Risk Assessment: Implement and execute vendor risk assessment frameworks to identify and mitigate operational, financial, cybersecurity, and data privacy risks. * Regulatory Adherence: Ensure all ...
Risk Assessment: Implement and execute vendor risk assessment frameworks to identify and mitigate operational, financial, cybersecurity, and data privacy risks. * Regulatory Adherence: Ensure all ...
Risk Assessment: Implement and execute vendor risk assessment frameworks to identify and mitigate operational, financial, cybersecurity, and data privacy risks. * Regulatory Adherence: Ensure all ...
Risk Assessment: Implement and execute vendor risk assessment frameworks to identify and mitigate operational, financial, cybersecurity, and data privacy risks. * Regulatory Adherence: Ensure all ...
Lead and support third-party risk management activities including vendor due diligence, risk assessments, contract reviews, and ongoing monitoring. * Partner with procurement, legal, and business ...
Lead and support third-party risk management activities including vendor due diligence, risk assessments, contract reviews, and ongoing monitoring. * Partner with procurement, legal, and business ...
Lead and support third-party risk management activities including vendor due diligence, risk assessments, contract reviews, and ongoing monitoring. * Partner with procurement, legal, and business ...
Lead and support third-party risk management activities including vendor due diligence, risk assessments, contract reviews, and ongoing monitoring. * Partner with procurement, legal, and business ...
Senior TPRM Security Lead
Austin, TX · On-site
Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements. * Partner with Procurement and ...
Senior TPRM Security Lead
Austin, TX · On-site
Conduct vendor risk assessments across security, privacy, compliance, financial, and operational domains, and clearly communicate findings and remediation requirements. * Partner with Procurement and ...
Sr GRC Analyst - w2
Texas City, TX · On-site
Perform vendor risk assessments against all security domains Perform technical implementation assessments from a security perspective related to vendor integrations (i.e. API integrations, SFTP ...
Quick apply
Sr GRC Analyst - w2
Texas City, TX · On-site
Perform vendor risk assessments against all security domains Perform technical implementation assessments from a security perspective related to vendor integrations (i.e. API integrations, SFTP ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Cybersecurity Governance & Risk Analyst
Austin, TX · On-site
$7.0K - $10K/mo
Oversees vendor risk management activities, including third-party assessments, contract security requirements, and ongoing monitoring. * Ensures risk-management practices are aligned with agency ...
Cybersecurity Governance & Risk Analyst
Austin, TX · On-site
$7.0K - $10K/mo
Oversees vendor risk management activities, including third-party assessments, contract security requirements, and ongoing monitoring. * Ensures risk-management practices are aligned with agency ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
GRC Risk Management Analyst
Austin, TX · On-site
... assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review * Administer risk-based vendor ...
New
GRC Risk Management Analyst
Austin, TX · On-site
... assessments, including due diligence, inherent-risk tiering, control evaluation, residual-risk determination, periodic reassessment, and offboarding review * Administer risk-based vendor ...
New
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
IT Security Risk Mgr
Fort Worth, TX · On-site
... vendor risk assessments and third-party reviews. Preferred : • Master's Degree in Information technology, Computer Science, Cybersecurity, Risk Management, or related field of study from accredited ...
IT Security Risk Mgr
Fort Worth, TX · On-site
... vendor risk assessments and third-party reviews. Preferred : • Master's Degree in Information technology, Computer Science, Cybersecurity, Risk Management, or related field of study from accredited ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Support vendor security assurance and third-party compliance assessments. Stakeholder Management Collaborate with Cybersecurity Architecture, IT, OT, Legal, Procurement, Risk, and business teams to ...
New
Support vendor security assurance and third-party compliance assessments. Stakeholder Management Collaborate with Cybersecurity Architecture, IT, OT, Legal, Procurement, Risk, and business teams to ...
New
Commercial Governance Manager
Houston, TX · On-site
Direct the work of the Vendor Compliance Risk Analyst to align commercial governance with vendor risk assessments, ensuring high-risk or high-criticality suppliers receive appropriate scrutiny * Set ...
Commercial Governance Manager
Houston, TX · On-site
Direct the work of the Vendor Compliance Risk Analyst to align commercial governance with vendor risk assessments, ensuring high-risk or high-criticality suppliers receive appropriate scrutiny * Set ...
Senior Privacy Specialist
Dallas, TX · Hybrid
Vendor Risk & Third-Party Oversight * Lead privacy-related components of vendor risk assessments, including review of data protection documentation. * Evaluate vendor practices and identify gaps ...
Senior Privacy Specialist
Dallas, TX · Hybrid
Vendor Risk & Third-Party Oversight * Lead privacy-related components of vendor risk assessments, including review of data protection documentation. * Evaluate vendor practices and identify gaps ...
Vendor Risk Assessment information
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?
What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?
What is a vendor risk assessment?

Full-time
Re-posted 13 days ago
Goldman Sachs rating
8.3
Based on 27 frontline employees who took The Breakroom Quiz
47th of 170 rated banks
Job description
TRANSACTION BANKING
Our mission is simple: provide a global transaction banking platform that is nimble, secure, and easy for clients use.
We have delivered a modern, digital-first transaction banking platform to serve GS' varied client base. Our business combines the strength, heritage, and expertise of a 150-year-old firm with the agility and entrepreneurial spirit of a tech start-up designed to solve some of the most complex operational needs in the industry. We aim to help our clients achieve Working Capital efficiency gains by optimizing their short term liquidity needs and simplifying their Cash Management operations.
We do so by delivering a best-in-class digital solution that helps clients manage their liquidity movements, foreign exchange and payments enabling international treasury operations and commerce.
We're a team of diverse Treasury and Payments specialists helping our clients solution and build for the future.
JOB SUMMARY AND RESPONSIBILITIES
Responsible for the strategic oversight and governance of the organization's key technology vendor relationships. This role manages the entire vendor engagement lifecycle-encompassing strategic sourcing, complex contract negotiation, financial optimization, risk mitigation, and performance evaluation. Operating at the intersection of Technology, Finance, and Legal, candidate ensures that external partnerships align with corporate standards, drive operational efficiency, and support the organization's technology roadmap.
Key Responsibilities
Contract & Lifecycle Management
- End-to-End Governance: Oversee the complete contract lifecycle for Information Technology vendors (including software, hardware, SaaS, Cloud, and professional services), from initial drafting and legal review to execution and renewal.
- Compliance & Alignment: Ensure all vendor agreements comply with corporate policies, legal standards, and regulatory requirements.
- Repository Management: Maintain a centralized, auditable repository of all contracts, amendments, and nondisclosure agreements to ensure organizational transparency.
Negotiation & Relationship Management
- Commercial Negotiations: Lead complex, high-value negotiations to secure competitive pricing, favorable commercial terms, and robust Service Level Agreements (SLAs).
- Executive Liaison: Serve as the primary point of contact for key technology partners, fostering collaborative, long-term relationships.
- Business Reviews: Conduct structured, periodic business reviews with strategic vendors to evaluate performance, discuss product roadmaps, and resolve escalated issues.
Technology & Portfolio Alignment
- Strategic Evaluation: Partner with IT leadership and business units to evaluate vendor capabilities, ensuring technology offerings align with the organization's infrastructure and security standards.
- Market Intelligence: Monitor industry trends, emerging technologies, and shifting licensing models to identify opportunities for portfolio optimization and cost efficiencies.
Risk Management & Compliance
- Risk Assessment: Implement and execute vendor risk assessment frameworks to identify and mitigate operational, financial, cybersecurity, and data privacy risks.
- Regulatory Adherence: Ensure all third-party partners adhere to corporate information security policies and industry-specific regulatory standards.
- Contingency Planning: Develop and maintain robust business continuity plans and exit strategies for critical, tier-1 vendor dependencies.
Performance Monitoring & Reporting
- Performance Metrics: Establish, track, and report on Key Performance Indicators (KPIs) and SLAs to ensure vendor accountability.
- Executive Reporting: Analyze vendor performance and spend data to deliver actionable insights, risk postures, and strategic recommendations to senior management.
Qualifications
- Education: Bachelor's degree in Business Administration, Supply Chain Management, Information Technology, Finance, or a related field.
- Experience: 8+ years of progressive experience in IT vendor management, technology procurement, contract management, or strategic sourcing (adjusted slightly from 10 years to capture highly qualified senior talent, though adaptable based on organizational requirements).
- Negotiation Expertise: Proven track record of leading complex, multi-million dollar negotiations with major technology publishers and service providers.
- Technical Acumen: Strong understanding of IT infrastructure, software licensing models, cloud services (SaaS/PaaS/IaaS), and IT service delivery frameworks.
- Legal & Risk Knowledge: Solid proficiency in contract law principles, third-party risk management (TPRM) frameworks, and data privacy regulations.
- Communication: Exceptional written and verbal communication skills, with a demonstrated ability to influence stakeholders and build consensus across cross-functional teams (Legal, Finance, Security, and IT).
ABOUT GOLDMAN SACHS
At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world.
We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs. Learn more about our culture, benefits, and people at GS.com/careers .
We're committed to finding reasonable accommodations for candidates with special needs or disabilities during our recruiting process. Learn more: https:// www.goldmansachs.com/careers/footer/disability-statement.html
© The Goldman Sachs Group, Inc., 2025. All rights reserved.
Goldman Sachs is an equal opportunity employer and does not discriminate on the basis of race, color, religion, sex, national origin, age, veterans status, disability, or any other characteristic protected by applicable law.
What Goldman Sachs employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Goldman Sachs
Sourced by ZipRecruiter
At Goldman Sachs, we commit our people, capital and ideas to help our clients, shareholders and the communities we serve to grow. Founded in 1869, we are a leading global investment banking, securities and investment management firm. Headquartered in New York, we maintain offices around the world. We believe who you are makes you better at what you do. We're committed to fostering and advancing diversity and inclusion in our own workplace and beyond by ensuring every individual within our firm has a number of opportunities to grow professionally and personally, from our training and development opportunities and firmwide networks to benefits, wellness and personal finance offerings and mindfulness programs.
Industry
Finance and insurance
Company size
10,000+ Employees
Headquarters location
New York, NY, US
Year founded
1869