1

Vendor Risk Analyst Jobs in Pennsylvania (NOW HIRING)

The role makes heavy use of AI and LLM tools to research vendors, analyze risk and spend, and prepare clear, well-organized reporting. It partners with Security, Legal, Procurement, IT, and ...

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience withthird-party/vendor risk management, regulatory compliance assessments, and security ...

The Analyst independently leads risk assessments and partners closely with IT, OT, audit, andsenior ... Experience withthird-party/vendor risk management, regulatory compliance assessments, and security ...

The Department currently concentrates its efforts on Securities Lending oversight, Operations and Control Testing and Third-Party Vendor Risk Management. What you are good at: Analytical ability ...

The Department currently concentrates its efforts on Securities Lending oversight, Operations and Control Testing and Third-Party Vendor Risk Management. What you are good at: Analytical ability ...

The Risk Analyst initiates and supports Credit Risk Management analysis and decisions using queries, reports, and visual tools. Produces and analyzes ongoing risk management reports and analyses.

The Risk Analyst initiates and supports Credit Risk Management analysis and decisions using queries, reports, and visual tools. Produces and analyzes ongoing risk management reports and analyses.

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

New

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

New

As a Physical Security & Risk Analyst, you will help organizations enhance security, resilience, and mission assurance across critical facilities, infrastructure, and operations. In this role, you ...

New

Analytical Thinking: Can apply critical thinking to analyze data, identify patterns, and make basic ... Familiarity with vendor risk assessment methodologies and procurement processes. * Experience with ...

New

next page

Showing results 1-20

Vendor Risk Analyst information

See Pennsylvania salary details

$15

$40

$66

How much do vendor risk analyst jobs pay per hour?

As of Aug 9, 2026, the average hourly pay for vendor risk analyst in Pennsylvania is $40.58, according to ZipRecruiter salary data. Most workers in this role earn between $29.86 and $49.38 per hour, depending on experience, location, and employer.

What does a vendor risk analyst do?

A vendor risk analyst evaluates the risks associated with third-party vendors to ensure they meet security, compliance, and operational standards. They conduct risk assessments, review vendor controls, and monitor ongoing vendor performance, often using tools like risk management software. Their work helps organizations mitigate potential threats from external partners.

Is risk analyst an entry level job?

A risk analyst role can be entry level or require several years of experience, depending on the organization. Entry-level risk analyst positions typically require a bachelor's degree in finance, economics, or a related field, and may involve basic data analysis skills and familiarity with risk management tools. Advancement often depends on gaining experience and developing specialized skills or certifications such as FRM or CRM.

What is a vendor risk analyst?

A Vendor Risk Analyst is a professional responsible for assessing and managing risks associated with third-party vendors that provide products or services to an organization. They evaluate vendor practices, security protocols, and compliance with regulations to minimize potential risks such as data breaches, financial losses, or operational disruptions. Their work helps organizations ensure that vendors meet required standards and do not pose undue risk to business operations. Vendor Risk Analysts often use questionnaires, audits, and ongoing monitoring to perform their assessments.

How does a vendor risk analyst typically collaborate with other departments within an organization?

Vendor Risk Analysts work closely with various departments such as procurement, legal, IT security, and compliance to assess and manage risks associated with third-party vendors. They facilitate communication between teams to ensure vendor contracts meet security and regulatory requirements. Regularly, they coordinate risk assessments, share findings, and help develop mitigation strategies, ensuring that vendor relationships support the organization's risk tolerance and business goals.

What are the key skills and qualifications needed to thrive as a vendor risk analyst, and why are they important?

To thrive as a Vendor Risk Analyst, you need strong analytical skills, knowledge of risk management frameworks, and a relevant degree in business, finance, or a related field. Familiarity with third-party risk management platforms, regulatory compliance tools, and certifications like Certified Third Party Risk Professional (CTPRP) are often required. Excellent communication, attention to detail, and problem-solving abilities help you effectively assess vendor risks and collaborate with cross-functional teams. These competencies ensure your organization can identify, mitigate, and manage risks associated with external vendors, protecting both operational integrity and regulatory compliance.
What are the most commonly searched types of Vendor Risk Analyst jobs in Pennsylvania? The most popular types of Vendor Risk Analyst jobs in Pennsylvania are:
What are popular job titles related to Vendor Risk Analyst jobs in Pennsylvania? For Vendor Risk Analyst jobs in Pennsylvania, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Analyst jobs in Pennsylvania look for? The top searched job categories for Vendor Risk Analyst jobs in Pennsylvania are:
Infographic showing various Vendor Risk Analyst job openings in Pennsylvania as of August 2026, with employment types broken down into 100% Full Time. Highlights an 50% In-person, and 50% Remote job distribution, with an average salary of $84,412 per year, or $40.6 per hour.

Vendor Management Analyst

The Institutes

Malvern, PA โ€ข On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 14 days ago


Job description

About The Institutes
Located in beautiful Malvern, Pennsylvania, The Institutesยฎ are a not-for-profit comprised of diverse affiliates that educate, elevate, and connect people in the essential disciplines of risk management and insurance. Through products and services offered by our nearly 20 affiliated business units, people and organizations are empowered to help those in need with a focus on understanding, predicting, and preventing losses to create a more resilient world.
Additionally, we understand the importance of work-life balance-in 2025 Philly.com named us a Top Workplace for the tenth year and USA Today named us a USA Top Workplace for the fourth year. We provide excellent benefits and a friendly, team-focused work environment to drive employee engagement.
Vendor Management AnalystThe Vendor Management Analyst supports The Institutes' vendor governance and third-party risk management (TPRM) program day to day. This role handles vendor lifecycle administration, third-party and AI-related risk intake and assessment, contract and renewal tracking, and SaaS/portfolio data, applying the frameworks, scoring criteria, and standards set by IT leadership. The role makes heavy use of AI and LLM tools to research vendors, analyze risk and spend, and prepare clear, well-organized reporting. It partners with Security, Legal, Procurement, IT, and Application Development to keep vendor and AI risk visible, documented, and current.
What You'll Do:
Vendor Governance & Lifecycle Administration
  • Maintain the contract repository and renewal calendar.
  • Coordinate renewals with Legal and Procurement.
  • Maintain vendor tier classifications and risk profiles using the established tiering framework.
  • Track remediation items and follow up with vendors.
  • Distribute, collect, and organize security questionnaires.
  • Collect and review SOC reports, cyber insurance documentation, and compliance artifacts.
  • Research vendor markets for trends, risks, and current events, and raise risks as needed.
  • Identify continuous-improvement opportunities and flag them.

AI & Third-Party Risk Analysis
  • Conduct AI-focused vendor risk assessments - covering model usage, training-data sources, and data-retention practices - using the established assessment criteria.
  • Apply the AI risk-scoring methodology to evaluate vendor AI posture and document findings.
  • Assess AI model risk exposure (bias, explainability, and regulatory considerations) and record results.
  • Support Security in identifying and flagging Shadow AI usage across the organization.
  • Track vendor data-exposure risk and data-sharing pathways.
  • Maintain vendor and AI-governance records in OneTrust (or equivalent TPRM platform).

Contract & Data Governance Support
  • Review AI- and data-related contract clauses and flag items for Legal, including data ownership, data residency, model-training rights, subprocessor disclosures, and AI indemnification/liability language.
  • Support Legal in applying AI and data-protection contractual standards.
  • Support contractual reviews of AI/data usage during vendor onboarding and renewals.

Technology Portfolio & SaaS Tracking
  • Maintain the enterprise SaaS inventory and technology portfolio map.
  • Analyze license utilization and identify consolidation opportunities.
  • Surface redundant platforms and overlapping AI tool capabilities to the Manager.
  • Prepare cost-and-risk optimization options for the Manager's review.

Reporting & Analytics
  • Maintain vendor risk dashboards and AI-posture reporting.
  • Prepare reporting for the Manager and stakeholders on AI vendor exposure, data-risk trends, model-risk concentration, and SaaS redundancy and cost.
  • Flag recurring risk patterns across vendor categories.

What We're Looking For:
Required
  • 3+ years of experience in vendor management, third-party risk, IT governance, compliance, procurement, or operations.
  • Comfortable using AI/LLM tools (e.g., Claude, Microsoft Copilot) as a daily part of research, analysis, and documentation.
  • Able to use AI tools effectively to manage the volume of vendor research and analysis the role requires.
  • Experience reviewing vendor contracts and tracking renewals.
  • Exposure to third-party risk assessments and security-questionnaire processes.
  • Strong analytical and documentation skills.
  • Highly curious, with a drive to improve the customer experience and risk-management processes.
  • Experience maintaining SaaS inventories or technology portfolios.
  • Proficiency in Excel and vendor management platforms.

Preferred
  • Experience supporting SOC 2, ISO 27001, or similar audits.
  • Familiarity with OneTrust or TPRM platforms.
  • Exposure to AI governance, data risk management, or emerging technology risk.
  • Understanding of AI model risk principles (bias, explainability, regulatory impact).

Ability to be on-site 5 days a week is a must. The need for extended hours may be required to support meetings/events.
Required Competencies
  • Analytical, risk-based thinking
  • Strong organization and follow-through
  • AI and data-governance awareness
  • Effective use of AI/LLM tools for research, analysis, and documentation
  • Cross-functional collaboration
  • Process-improvement mindset
  • Clear, well-organized reporting
  • Commitment to The Institutes' cultural values: Put the Customer First, Do What You Say, Work Together, Be Innovative, and Do the Right Thing.

The Best Part? The Benefits!
To enforce the importance of work-life balance, employees enjoy excellent benefits, including:
  • 401(k) plan with company contribution up to 16%
  • Generous time off package that includes paid vacation, personal, sick, and holidays
  • Paid maternity and parental leave
  • Tuition reimbursement
  • Medical, dental, vision, and prescription coverage
  • On our Malvern campus: Free lunch every day when working on campus, onsite fitness center, and a beautiful 1.25-mile walking path!

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.