1

Vendor Risk Assessment Jobs in Illinois (NOW HIRING)

Pay Range: $45 - $55 per hour Seeking a Third Party Risk Management Consultant II to support continuous monitoring, risk assessments, and ongoing oversight of critical third-party vendors. The ideal ...

Assess AI vendors and features embedded in existing software (e.g., new AI features rolled into SaaS products) for security implications Third-Party & Vendor Risk * Conduct vendor security ...

Assess AI vendors and features embedded in existing software (e.g., new AI features rolled into SaaS products) for security implications Third-Party & Vendor Risk * Conduct vendor security ...

GRC Specialist II

Chicago, IL · On-site

$116K - $144K/yr

Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Exception & Risk Treatment: Oversee the ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in Illinois are hiring for Vendor Risk Assessment jobs?

Cities in Illinois with the most Vendor Risk Assessment job openings:

Third Party Risk Mgmt Consultant II

Epitec

Chicago, IL • On-site, Remote

$45 - $55/hr

Contractor

Medical, Dental, Vision, Retirement, PTO

This job post has expired today. Applications are no longer accepted.


Job description

  • Location: Chicago, Illinois
  • Type: Contract
  • Job #106468
  • Job Title: Third Party Risk Management Consultant II (TPRM Continuous Monitoring Analyst)
  • Location: Chicago, IL (Remote considered, Chicago preferred)
  • Job Type: Full Time, Contract
  • Expected Hours per Week: 40
  • Schedule: Monday-Friday, 8 hours per day, Remote/Hybrid based on candidate location
  • Pay Range: $45 - $55 per hour

Job Description:
Seeking a Third Party Risk Management Consultant II to support continuous monitoring, risk assessments, and ongoing oversight of critical third-party vendors. The ideal candidate will have experience in vendor risk management, information security, and risk intelligence analysis, with the ability to communicate effectively with executive stakeholders and cross-functional teams.
This role focuses on identifying, assessing, and remediating vendor risks utilizing risk intelligence tools and industry-standard control frameworks while ensuring regulatory and organizational compliance.
Key Responsibilities
  • Monitor third-party vendor risk using risk intelligence tools such as Supply Wisdom and Black Kite, including daily alert reviews and risk triage.
  • Conduct periodic vendor reassessments, trigger-based reviews, due diligence evaluations, and SOC report reviews.
  • Evaluate vendor controls across cybersecurity, privacy, business continuity, operational resilience, and compliance domains.
  • Analyze risk trends, document findings, and provide recommendations regarding inherent and residual risk ratings.
  • Escalate critical and high-risk findings within established SLAs and coordinate remediation efforts with internal stakeholders.
  • Maintain accurate records in ProcessUnity and support monthly and quarterly executive reporting.

Required Qualifications
  • Bachelor's degree or equivalent experience.
  • 3 to 5 years of experience in Information Security, Third-Party Risk Management, Vendor Risk Management, or IT Risk Management.
  • Experience conducting vendor risk assessments, reassessments, and control validations.
  • Familiarity with NIST, ISO 27001, SOC 2, SIG, and other risk and control frameworks.
  • Strong analytical, communication, and stakeholder management skills.
  • Ability to manage multiple priorities in a fast-paced environment while maintaining attention to detail.

Preferred Qualifications
  • CISSP, CRISC, or CISA certification.
  • Experience with ProcessUnity, Supply Wisdom, and Black Kite platforms.
  • Proven expertise in continuous monitoring, risk intelligence, investigations, and remediation activities.
  • Experience presenting findings and recommendations to executive leadership and cross-functional stakeholders.

Why This Role?
  • Opportunity to play a key role in protecting the organization from evolving third-party risks.
  • Work closely with executive leadership and cross-functional risk professionals on high-impact initiatives.
  • Potential contract extension based on business needs and performance.

Work Environment
  • Chicago-based team with preference for local candidates, though remote candidates will be considered.
  • Collaborative environment working alongside Information Security, Privacy, Legal, Compliance, and Business Continuity teams.
  • Fast-paced risk management setting requiring strong judgment, prioritization, and communication skills.

Benefits: Medical, Dental, Vision, PTO & 401K
#INDOEM #LI-KG1