1

Vendor Risk Assessment Jobs in California (NOW HIRING)

Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture ...

Sr IT Vendor Manager

Irvine, CA · On-site

$116K - $197K/yr

Manage vendor contracts, commercial governance, risk, compliance, audits, controls, and performance ... Conduct ongoing vendor capability assessments and benchmarking exercises. * Drive continuous cost ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in California are hiring for Vendor Risk Assessment jobs?

Cities in California with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in California as of August 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 84% In-person, 8% Hybrid, and 8% Remote job distribution.

Third Party Risk Management Lead

Jobtailor

Foster City, CA • On-site

$150 - $230/hr

Other

Posted 11 days ago


Job description

Responsibilities
  • Run substantive third‑party risk management (TPRM), independently evaluating real risk, not just processing questionnaire responses
  • Review SOC 2 reports, pen test findings, and architecture documentation to form an independent view of vendor risk, extending the same rigor to AI/model providers
  • Partner with Legal on vendor and AI contract terms, including DPAs, subprocessor agreements, and AI‑specific provisions
  • Review contracts for non‑standard security language when flagged by Legal or deal desk, and recommend redlines
  • Maintain the vendor and AI/model risk register, feeding findings into the company's master risk register
  • Enable sales through maturing the customer trust program
  • Build the capability for continuous monitoring of vendor ecosystem
Requirements
  • 8+ years in third‑party/vendor risk management, security risk, or a related GRC role
  • Demonstrated ability to independently assess vendor risk rather than relying on questionnaire responses alone, fluent in reading SOC 2 reports, ISO certificates, pen test summaries, and architecture documentation
  • Experience reviewing or redlining security and data‑handling contract language, ideally in partnership with a legal team
  • Working knowledge of data privacy fundamentals (GDPR, CCPA) as they relate to vendor and subprocessor relationships
  • Strong cross‑functional collaboration skills — this role touches Legal, Engineering, Product, and Sales regularly
  • Experience building repeatable, scalable vendor review processes rather than inheriting an existing one
  • Bonus Qualifications include direct experience assessing foundation model providers or AI/ML vendors specifically
Core Competencies

Expertise in third‑party risk management, including independent vendor risk assessment and contract review, with a strong understanding of data privacy regulations and the ability to collaborate across multiple functions. Proven capability in building scalable vendor review processes and maintaining comprehensive risk registers.

#J-18808-Ljbffr