Risk Assessment or Audit experience. * Knowledge of SOC 1 and SOC 2 type II reports, Third Party vendor risk management * Preferred: Certificates: CIA, CRISC, CISA, CISM. * Supply chain background ...
Risk Assessment or Audit experience. * Knowledge of SOC 1 and SOC 2 type II reports, Third Party vendor risk management * Preferred: Certificates: CIA, CRISC, CISA, CISM. * Supply chain background ...
You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities. You will partner with ...
You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities. You will partner with ...
You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities. You will partner with ...
You will conduct third-party risk assessments, track control gaps and remediation to closure, monitor high-risk vendors, and support broader cyber risk assessment activities. You will partner with ...
Conduct vendor risk assessments, including cybersecurity, operational, and compliance risks * Develop and maintain vendor risk inventory, tiering, and ongoing monitoring processes * Partner with ...
Conduct vendor risk assessments, including cybersecurity, operational, and compliance risks * Develop and maintain vendor risk inventory, tiering, and ongoing monitoring processes * Partner with ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Risk Manager
Mclean, VA · On-site
$55 - $60/hr
... assessment. * Recommend enhancements to the business/technology processes and controls to improve effectiveness of technology & vendor risk management capabilities * Perform risk tracking, trending ...
Quick apply
Risk Manager
Mclean, VA · On-site
$55 - $60/hr
... assessment. * Recommend enhancements to the business/technology processes and controls to improve effectiveness of technology & vendor risk management capabilities * Perform risk tracking, trending ...
Cyber Solutions Architect (Hybrid)
Arlington, VA · On-site
$90/hr
Serve as the senior technical advisor for collaboration platforms and cross-enterprise solutions that support vendor risk assessment and cyber supply chain mission outcomes. * Lead modernization and ...
Cyber Solutions Architect (Hybrid)
Arlington, VA · On-site
$90/hr
Serve as the senior technical advisor for collaboration platforms and cross-enterprise solutions that support vendor risk assessment and cyber supply chain mission outcomes. * Lead modernization and ...
Experience developing risk registers and formal risk-assessment reports. * Knowledge of systems handling sensitive financial, tax, payment, vendor, or personally identifiable information. * Ability ...
Quick apply
Experience developing risk registers and formal risk-assessment reports. * Knowledge of systems handling sensitive financial, tax, payment, vendor, or personally identifiable information. * Ability ...
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Supply Chain Risk Management (SCRM) Lead Falls Church, Virginia Full-time Important Notice: This ... This role coordinates vendor security assessments, establishes SCRM policies, and interfaces with ...
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Supply Chain Risk Management (SCRM) Lead Falls Church, Virginia Full-time Important Notice: This ... This role coordinates vendor security assessments, establishes SCRM policies, and interfaces with ...
Establish and maintain a new vendor, ongoing vendor, contract/agreement renewal changes and termination processes within the risk assessment program. Following regulatory guidance, develop and ...
Establish and maintain a new vendor, ongoing vendor, contract/agreement renewal changes and termination processes within the risk assessment program. Following regulatory guidance, develop and ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Quick apply
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
IT Risk Senior
Mclean, VA · On-site
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
IT Risk Senior
Mclean, VA · On-site
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Vendor Risk Assessment information
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?
What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?
What is a Vendor Risk Assessment?

Other
Posted 4 days ago
Job description
Supplier Risk Management (SRM) Assessor @ McLean , VA
6 Months contract – Hire/ CTH
McLean , VA – Hybrid Model
Must Have Qualifications:
- Risk Assessment or Audit experience.
- Knowledge of SOC 1 and SOC 2 type II reports, Third Party vendor risk management
- Preferred: Certificates: CIA, CRISC, CISA, CISM.
- Supply chain background, compliance risk management audit background, knowledge of Process Unity.
Job Description:
Overview:
- Looking for an eager go-getter who is proactive and can see things through to resolution.
- A person with transferable skills in analyzing risks and controls and coming up with results.
- Has a good sense of project management and will communicate escalations to management as needed.
- Direct risk management experience is preferred, but demonstrable transferable skills may be acceptable.
Supplier Risk Management (SRM) Assessor Job Description:
- Analyze and assess risks (including technology, privacy security, resiliency, and other operational risks) that the organization and suppliers (vendors) may face
- Evaluate and analyze supplier controls, identify, and document risk findings based on that evaluation
- Recommend action plans/remediation to decrease risk factors
- Gather confidential financial information from client such as income, assets, and debts
- Able to handle private, sensitive, confidential information appropriately
- Make risk-avoiding adjustments to current methods of operation to minimize their future risks
- Strong working knowledge of risk management and previous experience working with risk (i.e., risk assistant or risk analyst)
- Solid research skills using the internet and first-person interviews
- Comfortable working in a fast-paced environment, and able to adapt to changing priorities
- Thorough understanding of each Division and FRE’s goals and values
- Strong attention to detail and organization
- Excellent soft skills such as communication skills (written and spoken)
- Computer, data entry and MS Office skill
About eSolutionsFirst
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Reston, VA, US
Year founded
2007