1

Vendor Risk Assessment Jobs in Arizona (NOW HIRING)

ServiceNow IRM Developer

Phoenix, AZ · On-site

$53.50 - $73.75/hr

... Vendor Risk Management, Regulatory Change Management, and Business Continuity Management. * Strong knowledge of IRM workflows , scoring methodologies , Risk Assessment Methodologies (RAM) , and IRM ...

Strong experience in SaaS assessments, vendor risk management, or cloud security. * Good understanding of shared responsibility models across cloud providers. * Knowledge of regulatory and control ...

Maintain strong oversight of thirdparty, vendor, and businesspartner risks and update the risk register to reflect identified issues or required remediation. * Analyze and assess risk findings and ...

Additional contribution will be expected for internal assessments and 3rd Party audits to gather ... Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a Vendor Risk Assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
What are popular job titles related to Vendor Risk Assessment jobs in Arizona? For Vendor Risk Assessment jobs in Arizona, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Assessment jobs in Arizona look for? The top searched job categories for Vendor Risk Assessment jobs in Arizona are:
What cities in Arizona are hiring for Vendor Risk Assessment jobs? Cities in Arizona with the most Vendor Risk Assessment job openings:
Infographic showing various Vendor Risk Assessment job openings in Arizona as of June 2026, with employment types broken down into 81% Full Time, 17% Part Time, and 2% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution.

Third Party Risk Management Analyst 2

Choice Hotels International

Scottsdale, AZ • Hybrid

$81K - $95K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 21 days ago


Job description

** This role is not eligible for sponsorship AND is four days onsite hybrid at our N. Scottsdale office **


Job Summary
The Third Party Risk Management (TPRM) Analyst II supports the execution and continuous improvement of Choice's Third Party Risk Management program. This role performs vendor risk assessments, evaluates control effectiveness, reviews supporting evidence, monitors remediation activities, and helps ensure thirdparty partners meet Choice's security, privacy, and compliance requirements.
The Analyst II operates with moderate autonomy, applying strong analytical, communication, and collaboration skills to solve problems, influence outcomes, and execute consistently in alignment with Choice's expectations for adaptability and operational excellence.
Organization & Role Context
This is an individual contributor role within the Information Technology Risk Management organization. The position reports to the Senior Manager, GRC and partners closely with Technology, Internal Audit, Legal, Procurement, Privacy, and business unit stakeholders to support thirdparty risk oversight across the enterprise.
Primary Duties & AccountabilitiesThirdParty Risk Assessments
  • Conduct inherent and residual risk assessments for new and existing thirdparty vendors.
  • Perform security, privacy, and compliance assessments using standardized questionnaires and industry frameworks (e.g., SOC 2, SIG, ISO 27001, NIST).
  • Review and analyze vendorprovided documentation and evidence for adequacy, completeness, and control effectiveness.
  • Document assessment results, identify risk gaps, and recommend remediation actions aligned with defined standards.
  • Ensure assessments are completed in accordance with internal procedures and execution expectations.
Vendor Monitoring & Issue Management
  • Track vendor remediation plans and validate closure of corrective actions.
  • Monitor highrisk vendors for changes in risk posture, control effectiveness, or material issues.
  • Maintain centralized records, reporting, and dashboards to support ongoing oversight.
  • Support periodic vendor reviews and recurring reassessment cycles.
Process Documentation & Governance Support
  • Contribute to updates of TPRM procedures, workflows, and program documentation.
  • Support internal and external audits by gathering evidence and documenting processes.
  • Ensure program activities align with Choice's governance standards and risk expectations.
CrossFunctional Collaboration & Communication
  • Partner with Legal, Procurement, Technology, Privacy, and business units to determine appropriate risk requirements for vendor engagements.
  • Communicate assessment results, risk issues, and required next steps clearly to stakeholders.
  • Provide guidance to internal partners on vendor intake forms and required risk documentation.
  • Participate in vendor onboarding and review meetings as needed.
Continuous Improvement & Professional Development
  • Stay current on thirdparty risk trends, regulatory requirements, and industry best practices.
  • Identify incremental improvements to assessment workflows and vendor experience.
  • Pursue relevant TPRM, information security, or GRC training and certifications to support professional growth.
Qualifications
Education
  • Bachelor's degree in Information Security, Information Technology, Business, Risk Management, or a related field or an equivalent combination of education and relevant work experience.
Experience
  • 2-4 years of experience in thirdparty/vendor risk management, IT risk, cybersecurity, compliance, or GRC.
  • Experience reviewing SOC reports, security questionnaires, and vendor compliance evidence preferred.
  • Familiarity with frameworks such as SOC 2, ISO 27001, NIST, PCI, and SIG beneficial.
Skills & Competencies
  • Strong analytical skills with the ability to interpret technical security documentation and identify risk gaps.
  • Solid problemsolving and decisionmaking capabilities.
  • Effective written and verbal communication skills, with the ability to explain risk concepts to nontechnical audiences.
  • Ability to manage work independently while collaborating effectively across teams.
  • High attention to detail with strong organizational and documentation skills.
  • Ability to adapt to change and shifting priorities, consistent with Analyst II / midlevel IC expectations.

Salary Range

The salary range for this position is $81,000 to $95,000 annually.

The pay range listed is for this position and is what Choice Hotels reasonably expects to pay. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee's pay position within the pay range will be based on several factors including, but not limited to, relevant education, qualifications, qualifications, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, and business or organizational needs.

**This role is not eligible for sponsorship**

#LI-Onsite

Choice prioritizes our associate wellbeing by offering a comprehensive benefits program that is both competitive and flexible to help you achieve your wellbeing goals - here are just a few:

  • Competitive compensation and benefits, including medical, dental, and vision coverage
  • Leave and paid time-off for holidays, vacation, personal, family, volunteer, sick, jury duty, bereavement, military, and religious observance
  • Financial benefits for retirement and health savings
  • Employee recognition programs
  • Discounts at Choice hotels worldwide

About Choice

Choice Hotels International, Inc. (NYSE: CHH), is one of the largest lodging franchisors in the world. With 7,500 hotels in 45+ countries and territories, we offer a range of high-quality lodging options in the upper upscale, upper midscale, midscale, extended stay, and economy segments. We're the hotel company for those who choose to bet on themselves - the striver, the dreamer, the entrepreneur - because that's who we are, too.

At Choice, we are united by the simple belief that tomorrow will be even better than today - for associates, our company, and our franchisees. At our worldwide corporate headquarters in North Bethesda, Maryland, at our technology center in Scottsdale, Arizona, and through our associates around the globe, every voice is heard and every idea is listened to, no matter what area of the company they come from. We are united in supporting the entrepreneurial dreams of our thousands of franchise owners, which propels us forward - giving our work at Choice a purpose larger than our business.

Our corporate office locations:

North Bethesda, MD - Located at Pike & Rose, our worldwide headquarters is less than 15 miles from Washington, D.C., one block away from the North Bethesda Metro station, with easy access to I-495, complimentary parking, electronic charging stations, restaurants and retail.

Scottsdale, AZ - Located at the northwest corner of Loop 101, the Scottsdale office is home to our technology, eCommerce and customer service organizations, with easy access to complimentary parking, electronic charging stations, restaurants and retail.

Minneapolis, MN - Select roles are based in our Minneapolis office on Highway 394, near the intersection with Highway 100, only five minutes from downtown.

Field/Remote - Select roles designated as field/remote will require associates to work from a home office, connecting virtually with Choice team members and leadership on Zoom, with possible required travel depending on the role.

Choice's Cultural Values

Welcome and Respect Everyone | Be Bold | Be Quick | Listen | Be Curious | Show Integrity

Choice's Leadership Principles

Act with Intention | Lead with Authenticity | Grow & Deliver