1

Vendor Risk Assessment Jobs in Maryland (NOW HIRING)

Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)

Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)

Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)

Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)

... to assess and communicate risks associated U.S. and European corporate bonds, interest rate and ... Prototype and develop risk reporting and tools to enhance existing vendor risk platforms (primarily ...

Director of Risk Management

Towson, MD · On-site

$106.46 - $175.42/hr

Maintain risk management policies, procedures, and risk assessment tools, including the Risk Matrix ... Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage ...

Maintain risk management policies, procedures, and risk assessment tools, including the Risk Matrix ... Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage ...

Director of Risk Management

Towson, MD · On-site

$51.18 - $84.34/hr

Maintain risk management policies, procedures, and risk assessment tools, including the Risk Matrix ... Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in Maryland are hiring for Vendor Risk Assessment jobs?

Cities in Maryland with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution.

Senior, Technology 3rd Party Risk - Tax Transformation

Deloitte

Baltimore, MD • On-site

Full-time

Re-posted 10 days ago


Deloitte rating

8.2

Company rating: 8.2 out of 10

Based on 93 frontline employees who took The Breakroom Quiz

46th of 152 rated financial services


Job description

The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.

At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.

Recruiting for this role ends on May 31, 2027

Work you'll do 

The Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.

Responsibilities include:

  • Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
  • Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
  • Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
  • Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
  • Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
  • Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.

A successful candidate would possess these skills:

  • Strong communicator with the ability to tailor messages for technical and non-technical audiences. 
  • Collaborative relationship builder who works effectively across functions and levels to drive alignment. 
  • Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams. 
  • Confident facilitator who influences without authority and helps move issues to resolution.

The Team 

Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients. 

Qualifications 

Required:

  • Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
  • Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
  • 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
  • Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
  • Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
  • Limited immigration sponsorship may be available.
  • Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
  • One of the following active accreditations obtained:
    • Licensed CPA in state of practice/primary office if eligible to sit for the CPA
    • If not CPA eligible:
      • Licensed Attorney
      • Enrolled Agent
      • CBAP - Certified Business Analysis Professional
      • Certified in Risk and Information System Controls (CRISC)
      • Microsoft Azure
      • Project Management Professional (PMP)

Preferred:

  • Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes. 
  • Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences. 
  • Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels. 
  • Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs. 
  • Experience supporting business process improvement, transformation, or technology-enabled change initiatives. 
  • Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Qualifications:

The Deloitte Tax LLP's (Deloitte Tax) Tax Transformation Office (TTO) is pivotal to supporting Deloitte Tax client service delivery by optimizing end-to-end business processes and utilizing technology across all Tax offerings. This methodology improves efficiency in service delivery and encourages growth. The Senior Consultant - Technology Third Party Risk Management (TPRM) role offers an opportunity to be part of an innovative team within Deloitte Tax, focused on delivering value consistent with the Deloitte brand.

At Deloitte, we guide clients through the complex and evolving field of tax transformation. Through a broad suite of integrated tax services, we generate greater impact for clients. Our approach merges advanced technology and tax expertise to provide insights and smarter solutions, supporting clients to navigate a rapidly changing global environment.

Recruiting for this role ends on May 31, 2027

Work you'll do 

The Senior Consultant - Technology Third Party Risk Management role in the Tax Transformation Office (TTO) requires hands-on understanding of professional services, models for third-party relationships, and relevant technologies. In this position, you will collaborate across different tax offerings, engaging with Business Leaders and professionals from multiple Risk Review teams. Key responsibilities include managing a portfolio of technology vendors, software platforms, and strategic alliance partners by supporting the creation of new third-party relationships as Deloitte Tax pursues strategic growth initiatives.

Responsibilities include:

  • Leading end-to-end TPRM reviews - coordinating intake, managing due diligence documentation (such as security questionnaires and SOC reports), for both new and renewing vendors.
  • Maintaining the vendor risk register and tracking dashboards - providing leadership with timely and accurate updates on current reviews, escalations, and remediation actions.
  • Establishing a reputation as a primary point of contact for TPRM process questions - offering subject matter guidance to business sponsors, vendor managers, and other stakeholders throughout the review lifecycle.
  • Partnering with Independence, Risk, Legal (OGC), Vendor Cyber, Confidentiality & Privacy, and Procurement teams - ensuring alignment on compliance requirements, identifying and resolving obstacles, and maintaining consistent application of policies and practices.
  • Identifying process improvement opportunities within the TPRM lifecycle - driving efficiency gains through enhanced tooling, improved documentation standards, or workflow redesign.
  • Supporting broader TTO Strategic Technology Services initiatives - contributing to third-party relationship strategy, vendor portfolio governance, and alliance program operations.

A successful candidate would possess these skills:

  • Strong communicator with the ability to tailor messages for technical and non-technical audiences. 
  • Collaborative relationship builder who works effectively across functions and levels to drive alignment. 
  • Adaptable, self-directed problem solver who can manage shifting priorities and multiple workstreams. 
  • Confident facilitator who influences without authority and helps move issues to resolution.

The Team 

Deloitte Tax LLP's Tax Transformation Office (TTO) is responsible for the design, development, and deployment of innovative, enterprise technology, tools, and standard processes to support the delivery of tax services. The TTO team focuses on enhancing Deloitte Tax LLP's ability to deliver comprehensive, value-added, and efficient tax services to our clients. The TTO Strategic Technology Services team is responsible for the enablement of standard technology to support Tax service delivery and developing technology to facilitate these services. TTO is focused on expanding Deloitte Tax capacity to deliver efficient, value-added Tax services to clients. 

Qualifications 

Required:

  • Ability to perform job responsibilities within a hybrid work model that requires US Tax professionals to co-locate in person 2 - 3 days per week
  • Bachelor's degree in Business Administration, Information Systems, Computer Science or other relevant discipline
  • 3+ years' experience in transformation, consulting, strategic program delivery, or vendor/third-party management.
  • Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment.
  • Demonstrated familiarity with risk and compliance frameworks - TPRM, SOC 2, or similar.
  • Limited immigration sponsorship may be available.
  • Ability to travel up to 10%, on average, based on the work you do and the clients and industries/sectors you serve
  • One of the following active accreditations obtained:
    • Licensed CPA in state of practice/primary office if eligible to sit for the CPA
    • If not CPA eligible:
      • Licensed Attorney
      • Enrolled Agent
      • CBAP - Certified Business Analysis Professional
      • Certified in Risk and Information System Controls (CRISC)
      • Microsoft Azure
      • Project Management Professional (PMP)

Preferred:

  • Experience in a tax, financial services, or professional services environment, with exposure to third-party risk, vendor management, or related compliance processes. 
  • Strong verbal and written communication skills, with the ability to tailor messages for both technical and non-technical audiences. 
  • Proven stakeholder management, listening, and facilitation skills, including the ability to build alignment across diverse teams and levels. 
  • Broad awareness of technology tools, platforms, and emerging capabilities, with the ability to assess practical fit to business needs. 
  • Experience supporting business process improvement, transformation, or technology-enabled change initiatives. 
  • Prior consulting or professional services experience, and/or relevant certifications such as PMP, CTPRM, or similar.

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $93,000 to $191,000.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom