1

Vendor Risk Analyst Jobs in New York (NOW HIRING)

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Vendor Risk Manager Dalio Family Office Dalio Family Office Overview: The Dalio Family Office (DFO ... Strong risk assessment and analytical skills * Technical understanding of enterprise security ...

Risk Analyst

Hauppauge, NY ยท On-site

$65K - $80K/yr

The Risk Analyst is part of Dime's Second Line of Defense. NOTE: This role is risk management over processes within the Bank and is NOT data analytics/risk management in investment banking. This role ...

Risk Analyst

Hauppauge, NY ยท On-site

$65K - $80K/yr

Under the direction of the Risk Manager, the Risk Analyst is responsible for the completion of assigned process-level risk and control self-assessments (RCSAs) in collaboration with business managers ...

AECOM Technical Services, Inc. is seeking a Risk Analyst in New York, NY: Job Details: * Review project documents and analyze project data to develop risk profiles and risk registers for projects and ...

Risk Analyst

New York, NY ยท On-site +1

$100K - $175K/yr

Role Overview We are hiring our first Fraud/Risk Analyst to join our Risk & Compliance team . This role will focus on identifying, analyzing, and mitigating risks associated with digital asset ...

Risk Analyst

Manhattan, NY ยท On-site

$63K - $73K/yr

The Analyst will work with internal and external stakeholders in quantifying and analyzing risk results and practice patterns to explain and financial performance and key drivers. Scope of Role ...

The Enterprise Risk Analyst supports the development, implementation, and continuous enhancement of the organization's Enterprise Risk Management (ERM) framework within a property and casualty ...

AECOM Technical Services, Inc. is seeking a Risk Analyst in New York, NY: Job Details: * Review project documents and analyze project data to develop risk profiles and risk registers for projects and ...

Risk Analyst

New York, NY ยท On-site

$100K - $175K/yr

Role Overview We are hiring our first Fraud/Risk Analyst to join our Risk & Compliance team . This role will focus on identifying, analyzing, and mitigating risks associated with digital asset ...

Risk Analyst

New York, NY ยท Remote

$100K - $175K/yr

Role Overview We are hiring our first Fraud/Risk Analyst to join our Risk & Compliance team . This role will focus on identifying, analyzing, and mitigating risks associated with digital asset ...

The Risk Analyst is responsible for reconciling, analyzing, and reporting the middle office P&L and risk position. The ideal candidate will possess the interpersonal skills to work well with all ...

The Risk Analyst is responsible for reconciling, analyzing, and reporting the middle office P&L and risk position. The ideal candidate will possess the interpersonal skills to work well with all ...

Job Summary Risk Analyst is responsible to review and analyze financials and credit of merchant accounts, merchant financial and activity risk, compliance with law and association rules and other ...

AECOM Technical Services, Inc. is seeking a Risk Analyst in New York, NY: Job Details: * Review project documents and analyze project data to develop risk profiles and risk registers for projects and ...

Risk Analyst

Manhattan, NY ยท Hybrid

$63K - $73K/yr

The Analyst will work with internal and external stakeholders in quantifying and analyzing risk results and practice patterns to explain and financial performance and key drivers. Scope of Role ...

next page

Showing results 1-20

Vendor Risk Analyst information

See New York salary details

$16

$44

$72

How much do vendor risk analyst jobs pay per hour?

As of Jul 28, 2026, the average hourly pay for vendor risk analyst in New York is $44.29, according to ZipRecruiter salary data. Most workers in this role earn between $32.60 and $53.89 per hour, depending on experience, location, and employer.

Do risk analysts make a lot of money?

Risk analysts, including vendor risk analysts, typically earn a competitive salary that varies by experience, industry, and location. Entry-level positions may start around $50,000 annually, while experienced professionals can earn over $100,000, especially with certifications like CRCM or CISA. The role often requires strong analytical skills and knowledge of risk management tools.

What is an example of a vendor risk?

A vendor risk for a Vendor Risk Analyst involves the potential for a third-party supplier or service provider to cause harm to the organization, such as data breaches, non-compliance with regulations, or operational disruptions. Assessing these risks requires evaluating the vendor's security controls, financial stability, and compliance history to mitigate potential impacts on the organization.

Is risk analyst an entry level job?

A risk analyst role can be entry-level or require more experience depending on the organization. Entry-level risk analyst positions typically require a bachelor's degree in finance, economics, or a related field, and may involve basic data analysis skills and familiarity with risk management tools. Advancing in this field often involves gaining certifications like FRM or CRM and developing stronger analytical and industry-specific knowledge.

What is a Vendor Risk Analyst?

A Vendor Risk Analyst is a professional responsible for assessing and managing risks associated with third-party vendors that provide products or services to an organization. They evaluate vendor practices, security protocols, and compliance with regulations to minimize potential risks such as data breaches, financial losses, or operational disruptions. Their work helps organizations ensure that vendors meet required standards and do not pose undue risk to business operations. Vendor Risk Analysts often use questionnaires, audits, and ongoing monitoring to perform their assessments.

How does a Vendor Risk Analyst typically collaborate with other departments within an organization?

Vendor Risk Analysts work closely with various departments such as procurement, legal, IT security, and compliance to assess and manage risks associated with third-party vendors. They facilitate communication between teams to ensure vendor contracts meet security and regulatory requirements. Regularly, they coordinate risk assessments, share findings, and help develop mitigation strategies, ensuring that vendor relationships support the organization's risk tolerance and business goals.

What are the key skills and qualifications needed to thrive as a Vendor Risk Analyst, and why are they important?

To thrive as a Vendor Risk Analyst, you need strong analytical skills, knowledge of risk management frameworks, and a relevant degree in business, finance, or a related field. Familiarity with third-party risk management platforms, regulatory compliance tools, and certifications like Certified Third Party Risk Professional (CTPRP) are often required. Excellent communication, attention to detail, and problem-solving abilities help you effectively assess vendor risks and collaborate with cross-functional teams. These competencies ensure your organization can identify, mitigate, and manage risks associated with external vendors, protecting both operational integrity and regulatory compliance.

What does a vendor analyst do?

A vendor risk analyst evaluates third-party vendors to ensure they meet security, compliance, and operational standards. They review contracts, perform risk assessments, and monitor vendor performance using tools like risk management software to mitigate potential threats to the organization.
What are the most commonly searched types of Vendor Risk Analyst jobs in New York? The most popular types of Vendor Risk Analyst jobs in New York are:
What job categories do people searching Vendor Risk Analyst jobs in New York look for? The top searched job categories for Vendor Risk Analyst jobs in New York are:
Infographic showing various Vendor Risk Analyst job openings in New York as of July 2026, with employment types broken down into 90% Full Time, 6% Part Time, 2% Temporary, and 2% Contract. Highlights an 72% In-person, 17% Hybrid, and 11% Remote job distribution, with an average salary of $92,128 per year, or $44.3 per hour.

Vendor Risk Manager

DFO Referrals

Westport, CT โ€ข On-site

Full-time

Dental, Vision, Life, Retirement, PTO

Posted 26 days ago


Job description

Vendor Risk Manager
Dalio Family Office
Dalio Family Office Overview:
The Dalio Family Office (DFO) supports Barbara and Ray Dalio and their family in their ventures, investments, and philanthropic efforts under Dalio Philanthropies, which includes OceanX, Dalio Education, Endless Network, and the Beijing Dalio Foundation. The core of the DFO's culture is built around meaningful work and meaningful relationships and the family's commitment to giving back. The office is headquartered in Westport, CT with regional offices in New York City, Singapore, and Abu Dhabi.
Position Summary:
The Vendor Risk Manager owns the end-to-end third-party risk lifecycle, onboarding, diligence, monitoring, and exit across a high-volume, diverse vendor portfolio. You will synthesize risk across cybersecurity, AI, privacy, financial, and AML/CFT/sanctions domains into clear, actionable risk positions, performing structured threat modeling for high-exposure vendors.
Day-to-day responsibilities would include a combination of the following:
  • Own the VRM program end-to-end: strategy, policy, procedure, workflow, tooling, metrics, and executive reporting for CISO/CRO/board visibility.
  • Lead holistic vendor risk assessments across cybersecurity, AI risk, privacy, financial, AML/CFT/sanctions.
  • Document residual risk acceptances with named accountable executives and time-boxed review dates; coordinate with IT, Legal, Finance, and Compliance as appropriate.
  • Evaluate and monitor vendor security controls based on data sensitivity and business criticality, leveraging industry frameworks and evidence such as SOC 2, ISO 27001, penetration testing, and security assessments.
  • Conduct structured threat models (STRIDE, PASTA) for high risk vendors, and document findings as durable artifacts informing contracting, monitoring, and exit planning.
  • Translate threat model outputs into concrete, testable control requirements drawing from OWASP (ASVS, API Security Top 10, LLM/Agentic Top 10), NIST (SP 800-53, SP 800-161, CSF 2.0, SP 800-207), and MITRE ATT&CK; scale requirements to vendor tier.
  • Partner with Legal to translate identified risks into enforceable contractual requirements.
  • Apply FAIR or comparable quantitative methods for high-impact vendor decisions, expressing cyber risk in loss-exposure terms that resonate with senior leadership.
  • Advise IT, Engineering and business teams on vendor integration architecture (SSO/SCIM, OAuth, conditional access, DLP, segmentation, BYOK, VPC peering) and maintain approved reference patterns.
  • Drive automation and tooling maturity to handle high vendor volume without proportional headcount growth; produce program dashboards tracking throughput, cycle time, recertification compliance, and remediation aging.

The ideal candidate will possess the following knowledge, skills, attributes, and values:
  • Expert knowledge of third-party/vendor risk management
  • Strong risk assessment and analytical skills
  • Technical understanding of enterprise security architecture
  • Excellent communication and stakeholder management skills
  • Proven ability to lead and optimize vendor risk programs

Illustrative Benefits:
  • 100% company paid medical premiums
  • 17 company paid holidays
  • Friday summer hours
  • Monthly community happy hours
  • Hybrid work environment
  • Free catered food services for in-office days
  • Generous PTO offering
  • Casual dress code
  • 150% 401(k) match up to $7,500 and 100% match above $7,500 ($15k match limit)
  • Gym reimbursement, back up childcare services, insurance, financial, and legal services, and much more!

Qualifications:
  • Bachelor's degree in Information Security, Risk Management, Computer Science, Cybersecurity, or a related discipline.
  • At least 7 years of progressive experience across vendor risk management, cybersecurity architecture, security engineering, GRC, audit, or related fields.
  • Experience managing the full third-party/vendor risk lifecycle, including vendor onboarding, due diligence, risk assessments, continuous monitoring, recertification, remediation tracking, and vendor exit planning, with at least 2 years owning an end-to-end TPRM program.
  • Strong technical knowledge of cybersecurity frameworks, standards, and methodologies including NIST, ISO 27001/27002, OWASP, MITRE ATT&CK, Shared Assessments, threat modeling approaches (STRIDE/PASTA), and risk management practices.
  • Hands-on experience evaluating enterprise security controls, cloud and integration architectures, SOC 2 Type II reports, ISO certifications, penetration testing results, data protection requirements, and third-party security risks across complex technology environments.
  • Ability to communicate complex technical and risk concepts to executive stakeholders, collaborate effectively across business functions
  • 10% travel as required based on business needs.

Compensation:
Compensation for the role includes a competitive salary in the range from $175,000 -$260,000 (inclusive of a merit-based bonus, dependent on years of experience, level of education obtained, as well as applicable skillset) and an excellent benefits package, including paid time off ranging from 15 to 25 days based on years of service, paid sick and safe leave, dental, vision, life and disability insurance, paid parental time off, birth mother recovery pay, sick family member pay, parental ramp back up program, gym reimbursement and generous employer match for 401k.
Please note we are unable to provide immigration sponsorship for this position.
At the DFO, we believe our biggest asset is our people. We are proud to be an equal opportunity employer, hiring and developing individuals from diverse backgrounds and experiences to add to our collaborative culture. The DFO treats all candidates and employees with respect and does not discriminate in our recruiting, hiring, and promoting processes and general treatment during employment, including on the basis of actual or perceived race, creed, color, religion, sex, age, sexual orientation, gender identity and/or expression, alienage or national origin, ancestry, citizenship status, marital status, veteran status, or disability.