • Health Reimbursement Account.
    • Employee Assistance Program.
    • Retirement Savings 401(k) Plan with Company Match.
    • Generous holiday and Paid Time Off.
    • Tuition Reimbursement.
    • Paid Parental Leave.


The base salary range for this position in Boston is $160,000.00 to $180,000.00, along with annual bonus eligibility. Total compensation for a candidate is determined by their relevant skills, location, and experience. We value our teammates – both their capabilities and character – as demonstrated by our amazing culture.


NOTE: Compensation will be commensurate with experience. This job description is not intended to be all-inclusive. Team Member may perform other related duties as negotiated to meet the ongoing needs of the organization.