1

Vendor Risk Assessment Jobs in California (NOW HIRING)

Sr IT Vendor Manager

Irvine, CA

$116K - $197K/yr

  • Medical

  • Life

  • Retirement

  • PTO

Conduct due diligence, market assessments, RFIs, and vendor capability reviews ... Standardize governance, segmentation, risk scoring, financial tracking, and spend analytics.

GRC Risk Management Analyst

San Jose, CA · On-site

$68 - $72/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review. * Administer risk-based vendor ...

GRC Risk Management Analyst

San Jose, CA · On-site

$68.97 - $72.80/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

... assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review. Administer risk-based vendor ...

The Vendor Management function supports supplier onboarding, contract routing and triaging of ... Risk Assessment & Mitigation * Perform continuous risk assessments on the supplier base ...

Manager, IT Risk Operations

Palo Alto, CA · On-site

$147K - $198K/yr

Enhance vendor risk processes, including risk tiering, assessments, and monitoring * Identifyopportunities to streamline processes, enhance reporting, and improve governance * Introduce data-driven ...

Lead - Vendor Management

San Mateo, CA · On-site

$105K - $130K/yr

The Vendor Management function supports supplier onboarding, contract routing and triaging of ... Risk Assessment & Mitigation * Perform continuous risk assessments on the supplier base ...

The Vendor Management function supports supplier onboarding, contract routing and triaging of ... Risk Assessment & Mitigation * Perform continuous risk assessments on the supplier base ...

... • Assess and manage security risk across Sierra's full third-party landscape, recognizing that vendors, strategic partners, and contractors carry distinct risk profiles and require tailored ...

Showing results 21-40

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What cities in California are hiring for Vendor Risk Assessment jobs?

Cities in California with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in California as of August 2026, with employment types broken down into 92% Full Time, and 8% Contract. Highlights an 84% In-person, 8% Hybrid, and 8% Remote job distribution.

$116K - $197K/yr

Full-time

Medical, Life, Retirement, PTO

Re-posted 8 days ago


Job description

Accelerate your career. Join the organization that's driving the world's technology and shape the future.

Ingram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to business-to-business technology experts. Our market reach, diverse solutions and services portfolio, and digital platform Ingram Micro Xvantage set us apart. Learn more at www.ingrammicro.com

Come join our team where you'll make technology happen in surprising ways. Let's shape tomorrow - it'll be a fun journey!

The Sr. IT Vendor Manager is a key member of the Vendor Management Office (VMO) responsible for driving value, performance, and accountability across strategic technology vendors. The role establishes vendor strategy and governance, oversees contracts and commercials, manages vendor performance, escalations, risks & compliance and enables strong cross-functional collaboration.

This role also leads outsourcing lifecycle activities including opportunity identification, solution offerings, business case development, transitions, training programs, adoption strategies, and financial reporting for technology portfolios. The ideal candidate thrives in a fast-paced environment, handles high pressure, and manages heavy workloads

Your role:

Strategic Vendor Relationship Management

  • Manage vendor contracts, commercial governance, risk, compliance, audits, controls, and performance management.

  • Ensure alignment between vendor capabilities and Ingram Micro's strategic objectives.

  • Improve executive visibility into vendor performance, commitments, and value realization.

  • Leverage vendor intellectual property, innovation roadmaps, and best practices to maximize business outcomes

Technology & Spend Optimization

  • Inventory and analyze technology spend across software, hardware, cloud, managed services, and external labor.

  • Identifyopportunities for license optimization, asset rationalization, consumption management, and labor efficiency.

  • Conduct ongoing vendor capability assessments and benchmarking exercises.

  • Drive continuous cost optimization initiatives whilemaintainingservice quality and business outcomes.

Portfolio Advisory & Operating Model Assessment

  • Partner closely with IT portfolios and functional leaders to assess:

  • Spend and investment patterns

  • Processes and operating models

  • Technology tools and platforms

  • Resourceutilizationand effort allocation

  • Risks and control effectiveness

  • Provide recommendations to improve efficiency, scalability, and organizational effectiveness.

Business Case Development &Execution

  • Conduct due diligence, market assessments, RFIs, and vendor capability reviews.

  • Identifyinnovation, transformation, and consolidation opportunities.

  • Build data-driven business cases supported by financial analysis and measurable outcomes.

  • Partner with PMO, IT leadership, Finance, and vendors to execute approved initiatives.

  • Establish governance structures tomonitorbenefits realization and sustain outcomes

Team Management:

  • Support development of a highperforming vendor management function.

  • Oversee offshore vendor management activities, including communications, SLA tracking, deliverables, data collection, and documentation.

  • Maintain structured operating cadences (daily/weekly/monthly/quarterly).

  • Standardize governance, segmentation, risk scoring, financial tracking, and spend analytics.

  • Deliver training programs to upskill internal and vendor teams.

What you bring to the role:
  • Bachelor's degree in information technology, Business, Supply Chain, or a related field.

  • 7+ years of experience in IT vendor relationship management, vendor governance & performance management, vendor risk profiling, and escalation management.

  • Experience in IT Functions Operating Model Transformation; workforce automation, vendor consolidation, Application rationalization & optimization

  • Proven ability to continuously align vendor capabilities with IT vision and requirements

  • Strong understanding of Technology Platform and IT vendor management principles, procedures and best practices.

  • Proven ability to manage multiple Vendors, Transition, Delivery and Governance simultaneously.

  • Experienced in Managed Services Delivery Management, Financial Management and Contract Management.

  • Vendor Management Certifications preferred such as PMP, ITIL, OCM, CIVM, CVMP, or relevant certification.

#LI-LB2

The typical base pay range for this role across the U.S. is USD $116,000.00 - $197,200.00 per year.

The ranges above reflect the potential annual base pay across the U.S. for all roles; the applicable base pay range will depend on the candidate's primary work location, pay grade, and variable compensation plan. Individual base pay within each range depends on various factors, in addition to primary work location, such as complexity and responsibility of role, job duties/requirements, and relevant experience and skills. Base pay ranges are reviewed and typically updated each year. Offers are made within the base pay range applicable at the time of hire. New hires starting base pay generally falls in the bottom half (between the minimum and midpoint) of a pay range.

At Ingram Micro certain roles are eligible for additional rewards, including merit increases, annual bonus or sales incentives and long-term incentives. These awards are allocated based on position level and individual performance. U.S.-based employees have access to healthcare benefits, paid time off, parental leave, a 401(k) plan and company match, short-term and long-term disability coverage, basic life insurance, and wellbeing benefits, among others.

This is not a complete listing of the job duties. It's a representation of the things you will be doing, and you may not perform all these duties.

Please be prepared to pass a drug test and successfully pass a pre-employment (post offer) background check.

Ingram Micro Inc. is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected category under applicable law.