1

Vendor Risk Assessment Jobs in Virginia (NOW HIRING)

Risk Manager

Mclean, VA · On-site

$55 - $60/hr

... assessment. * Recommend enhancements to the business/technology processes and controls to improve effectiveness of technology & vendor risk management capabilities * Perform risk tracking, trending ...

Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...

Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a Vendor Risk Assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
What job categories do people searching Vendor Risk Assessment jobs in Virginia look for? The top searched job categories for Vendor Risk Assessment jobs in Virginia are:
What cities in Virginia are hiring for Vendor Risk Assessment jobs? Cities in Virginia with the most Vendor Risk Assessment job openings:
Infographic showing various Vendor Risk Assessment job openings in Virginia as of July 2026, with employment types broken down into 2% As Needed, 79% Full Time, 16% Part Time, and 3% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution.
Supplier Risk Management (SRM) Assessor

Supplier Risk Management (SRM) Assessor

eSolutionsFirst, LLC

Mclean, VA • On-site

Other

Posted 4 days ago


Job description

Supplier Risk Management (SRM) Assessor @ McLean , VA

6 Months contract –     Hire/ CTH    

McLean , VA –  Hybrid Model   

 Must Have Qualifications:

  • Risk Assessment or Audit experience.
  • Knowledge of SOC 1 and SOC 2 type II reports, Third Party vendor risk management
  • Preferred: Certificates: CIA, CRISC, CISA, CISM.
  • Supply chain background, compliance risk management audit background, knowledge of Process Unity.  

Job Description:

Overview:

  • Looking for an eager go-getter who is proactive and can see things through to resolution.
  • A person with transferable skills in analyzing risks and controls and coming up with results.
  • Has a good sense of project management and will communicate escalations to management as needed.
  • Direct risk management experience is preferred, but demonstrable transferable skills may be acceptable.

Supplier Risk Management (SRM) Assessor Job Description:

  • Analyze and assess risks (including technology, privacy security, resiliency, and other operational risks) that the organization and suppliers (vendors) may face
  • Evaluate and analyze supplier controls, identify, and document risk findings based on that evaluation
  • Recommend action plans/remediation to decrease risk factors
  • Gather confidential financial information from client such as income, assets, and debts
  • Able to handle private, sensitive, confidential information appropriately
  • Make risk-avoiding adjustments to current methods of operation to minimize their future risks
  • Strong working knowledge of risk management and previous experience working with risk (i.e., risk assistant or risk analyst)
  • Solid research skills using the internet and first-person interviews
  • Comfortable working in a fast-paced environment, and able to adapt to changing priorities
  • Thorough understanding of each Division and FRE’s goals and values
  • Strong attention to detail and organization
  • Excellent soft skills such as communication skills (written and spoken)
  • Computer, data entry and MS Office skill