1

Vendor Risk Analyst Jobs in Frederick, MD (NOW HIRING)

Salesforce Platform Manager

Rockville, MD · On-site

$125K - $155K/yr

... vendor risk/compliance management - Oversee and govern Salesforce integrations with: o SaaS ... analysis and delivery workflows, automated testing, and CI/CD pipelines for Salesforce and ...

... vendors, and project managers to ensure alignment on project scope, requirements, and successful delivery. * Support project planning activities, impact assessments, feasibility analysis, risk ...

... vendors, and project managers to ensure alignment on project scope, requirements, and successful delivery. * Support project planning activities, impact assessments, feasibility analysis, risk ...

Perform sensitivity analyses, what-if scenarios, and risk assessments to support bid strategy ... vendor inputs. * Support price-to-win analysis and competitive assessments in coordination with ...

Salesforce Platform Manager

Rockville, MD · On-site

$56.50 - $75/hr

... and vendor risk/compliance management Oversee and govern Salesforce integrations with: o SaaS ... Champion modern engineering practices, including AI-enhanced analysis and delivery workflows ...

Salesforce Platform Manager

Rockville, MD · On-site

$56.50 - $75/hr

... vendor risk/compliance management • Oversee and govern Salesforce integrations with: o SaaS ... analysis and delivery workflows, automated testing, and CI/CD pipelines for Salesforce and ...

Salesforce Platform Manager

Rockville, MD · On-site

$56.50 - $75/hr

... vendor risk/compliance management • Oversee and govern Salesforce integrations with: o SaaS ... analysis and delivery workflows, automated testing, and CI/CD pipelines for Salesforce and ...

... perform risk analysis and implement mitigation strategies; ensure compliance with organizational ... vendor performance; maintain documentation for change management and project controls processes.

Estimator

Gaithersburg, MD · On-site

$70 - $95/hr

Analyze data and produce forecasts. Perform risk analysis. * Work with Operations to ensure a ... Foster relationships with key vendors (subcontractors, architects). * Other duties as assigned.

New

Showing results 21-40

Vendor Risk Analyst information

See Frederick, MD salary details

$15

$40

$65

How much do vendor risk analyst jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for vendor risk analyst in Frederick, MD is $40.25, according to ZipRecruiter salary data. Most workers in this role earn between $29.62 and $48.99 per hour, depending on experience, location, and employer.

What is a vendor risk analyst?

A Vendor Risk Analyst is a professional responsible for assessing and managing risks associated with third-party vendors that provide products or services to an organization. They evaluate vendor practices, security protocols, and compliance with regulations to minimize potential risks such as data breaches, financial losses, or operational disruptions. Their work helps organizations ensure that vendors meet required standards and do not pose undue risk to business operations. Vendor Risk Analysts often use questionnaires, audits, and ongoing monitoring to perform their assessments.

How does a vendor risk analyst typically collaborate with other departments within an organization?

Vendor Risk Analysts work closely with various departments such as procurement, legal, IT security, and compliance to assess and manage risks associated with third-party vendors. They facilitate communication between teams to ensure vendor contracts meet security and regulatory requirements. Regularly, they coordinate risk assessments, share findings, and help develop mitigation strategies, ensuring that vendor relationships support the organization's risk tolerance and business goals.

What are the key skills and qualifications needed to thrive as a vendor risk analyst, and why are they important?

To thrive as a Vendor Risk Analyst, you need strong analytical skills, knowledge of risk management frameworks, and a relevant degree in business, finance, or a related field. Familiarity with third-party risk management platforms, regulatory compliance tools, and certifications like Certified Third Party Risk Professional (CTPRP) are often required. Excellent communication, attention to detail, and problem-solving abilities help you effectively assess vendor risks and collaborate with cross-functional teams. These competencies ensure your organization can identify, mitigate, and manage risks associated with external vendors, protecting both operational integrity and regulatory compliance.

Is risk analyst an entry level job?

A risk analyst role can be entry level or require several years of experience, depending on the organization. Entry-level risk analyst positions typically require a bachelor's degree in finance, economics, or a related field, and may involve basic data analysis skills and familiarity with risk management tools. More advanced roles may require professional certifications and prior experience in risk assessment or related areas.

What does a vendor risk analyst do?

A vendor risk analyst evaluates the risks associated with third-party vendors to ensure they meet security, compliance, and operational standards. They review vendor contracts, conduct risk assessments, and monitor vendor performance using tools like risk management software to protect their organization from potential threats and vulnerabilities.

What are the most commonly searched types of Vendor Risk Analyst jobs in Frederick, MD?

The most popular types of Vendor Risk Analyst jobs in Frederick, MD are:

What are popular job titles related to Vendor Risk Analyst jobs in Frederick, MD?

For Vendor Risk Analyst jobs in Frederick, MD, the most frequently searched job titles are:

What job categories do people searching Vendor Risk Analyst jobs in Frederick, MD look for?

The top searched job categories for Vendor Risk Analyst jobs in Frederick, MD are:

What cities near Frederick, MD are hiring for Vendor Risk Analyst jobs?

Cities near Frederick, MD with the most Vendor Risk Analyst job openings:

Infographic showing various Vendor Risk Analyst job openings in Frederick, MD as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $83,727 per year, or $40.3 per hour.

BISO - Enabling Units IT Security

AstraZeneca

Gaithersburg, MD • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 9 days ago


Key responsibilities

  • Lead risk posture and architecture engagement for enterprise SaaS and cloud environments.

  • Provide security consulting and risk management for enterprise applications such as Workday, SAP, Coupa, and Concur.

  • Support security controls to ensure compliance with financial, data privacy, M&A, and electronic records requirements.


AstraZeneca rating

8.4

Company rating: 8.4 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

23rd of 86 rated pharmaceutical


Job description

The BISO Enabling Units IT Security serves as the Information Security Officer for the Enabling Units IT organization. This position reports to the AstraZeneca Global Head of Cybersecurity Business Operations. The BISO delivers risk management and security expertise to educate, enable, and empower Enabling Units IT and business stakeholders to safeguard information, platforms, and business-critical systems.
The BISO team ensures information security is understood and embedded across enterprise business functions. The team leads security consultants and risk analysts responsible for embedding the security policy framework, industry-standard controls, and secure-by-design initiatives into enterprise SaaS platforms, cloud services, and applications supporting Finance, HR, Global Corporate Affairs, Global Business Services, Legal, and M&A functions.
The BISO, is the primary strategic cybersecurity partner to Enabling Units IT, covering enterprise business functions including Finance, HR, Global Corporate Affairs, Global Business Services, Legal, and Mergers & Acquisitions. This customer-facing role represents the CISO by leading cybersecurity engagement, alignment, and delivery of cybersecurity risk and resilience outcomes across enterprise business applications and services.
The role provides strategic guidance on cybersecurity risks, priorities, and long-term security posture across enterprise SaaS platforms, cloud services, and applications such as Workday, SAP, Coupa, and Concur. A central focus is balancing business enablement with compliance, data protection, identity governance, vendor assurance, and resilience needs across enterprise functions.
This leader directs cybersecurity consulting, risk management, remediation, posture reporting, and data analysis activities tailored to the enterprise SaaS and cloud platforms that underpin financial integrity, employee data protection, legal obligations, M&A activity, and critical business operations.
Accountabilities
  • Act as the primary strategic partner and security consultant to Enabling Units IT leadership, participating in governance forums that drive risk-based decisions, clear accountability, and visible security outcomes.
  • Lead risk posture and architecture engagement for enterprise SaaS and cloud environments, supporting cybersecurity architects in defining cloud-native security patterns that fit business application needs.
  • Lead security consulting and risk management for enterprise applications such as Workday, SAP, Coupa, and Concur, including identity and access management, data protection, integration security, privileged access governance, and vendor assurance.
  • Ensure security controls support financial controls, SOX compliance, data privacy obligations including GDPR, M&A due diligence requirements, and electronic records/signatures expectations where applicable.
  • Deliver change-controlled security improvements within enterprise applications and cloud services, including documentation expectations, governance alignment, and compensating controls where needed.
  • Drive comprehensive application visibility, security posture reporting, and risk-based vulnerability or exposure management across enterprise SaaS and cloud platforms with continuous update models.
  • Provide security consulting for critical enterprise integrations, including HR-to-Finance, procurement-to-payment, and other cross-functional data flows, ensuring secure patterns, identity controls, logging, and resilience.
  • Strengthen third-party risk management for SaaS providers, cloud platforms, business service providers, and professional services partners, including contractual controls, ongoing assurance, and secure support models.
  • Partner with security operations and business teams to create environment-specific incident response playbooks, tabletop exercises, and recovery readiness for business-critical enterprise applications.
  • Maintain audit-ready security evidence for financial controls, SOX compliance, data privacy audits, Legal and M&A due diligence, and other enterprise assurance needs.
  • Build enterprise-focused risk dashboards and KPIs covering SaaS security posture, identity governance maturity, critical exposure reduction, privileged access governance, vendor assurance, and recovery readiness.
  • Tailor cybersecurity culture and training for Finance, HR, Legal, Global Corporate Affairs, Global Business Services, M&A, and related business users, emphasizing role-appropriate security practices.
  • Coach a high-performing team with clear goals tied to measurable risk reduction, resilience improvement, and business enablement across Enabling Units IT.

Essential Skills & Experience Required
  • 10+ years of experience in information security positions, including 5+ years overseeing an information security function and influencing senior business and IT stakeholders.
  • Demonstrated experience securing enterprise business applications, SaaS platforms, and cloud services, with the ability to translate business realities into effective cybersecurity controls.
  • Strong familiarity with financial controls and SOX compliance, data privacy regulations including GDPR, electronic records/signatures regulations, and M&A due diligence requirements.
  • Proven ability to design and operationalize cloud-native security patterns for enterprise SaaS platforms and business applications.
  • Hands-on experience securing enterprise SaaS and cloud platforms, including identity and access management, data protection, integration security, privileged access governance, and vendor risk management.
  • Working knowledge of enterprise security frameworks such as NIST CSF, ISO 27001/27002, and CIS Controls, with the ability to apply appropriate controls across business application environments.
  • Experience running risk-based exposure management across enterprise SaaS and cloud platforms that operate under continuous update models.
  • Understanding of global incident response processes with experience adapting containment and recovery approaches to business continuity requirements such as financial close, payroll, procurement, legal workflows, and employee data protection.
  • Experience managing cyber risk across SaaS providers, cloud platforms, business service providers, and professional services partners, including enforceable minimum controls and ongoing assurance.
  • M&A security experience, including cybersecurity due diligence, integration security planning, and post-merger technology risk management, is highly desirable.
  • Demonstrated ability to apply emerging technologies, including AI and automation, to improve cybersecurity and business outcomes while protecting sensitive data and maintaining human oversight.
  • Strong written and verbal communication skills, with the ability to present complex technical information to finance executives, HR leadership, legal counsel, business service leaders, and global IT.
  • Proven ability to manage competing priorities and drive outcomes across enterprise functions with different risk profiles, regulatory obligations, and operational constraints.
  • Executive presence and influence, with the ability to build trusted relationships and guide risk-based decision-making across Enabling Units IT and business leadership.
  • Bachelor's degree in science or relevant technical field of study; Master's preferred.

When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.
The annual base pay for this position ranges from $190,956.80 - $286,435.20 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an "at-will position" and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.
Date Posted
26-Aug-2026
Closing Date
10-Sept-2026
Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.

What AstraZeneca employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


AstraZeneca logo

About AstraZeneca

Sourced by ZipRecruiter

AstraZeneca is a global, science-led, patient-focused biopharmaceutical company that focuses on the discovery, development and commercialization of prescription medicines for some of the world's most serious diseases. But we're more than one of the world's leading pharmaceutical companies. A place built on courage, curiosity and collaboration - we make bold decisions driven by patient outcomes. Empowered to lead at every level, free to ask questions and take smart risks that write the next chapter for our pipeline and Oncology team. Make a meaningful impact that brings real benefits to society. By applying your knowledge of data, you will help to redefine our industry and ultimately save lives. Work with experts who share a common goal: to accelerate the potential of medicines and the science of tomorrow.

Industry

Pharmaceutical product wholesalers and pharmaceutical and medicine manufacturing

Company size

10,000+ Employees

Headquarters location

Cambridge, Cambridgeshire, GB