1

Vendor Risk Assessment Jobs in Maryland (NOW HIRING)

Performs vendor risk assessments, residual risk assessments, and ongoing monitoring activities in accordance with established program requirements. Requests, reviews, uploads, categorizes, and tracks ...

Performs vendor risk assessments, residual risk assessments, and ongoing monitoring activities in accordance with established program requirements. Requests, reviews, uploads, categorizes, and tracks ...

New

... to assess and communicate risks associated U.S. and European corporate bonds, interest rate and ... Prototype and develop risk reporting and tools to enhance existing vendor risk platforms (primarily ...

Director of Risk Management

Towson, MD · On-site

$106.46 - $175.42/hr

Maintain risk management policies, procedures, and risk assessment tools, including the Risk Matrix ... Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage ...

Director of Risk Management

Towson, MD · On-site

$51.18 - $84.34/hr

Maintain risk management policies, procedures, and risk assessment tools, including the Risk Matrix ... Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage ...

Maintain risk management policies, procedures, and risk assessment tools, including the Risk Matrix ... Review and evaluate vendor agreements and contracts to identify, minimize, and appropriately manage ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in Maryland are hiring for Vendor Risk Assessment jobs?

Cities in Maryland with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution.

Risk Management Coordinator

Tower

Laurel, MD • On-site

Full-time

Posted 9 days ago


Job description

Summary of Position
Primary responsibilities include executing activities related to the Enterprise Risk Management Program, Vendor and Contract Management Program, and Corporate Insurance Program. The Risk Management Coordinator evaluates operational, third-party, and enterprise risks; analyzes complex data and risk information; identifies trends and emerging risks; and develops recommendations to strengthen internal controls and risk mitigation strategies. The Coordinator exercises sound judgment in performing risk assessments, interpreting due diligence documentation, and communicating findings to business leaders. This role is responsible for monitoring key risk indicators, identifying process improvement opportunities, supporting strategic risk initiatives, and contributing to the continued maturity of the Credit Union's risk management framework.
Principal Accountabilities and Functions
Evaluates vendor due diligence documentation, identifies material risks and control deficiencies, assesses overall risk exposure, and develops recommendations for risk mitigation and escalation.
Performs vendor risk assessments, residual risk assessments, and ongoing monitoring activities in accordance with established program requirements.
Requests, reviews, uploads, categorizes, and tracks vendor due diligence documentation within the risk management database; follows up with vendors and internal stakeholders to obtain required information.
Analyzes trends in vendor performance, cybersecurity ratings, financial condition, audit results, and other risk indicators to identify emerging risks and recommend corrective actions.
Evaluates data quality, identifies reporting discrepancies, and recommends enhancements to improve data integrity, reporting accuracy, and workflow efficiency.
Prepares and distributes recurring reports, dashboards, metrics, and scorecards related to vendor management, enterprise risk management, contract management, and corporate insurance activities.
Coordinates and independently manages assigned vendor onboarding activities, evaluates risk assessment results, resolves outstanding issues with business units, and recommends appropriate risk ratings.
Reviews contractual provisions for risk considerations, identifies unusual terms or potential concerns, and coordinates resolution with business owners and stakeholders.
Analyzes insurance claims, policy coverage, loss trends, and renewal information to identify exposures and recommend improvements to coverage or reporting practices.
Collaborates with internal stakeholders including Information Security, IT, Compliance, Finance, Business Continuity, Facilities, and Internal Audit to support risk management initiatives and ensure program alignment with regulatory expectations and industry best practices.
Assists with enterprise risk management activities, including gathering information, preparing risk assessments, maintaining risk inventories, and supporting risk reporting.
Researches regulatory guidance, industry trends, and emerging risks and communicates relevant information to management.
Facilitates cooperation with regulatory examinations, internal audits, and third-party audits by gathering documentation, responding to requests, and tracking remediation activities.
Develops, updates, and maintains procedures, training materials, forms, and intranet content related to risk management programs.
Participates in testing and validation activities related to risk management systems and process enhancements.
Identifies systemic issues through data analysis, develops recommendations to improve operational efficiency, strengthen internal controls, and increase automation within risk management processes.
Supports risk management training and awareness initiatives across the organization.
Performs related duties as assigned.
Required Qualifications
Associates degree in Business Administration, Finance, Risk Management, Information Technology, or a related field (or equivalent work experience).
Two to four years of relevant experience in vendor management, contract administration, compliance, risk management, insurance administration, audit, or a related function.
Working knowledge of third-party risk management, enterprise risk management, contract management, and corporate insurance processes.
Experience with risk management, governance, risk and compliance (GRC), contract management, or vendor management software preferred.
General knowledge of applicable regulatory requirements and guidance, including NCUA, FFIEC, GLBA, and third-party risk management expectations.
Professional certifications preferred, such as Certified Regulatory Vendor Program Manager (CRVPM), National Credit Union Risk Management Certification (NCRM), or similar credentials.
Or an equivalent combination of education and experience
Knowledge, Skills and Abilities
Strong organizational skills and attention to detail.
Ability to manage multiple tasks and meet deadlines.
Effective written and verbal communication skills.
Knowledge of SOC reports, independent audit reports, and other third-party assurance documentation.
Strong analytical, organizational, and problem-solving skills with the ability to identify, assess, and communicate risk-related issues.
Ability to evaluate existing processes and recommend enhancements that improve effectiveness, efficiency, and risk management outcomes.
Analytical and critical thinking skills with the ability to interpret complex information, identify trends, evaluate risk, and formulate sound recommendations.
Ability to synthesize information from multiple sources and communicate meaningful conclusions.
Demonstrated judgment in evaluating risk and determining appropriate escalation.
Ability to influence business partners through data-driven recommendations.
Ability to identify root causes and recommend practical risk mitigation strategies.
Proficiency in Microsoft Office (Excel, Word, Outlook, Teams).
Ability to work both independently and collaboratively.
Comfortable working with data and maintaining accurate records.
Professional and responsive when working with internal stakeholders.
Has knowledge of and adheres to credit union policies and procedures and all regulations related to the Bank Secrecy Act, the USA PATRIOT Act and OFAC.
Working Conditions
Ability to work the hours needed, which may extend beyond the defined work schedule when operating conditions dictate.
Ability to lift up to 15 lbs., with or without assistance, in compliance with ADA.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.