1

Vendor Risk Assessment Jobs in Arizona (NOW HIRING)

... vendors and SaaS platforms against security and compliance standards. Track remediation efforts and validate security control implementation. Prepare security assessment reports, risk registers ...

... vendors and SaaS platforms against security and compliance standards. Track remediation efforts and validate security control implementation. Prepare security assessment reports, risk registers ...

... vendors and cloud solutions for security and compliance requirements. Track remediation activities and verify implementation of security recommendations. Prepare assessment reports, risk ...

Showing results 41-60

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in Arizona are hiring for Vendor Risk Assessment jobs?

Cities in Arizona with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Arizona as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 9% Part Time, and 2% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution.

Data Security Assessor

Northern Base

Phoenix, AZ • On-site

Full-time

Posted 8 days ago


Job description

Data Security Assessor
Phoenix, AZ
Fulltime
 
Job Description
Role -   Data Security Assessor
Experience Required -6+ Years
 
We are seeking a highly skilled Security Assessment Consultant with strong expertise in Google Cloud Platform (GCP) Data Security to conduct security assessments for enterprise applications supporting Finance, Supply Chain, and HCM business functions. The ideal candidate will have hands-on experience implementing and assessing encryption, Data Loss Prevention (DLP), Database Activity Monitoring (DAM), IAM controls, and cloud security architectures. Experience with Oracle Cloud security assessments is preferred but not mandatory.
 
Must Have Technical/Functional Skills
 
Strong hands-on experience with GCP Data Security
Experience implementing and assessing:
Encryption controls (data at rest and in transit)
Data Loss Prevention (DLP)
Database Activity Monitoring (DAM)
Data classification and protection controls
Experience performing Application Security Reviews and Security Architecture Assessments
Strong understanding of Identity & Access Management (IAM), RBAC, privileged access management, and authentication/authorization
Experience with cloud security frameworks and risk assessment methodologies
Hands-on scripting/automation experience using Python or Java
Experience reviewing APIs, integrations, and enterprise application data flows
Strong documentation, analytical, stakeholder management, and communication skills
 
Preferred Skills
Experience conducting security assessments of Oracle Cloud applications, especially Oracle Fusion ERP, SCM, Finance, and HCM
Knowledge of Oracle security models, roles, and Segregation of Duties (SoD)
Experience with Oracle HSM integrations and key management solutions
Exposure to AWS and Azure security controls
Experience supporting compliance, audit, and governance initiatives
 
Roles & Responsibilities
 
Conduct security assessments of cloud-hosted Finance, Supply Chain, ERP, and HCM applications.
Perform detailed reviews of application architecture, APIs, integrations, and data flows to identify security risks.
Evaluate implementation of:
Encryption controls
DLP solutions
DAM controls
IAM and privileged access controls
Assess handling of sensitive data including PII, financial, payroll, supplier, and employee information.
Review cloud-native security controls within GCP environments.
Evaluate role-based access controls, Segregation of Duties (SoD), and user provisioning processes.
Conduct risk assessments and provide remediation recommendations.
Partner with Cybersecurity, Enterprise Architecture, Infrastructure, and Application teams throughout project lifecycles.
Assess third-party vendors and SaaS platforms against security and compliance standards.
Track remediation efforts and validate security control implementation.
Prepare security assessment reports, risk registers, executive summaries, and audit documentation.
Support internal and external audits and regulatory reviews.
 
Generic Managerial Skills, If any
The Cyber Threat Remediation Analyst serves as the operational coordinator for enterprise threat remediation activities. This role focuses on managing remediation processes, tracking cyber threat findings, facilitating stakeholder engagement, supporting threat applicability assessments, and improving remediation workflows.
Unlike traditional Vulnerability Management roles focused primarily on patching activities, this position supports a broader Threat Remediation Program that incorporates insights from Cyber Threat Intelligence, Incident Response, Red Team assessments, penetration testing, security assessments, and other cybersecurity initiatives.
This role is ideal for someone who enjoys combining cybersecurity knowledge, stakeholder engagement, process improvement, and program execution to help drive meaningful risk reduction across the enterprise. It goes beyond program tracking by helping evaluate threat applicability, assess organizational exposure, and influence remediation decisions in partnership with cybersecurity subject matter experts.