1

Vendor Risk Assessment Jobs in Texas (NOW HIRING)

Oversee Third-Party Risk Management (TPRM), including vendor risk assessments and ongoing monitoring. * Support governance activities related to security questionnaires, customer due diligence ...

... party/vendor risk oversight. * Conduct compliance testing, monitoring activities, and risk assessments to evaluate adherence to applicable laws, regulations, and internal policies. * Identify ...

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

The role owns the full lifecycle of security questionnaires, DDQs, and vendor risk assessments, managing approximately 500 engagements annually across Emburse's portfolio of 14 products. Emburse is ...

Own the Third-Party Risk Management program end to end, including vendor risk tiering, assessment methodology, due diligence standards, contractual security requirements, ongoing monitoring, and ...

New

Own the Third-Party Risk Management program end to end, including vendor risk tiering, assessment methodology, due diligence standards, contractual security requirements, ongoing monitoring, and ...

New

Deliver regular security updates, risk assessments, and actionable insights to executive leadership ... Manage third-party/vendor risk and ensure strong external security practices Expertise & Leadership ...

Showing results 41-60

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What cities in Texas are hiring for Vendor Risk Assessment jobs?

Cities in Texas with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Texas as of August 2026, with employment types broken down into 75% Full Time, and 25% Contract. Highlights an 100% In-person job distribution.

Other

Posted 14 days ago


Job description

Role: Director, Governance, Risk & Compliance (GRC)

Location: Addison, TX (Hybrid – 2–4 days onsite, 4 days preferred*)
Employment Type: Full-Time

Position Summary

We are seeking an experienced Director of Governance, Risk & Compliance (GRC) to lead and mature our enterprise governance, risk management, and compliance program. This strategic leadership role will be responsible for overseeing regulatory compliance initiatives, audit programs, third-party risk management, and enterprise security governance while partnering closely with executive leadership across the organization.

The ideal candidate is an accomplished GRC leader who has successfully owned enterprise compliance programs, led complex audits, and possesses the executive presence to effectively communicate risk, compliance, and control objectives to both technical and business stakeholders.


Key Responsibilities
  • Lead the organization''s Governance, Risk & Compliance (GRC) program and drive continuous program maturity.
  • Own and manage the enterprise SOX compliance program, including planning, execution, remediation, and audit coordination.
  • Lead SOC 2 Type II compliance efforts and serve as the primary point of contact for external auditors.
  • Develop, maintain, and enhance IT control frameworks and governance processes.
  • Partner with business and technology leaders to identify, assess, and mitigate enterprise risk.
  • Provide executive-level reporting on compliance initiatives, audit readiness, and organizational risk posture.
  • Oversee Third-Party Risk Management (TPRM), including vendor risk assessments and ongoing monitoring.
  • Support governance activities related to security questionnaires, customer due diligence requests, and regulatory inquiries.
  • Develop policies, standards, and procedures that align with industry best practices and regulatory requirements.
  • Lead and mentor a high-performing GRC team while fostering collaboration across Information Security, IT, Internal Audit, Legal, Privacy, and business units.
  • Drive continuous improvement initiatives to enhance operational efficiency and compliance effectiveness.

Required Qualifications
  • Bachelor''s degree in Information Systems, Cybersecurity, Computer Science, Business, or a related discipline (Master''s degree preferred).
  • 10+ years of progressive experience in Governance, Risk & Compliance, Information Security, IT Audit, or related disciplines.
  • 5+ years of leadership experience managing GRC or Information Security teams.
  • Demonstrated experience owning and leading enterprise SOX compliance programs.
  • Experience leading SOC 2 Type II audits from planning through successful completion.
  • Strong knowledge of IT General Controls (ITGCs), internal controls, risk management, and compliance methodologies.
  • Experience developing and implementing enterprise governance programs.
  • Excellent communication and presentation skills with the ability to engage executive leadership and translate complex technical concepts into business-friendly language.
  • Proven ability to influence cross-functional stakeholders and drive organizational change.

Preferred Qualifications
  • Experience within a healthcare or highly regulated industry.
  • Familiarity with healthcare regulatory requirements, including HIPAA.
  • Experience leading Third-Party Risk Management (TPRM) programs.
  • Working knowledge of vendor risk management and enterprise governance practices.
  • Experience supporting regulatory, customer, and compliance questionnaires.
  • Professional certifications such as CISSP, CISA, CRISC, CGEIT, CISM, or similar are highly preferred.

Technical Knowledge

Experience with one or more of the following is preferred:

  • NIST Cybersecurity Framework (CSF)
  • SOX Compliance
  • SOC 2 Type II
  • HIPAA
  • Enterprise Risk Management (ERM)
  • Third-Party Risk Management (TPRM)
  • IT General Controls (ITGCs)
  • Governance, Risk & Compliance (GRC) platforms

Leadership Profile

The successful candidate will be:

  • A strategic and collaborative leader who can build relationships across the organization.
  • An exceptional communicator with strong executive presence.
  • Comfortable presenting to senior leadership and executive stakeholders.
  • Highly organized with the ability to manage multiple enterprise initiatives simultaneously.
  • A proactive problem solver who can balance business objectives with risk management and compliance requirements.
  • Passionate about building scalable governance programs that support organizational growth.

Why Join Us?

This is an opportunity to shape and lead an enterprise GRC function within a growing organization where governance, security, and compliance are strategic priorities. You''ll partner with executive leadership, influence enterprise-wide initiatives, and help strengthen the organization''s overall risk and compliance posture while leading a talented and collaborative team.


About INSPYR Solutions
Technology is our focus and quality is our commitment. As a national expert in delivering flexible technology and talent solutions, we strategically align industry and technical expertise with our clients'' business objectives and cultural needs. Our solutions are tailored to each client and include a wide variety of professional services, project, and talent solutions. By always striving for excellence and focusing on the human aspect of our business, we work seamlessly with our talent and clients to match the right solutions to the right opportunities. Learn more about us at inspyrsolutions.com.
INSPYR Solutions provides Equal Employment Opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, INSPYR Solutions complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities.