Vendor Risk Assessments: Conduct risk assessments and due diligence for new and existing third-party vendors. Collect and analyze vendor responses (such as security questionnaires, audit reports, SOC ...
Vendor Risk Assessments: Conduct risk assessments and due diligence for new and existing third-party vendors. Collect and analyze vendor responses (such as security questionnaires, audit reports, SOC ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and risk ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and risk ...
Vendor Risk Assessments: Conduct risk assessments and due diligence for new and existing third-party vendors. Collect and analyze vendor responses (such as security questionnaires, audit reports, SOC ...
Vendor Risk Assessments: Conduct risk assessments and due diligence for new and existing third-party vendors. Collect and analyze vendor responses (such as security questionnaires, audit reports, SOC ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and riskbased ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and riskbased ...
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site +1
$200K - $225K/yr
Maintain vendor risk databases and communicate risk assessments findings across the organization * Establish and publish KPIs and SLAs to evaluate the effectiveness of area and initiatives
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site +1
$200K - $225K/yr
Maintain vendor risk databases and communicate risk assessments findings across the organization * Establish and publish KPIs and SLAs to evaluate the effectiveness of area and initiatives
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site
$200K - $225K/yr
Maintain vendor risk databases and communicate risk assessments findings across the organization * Establish and publish KPIs and SLAs to evaluate the effectiveness of area and initiatives
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site
$200K - $225K/yr
Maintain vendor risk databases and communicate risk assessments findings across the organization * Establish and publish KPIs and SLAs to evaluate the effectiveness of area and initiatives
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site +1
$200K - $225K/yr
Maintain vendor risk databases and communicate risk assessments findings across the organization * Establish and publish KPIs and SLAs to evaluate the effectiveness of area and initiatives
Vendor Risk Management & Onboarding, SVP - Procurement
Miami, FL · On-site +1
$200K - $225K/yr
Maintain vendor risk databases and communicate risk assessments findings across the organization * Establish and publish KPIs and SLAs to evaluate the effectiveness of area and initiatives
Lead, Information Risk and GRC
Miami, FL · On-site
Vendor onboarding and inherent risk tiering; Security due diligence (cyber risk assessments); Continuous monitoring and reassessment; Offboarding and risk closure * Define and enhance third-party ...
Lead, Information Risk and GRC
Miami, FL · On-site
Vendor onboarding and inherent risk tiering; Security due diligence (cyber risk assessments); Continuous monitoring and reassessment; Offboarding and risk closure * Define and enhance third-party ...
Senior Cybersecurity Risk Analyst - USA Remote
Miami, FL · Remote
$130K - $160K/yr
Assess supply-chain and geopolitical risk (including country-of-origin and concentration concerns) and apply AI vendor risk frameworks (NIST AI RMF, ISO/IEC 42001) to AI-enabled products and services ...
Senior Cybersecurity Risk Analyst - USA Remote
Miami, FL · Remote
$130K - $160K/yr
Assess supply-chain and geopolitical risk (including country-of-origin and concentration concerns) and apply AI vendor risk frameworks (NIST AI RMF, ISO/IEC 42001) to AI-enabled products and services ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
The Office Administrative & Vendor Management Associate provides direct operational and administrative support with a primary focus on supplier onboarding, compliance and risk assessment and as a key ...
The Office Administrative & Vendor Management Associate provides direct operational and administrative support with a primary focus on supplier onboarding, compliance and risk assessment and as a key ...
Role: Vendor & Commercial Manager (Licensing Specialist) Location: East Coast (NY/NJ, Atlanta ... License Risk Analysis * Conduct detailed license position assessments and risk diagnostics.
Role: Vendor & Commercial Manager (Licensing Specialist) Location: East Coast (NY/NJ, Atlanta ... License Risk Analysis * Conduct detailed license position assessments and risk diagnostics.
Role: Vendor & Commercial Manager (Licensing Specialist) Location: East Coast (NY/NJ, Atlanta ... License Risk Analysis * Conduct detailed license position assessments and risk diagnostics.
Quick apply
Role: Vendor & Commercial Manager (Licensing Specialist) Location: East Coast (NY/NJ, Atlanta ... License Risk Analysis * Conduct detailed license position assessments and risk diagnostics.
... vendor engagements; leading or supporting various programs, including risk and control self-assessment (RCSA), process, risk, and control, and other risk policies, standards, and processes. As part ...
... vendor engagements; leading or supporting various programs, including risk and control self-assessment (RCSA), process, risk, and control, and other risk policies, standards, and processes. As part ...
... and risk reduction * Lead regular business reviews with key vendors to assess performance and ... identify improvement opportunities Contracting & Commercial Oversight * Partner with procurement ...
... and risk reduction * Lead regular business reviews with key vendors to assess performance and ... identify improvement opportunities Contracting & Commercial Oversight * Partner with procurement ...
Vendor Risk Assessment information
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?
What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?
What is a Vendor Risk Assessment?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 14 days ago
AmeriLife rating
8.6
Based on 11 frontline employees who took The Breakroom Quiz
86th of 298 rated insurance
Job description
Explore how you can contribute at AmeriLife.
For over 50 years, AmeriLife has been a leader in the development, marketing and distribution of annuity, life and health insurance solutions for those planning for and living in retirement.
Associates get satisfaction from knowing they provide agents, marketers and carrier partners the support needed to succeed in a rapidly evolving industry.
Job Summary
Reporting to the Director of Third-Party Risk Management, the Third-Party Risk Management Associate supports the execution and continuous improvement of the organization's Third-Party Risk Management (TPRM) program. This role is responsible for conducting vendor risk assessments, managing day-to-day third-party risk processes, maintaining thorough documentation, and monitoring key risk indicators (KRIs). The Associate partners closely with cross-functional teams and leverages technology to help ensure that all vendors and third-party service providers meet the organization's security, compliance, operational and risk management requirements.
Job Description
Key Responsibilities
- Vendor Risk Assessments: Conduct risk assessments and due diligence for new and existing third-party vendors. Collect and analyze vendor responses (such as security questionnaires, audit reports, SOC reports), identify potential risk areas, recommend appropriate mitigation strategies, and summarize findings for management review.
- Third-Party Lifecycle Support: Help coordinate the end-to-end third-party lifecycle, including vendor onboarding, ongoing performance management and risk monitoring, contract reviews, issue management, and offboarding. Ensure all required risk checks and approvals are completed and documented at appropriate lifecycle stages.
- Documentation & Reporting: Maintain accurate TPRM documentation and records, including risk assessment results, remediation plans, and risk acceptance decisions. Prepare regular reports and dashboards on third-party risk metrics and Key Risk Indicators (KRIs) for review by senior risk management.
- Tool Management: Use approved technology to support automation of TPRM workflows. This includes managing vendor inventories, issuing and tracking risk assessment questionnaires, monitoring vendor compliance status, and generating risk reports.
- Risk Monitoring & Issue Tracking: Continuously monitor third-party risk profiles and compliance status. Track open risk issues or remediation plans in the TPRM system and follow up with vendors or internal stakeholders to ensure timely completion of mitigation actions. Escalate significant findings or delays to the Director, as needed.
- Stakeholder Collaboration: Work closely with internal teams such as IT Security, Compliance, Legal, Procurement, and business units to gather necessary information for vendor evaluations. Support communication with stakeholders and vendors to clarify requirements, obtain documentation, and resolve any identified risk or compliance issues.
- Program Administration: Assist in the development, maintenance, and enhancement of TPRM policies, procedures, standards, and templates. Support audits, regulatory examinations, and compliance reviews related to third-party risk management activities. Contribute to ongoing process improvements and program maturity initiatives.
Required Qualifications
- Education & Experience: Bachelor's degree in Business, Information Systems, Cybersecurity, or related field. 3-5 years of experience in risk management, vendor management, compliance, or information security, with exposure to third-party risk management or vendor due diligence processes.
- Regulatory & Industry Knowledge: Familiarity with key compliance and security frameworks and regulations (such as CPRA, HIPAA, SOX, ISO 27001, NIST) and an understanding of how they apply to third-party/vendor risk.
- Professional Certifications: Certified Third-Party Risk Professional (CTPRP), Certified Risk and Compliance Management Professional (CRCMP) or Certified Regulatory Vendor Program Manager (CRVPM).
- Technical Skills: Experience using vendor risk management technology to manage risk assessments, workflows, and reporting. Proficient with standard business software (Excel, PowerPoint, Word) for data analysis and presentation.
- Analytical Abilities: Strong analytical and problem-solving skills with keen attention to detail. Ability to interpret risk assessment data, identify trends or red flags in vendor responses, and assist in developing mitigation steps.
- Communication Skills: Excellent written and verbal communication skills. Capable of preparing clear reports and effectively communicating findings and requirements to internal stakeholders and vendors.
- Collaboration & Organization: Demonstrated ability to work collaboratively in cross-functional teams. Strong organizational and time-management skills, with the ability to manage multiple vendor assessments and tasks concurrently and meet deadlines.
Preferred Qualifications
- Process Improvement & Automation: Experience in optimizing risk management processes or workflows. Familiarity with automation features in GRC platforms or other risk management tools to improve efficiency and reporting.
- Industry Knowledge: Working understanding of vendor contract terms related to security and privacy, as well as awareness of emerging third-party risk trends (such as cloud security, data protection, artificial intelligence fourth-party risk).
- Financial Services Experience (Preferred): Experience supporting third-party risk management programs within banking, financial services, insurance, fintech, or other highly regulated industries.
- Project Management: Ability to manage multiple assignments/projects and meet deadlines in a fast-paced environment.
What AmeriLife Offers
A comprehensive benefits package that includes PTO, medical, dental, vision, retirement savings, disability insurance, and life insurance.
Equal Employment Opportunity Statement
We are an Equal Opportunity Employer and value diversity at all levels of the organization. All employment decisions are made without regard to race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), sexual orientation, gender identity or expression, age, national origin, ancestry, disability, genetic information, marital status, veteran or military status, or any other protected characteristic under applicable federal, state, or local law. We are committed to providing an inclusive, equitable, and respectful workplace where all employees can thrive.
Americans with Disabilities Act (ADA) Statement
We are committed to full compliance with the Americans with Disabilities Act (ADA) and all applicable state and local disability laws. Reasonable accommodations are available to qualified applicants and employees with disabilities throughout the application and employment process. Requests for accommodation will be handled confidentially. If you require assistance or accommodation during the application process, please contact us at HR@AmeriLife.com.
Pay Transparency Statement
We are committed to pay transparency and equity, in accordance with applicable federal, state, and local laws. Compensation for this role will be determined based on skills, qualifications, experience, and market factors. Where required by law, the pay range for this position will be disclosed in the job posting or provided upon request. Additional compensation information, such as benefits, bonuses, and commissions, will be provided as required by law. We do not discriminate or retaliate against employees or applicants for inquiring about, discussing, or disclosing their pay or the pay of another employee or applicant, as protected under applicable law. Pay ranges are available upon request.
Background Screening Statement
Employment offers are contingent upon the successful completion of a background screening, which may include employment verification, education verification, criminal history check, and other job-related inquiries, as permitted by law. All screenings are conducted in accordance with applicable federal, state, and local laws, and information collected will be kept confidential. If any adverse decision is made based on the results, applicants will be notified and given an opportunity to respond.
What AmeriLife employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom