1

Vendor Risk Assessment Jobs in Arizona (NOW HIRING)

IT Compliance Analyst

Tempe, AZ · On-site

$111K - $130K/yr

... Vendor Risk Assessments - Conduct and manage vendor security assessments by evaluating third-party controls, reviewing audit reports (e.g., CMMC, SOC 2, ISO/IEC 27001), identifying risks, and ...

Director of IT Central Services

Chandler, AZ · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... vendor risk, and audit or insurance requirements. * Experience supporting post-acquisition or multi-entity IT integration work, including system assessment, migration planning, access, devices ...

Director of IT Central Services

Chandler, AZ · On-site +1

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

... vendor risk, and audit or insurance requirements. * Experience supporting post-acquisition or multi-entity IT integration work, including system assessment, migration planning, access, devices ...

Showing results 21-40

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
What cities in Arizona are hiring for Vendor Risk Assessment jobs? Cities in Arizona with the most Vendor Risk Assessment job openings:
Infographic showing various Vendor Risk Assessment job openings in Arizona as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

IT Compliance Analyst

CNA National Warranty Corp

Scottsdale, AZ • On-site

$90K - $115K/yr

Full-time

Posted 21 days ago


Job description

We are looking for an experienced IT Compliance Analyst to help strengthen and mature our technology risk, security, and compliance programs. This is an excellent opportunity for a detail-oriented, collaborative professional who enjoys building strong controls, supporting audit readiness, and partnering across IT, Security, and business teams to protect the organization and support continued growth.

In this role, you will serve as a trusted compliance partner and subject matter expert, helping align internal controls and security practices with key frameworks such as SOX, CMMC, SOC 2, NIST, and ISO/IEC 27001. You will support audits, assess risks, coordinate evidence, strengthen vendor and customer security review processes, and contribute to emerging areas such as AI risk governance and business continuity readiness.


Why This Role Matters

Technology compliance is critical to CNA National’s ability to operate securely, serve our customers, and continue advancing our security and risk programs. The IT Compliance Analyst will play a key role in reducing compliance risk, improving audit preparedness, and helping teams translate complex regulatory and security expectations into clear, practical actions.


Schedule and Location

Role is based in Scottsdale, Arizona, working a hybrid schedule of four days in the office and one day remote.


What You’ll Do

  • Support IT compliance programs through control assessments, audit coordination, evidence preparation, and continuous monitoring.
  • Partner with IT, Security, Development, and business teams to identify risks, address control gaps, and improve compliance readiness.
  • Lead or support security and privacy assessments, vendor risk reviews, and customer security questionnaire responses.
  • Map internal policies and technical safeguards to applicable frameworks, including SOX, CMMC, SOC 2, NIST, and ISO/IEC 27001.
  • Contribute to AI risk and governance activities by helping assess use cases, document controls, and support responsible AI practices.
  • Assist with business continuity, disaster recovery, and team documentation efforts to support operational resilience.


What You’ll Bring

  • Strong experience in IT, security, audit, risk, or compliance, with hands-on knowledge of common security frameworks and control environments.
  • Experience supporting audits, managing evidence requests, documenting controls, and working with GRC tools.
  • Excellent communication skills with the ability to explain technical and compliance requirements clearly to a variety of stakeholders.
  • A collaborative, solutions-oriented mindset and the ability to manage multiple priorities with accuracy and follow-through.
  • Curiosity and adaptability as compliance expectations evolve, including emerging areas such as AI governance and security risk management.


Why Join CNA

At CNA, your work makes a meaningful impact. We are a respected leader in automotive protection products with a strong history, award-winning service, and a continued focus on investing in our people and technology. You’ll join a collaborative team environment where integrity, accountability, innovation, and customer focus guide how we serve our clients and support one another.

If you are passionate about compliance, security, risk management, and building practical solutions that help an organization operate with confidence, we encourage you to apply.