1

Vendor Risk Assessment Jobs in Maryland (NOW HIRING)

Complete vendor-related quality activities such as risk assessments, Supplier Corrective Action Requests (SCARs), Corrective and Preventive Actions (CAPAs), and other vendor quality events. * Draft ...

Complete vendor-related quality activities such as risk assessments, Supplier Corrective Action Requests (SCARs), Corrective and Preventive Actions (CAPAs), and other vendor quality events. * Draft ...

Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. * Maintain the risk register, including tracking third-party and vendor risk. * Keep control mapping and ...

Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. * Maintain the risk register, including tracking third-party and vendor risk. * Keep control mapping and ...

Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. * Maintain the risk register, including tracking third-party and vendor risk. * Keep control mapping and ...

Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. * Maintain the risk register, including tracking third-party and vendor risk. * Keep control mapping and ...

Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. * Maintain the risk register, including tracking third-party and vendor risk. * Keep control mapping and ...

Support audits, assessments, and certification renewals for HIPAA, GDPR, HITRUST, and SOC 2. * Maintain the risk register, including tracking third-party and vendor risk. * Keep control mapping and ...

Perform 3rd party vendor risk management assessments. * Plan, develop, and enhance security standards, requirements gathering, and engineer security solutions across the risk and technology portfolio ...

Showing results 21-40

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in Maryland are hiring for Vendor Risk Assessment jobs?

Cities in Maryland with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Maryland as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution.

Senior Risk Analyst, Privacy & Third-Party Risk

T Rowe Price

Baltimore, MD • On-site

Full-time

Re-posted 28 days ago


T. Rowe Price rating

9.1

Company rating: 9.1 out of 10

Based on 21 frontline employees who took The Breakroom Quiz


Job description

Role Summary

The Senior Risk Analyst - Privacy &ThirdPartyRisk is aSecond Line of Defense (2LoD)role and a member of theGlobal Privacy Office (GPO)andThirdPartyRisk Management (TPRM)function. The role provides independent risk oversight, effective challenge, and assurance over first-line activities andoutsourced TPRM services,operatingwithminimal supervisionand a high degree of professional judgment.

This position is expected to independently manage complex risk assessments, lead oversight activities,identifyemerging risk themes, and deliver clear, actionable insights to senior stakeholders and governance committees.

Responsibilities

Privacy Risk- Global Privacy Office:

  • Independently provide 2LoD oversight of privacy risks arising from first-line business activitiesand serveas a subject matter resource on privacy risk matters.
  • Lead review andchallengeofPrivacy Impact Assessments (PIAs), Data Protection Impact Assessments (DPIAs), and privacy risk assessments.
  • Evaluate the design and operating effectiveness of privacy controls and recommend enhancements aligned with regulatory expectations and risk appetite.
  • Independently review privacy incidents, including root cause analyses and remediation plans.
  • Provide technicalexpertiseandsupportthe implementation of privacy and data protection processes, controls, and procedures based on enterprise-wide guidance issued by the Global Privacy Office.
  • Support the process of Privacy and Security by Design reviews, in particular, wherethey relate to the development and deployment of new technologies.This includes reviewing technical implementation details and design documentation for new systems andfeatures, andproviding guidance on improving privacy features in
  • those systems.
  • Collaborate with technology and security teams to embed privacy controls into the architecture of products and services, including providing advice and best practices to protect and mitigate privacy risks.
  • Identifyopportunities to enhance the Global Privacy Office's technical capabilities, develop,testand work with technology teams to deploy such capabilities.
  • Support the maintenance of the firm's required privacy compliance documentation (e.g., Records of Processing Activities, Transfer Impact Assessments, procedures, guides, training, SharePoint sites).
  • Support the execution of the privacy compliance monitoring program.

Third-Party Risk Management:

  • Perform quality assurance and effective challenge of third-party risk outputs produced by external service providers and first-line stakeholders.
  • Monitor adherence to SLAs, KPIs, and contractual obligations of outsourced TPRM providers and escalate deficiencies asappropriate.
  • Identifysystemic control gaps, concentration risk, and emerging third-party risk trends across the vendor population.
  • Support thirdparty cyber and information security risk review activities.
  • Contribute to the ongoing development of fourth-party risk governance and oversight practices.
  • Identifyopportunities to enhanceTRPM's technical capabilities, develop,testand work with technology teams to deploy such capabilities.
  • Support the maintenance of the firm's requiredTPRMcompliance documentation (e.g.,Policy, Supplier Management Standards, questionnaire templates, frameworks, training, Share Point sites).

Risk Governance, Reporting & Analytics:

  • Independently develop and deliver executive-level risk reporting, dashboards, and management information.
  • Assistwith monitoring and reporting emerging AI and technology risks across privacy andthird partyrisk, contributing to oversight of controls, assessments, and reporting.
  • Leverage AI-enabled tools and advanced analytics toidentifytrends, emerging risks, and control weaknesses.
  • Lead preparation for regulatory examinations, internal audits, and management assurance activities related to privacy and third-party risk oversight.
  • Maintainaccurate, complete documentation in GRC, privacy, and TPRM systems and ensure audit-ready artifacts.

Qualifications

Required:

  • Bachelor's degree in Risk Management, Information Systems, Finance, Business, Law, ora relatedfield.
  • 5+ years of experience insecond-line risk management, privacy risk, or third-party risk oversight, preferably within financial services or asset management(or other industry subject to equivalent regulatory scrutiny).
  • Demonstrated ability tooperateindependently with minimal guidance in a 2LoD environment.
  • In-depth knowledge of global privacy regulations andoutsourced TPRM operating models.
  • Required Certifications (at least one):
  • Certified Information Privacy Professional (CIPP/US, CIPP/E)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Third Party Risk Professional (CTPP)

Preferred:

  • Experience leading or independently managing 2LoD privacy or TPRM oversight activities.
  • Asset management or broader financial services experience.
  • Additionalcertifications:
  • CIPM or CIPT
  • ISO 27001 Lead Implementer or Auditor
  • Familiarity with SEC, FINRA, and global regulatory expectations.

Tools & Technology (Preferred)

  • Advanced experience with GRC, privacy, and TPRM platforms (e.g., Archer, ServiceNow, OneTrust,IBM OpenPages).
  • Strongproficiencywith reporting and analytics tools (e.g., Power BI, advanced Excel).
  • Practical experience using AI-enabled risk, compliance, or data analytics tools to enhance oversight and reporting(e.g., Microsoft Co-Pilot, ChatGPT Enterprise).
  • Ability to automate reporting and improve risk visibility.

Key Competencies

  • Strong independent judgment and risk-based decision-making.
  • Ability to provide credible, effectivechallengeat senior levels.
  • Excellent written and verbal communication skills.
  • Strong issue management, quality assurance, and governance discipline.
  • Comfortoperatingautonomously in a global, regulated environment.

FINRA Requirements

FINRA licenses are not required and will not be supported for this role.

Work Flexibility

This role is eligible for hybrid work, with up to one day per week from home.


What T. Rowe Price employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom