Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational ...
Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational ...
Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational ...
Conduct enterprise-level vendor risk assessments and technical security reviews for software suppliers, cloud providers (SaaS/PaaS/IaaS), AI tools, telecommunications, and OT/ICS (Operational ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Risk Manager
Mclean, VA · On-site
$55 - $60/hr
... assessment. * Recommend enhancements to the business/technology processes and controls to improve effectiveness of technology & vendor risk management capabilities * Perform risk tracking, trending ...
Quick apply
Risk Manager
Mclean, VA · On-site
$55 - $60/hr
... assessment. * Recommend enhancements to the business/technology processes and controls to improve effectiveness of technology & vendor risk management capabilities * Perform risk tracking, trending ...
... and vendors. The successful candidate will assess supplier controls across technology ... This role requires strong analytical capabilities, risk assessment expertise, stakeholder ...
... and vendors. The successful candidate will assess supplier controls across technology ... This role requires strong analytical capabilities, risk assessment expertise, stakeholder ...
Experience developing risk registers and formal risk-assessment reports. * Knowledge of systems handling sensitive financial, tax, payment, vendor, or personally identifiable information. * Ability ...
Quick apply
Experience developing risk registers and formal risk-assessment reports. * Knowledge of systems handling sensitive financial, tax, payment, vendor, or personally identifiable information. * Ability ...
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Supply Chain Risk Management (SCRM) Lead Falls Church, Virginia Full-time Important Notice: This ... This role coordinates vendor security assessments, establishes SCRM policies, and interfaces with ...
Quick apply
Supply Chain Risk Management (SCRM) Lead
Falls Church, VA · On-site
$180K - $210K/yr
Supply Chain Risk Management (SCRM) Lead Falls Church, Virginia Full-time Important Notice: This ... This role coordinates vendor security assessments, establishes SCRM policies, and interfaces with ...
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Participate in operational control testing activities to assess control execution effectiveness * Support third-party vendor risk governance activities, including vendor SOC reviews and Enhanced ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Senior Consultant - IT Governance, Risk & Compliance (GRC)
Ashburn, VA · On-site
$90K - $139K/yr
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Assessment Analyst
Leesburg, VA · On-site +1
$87K - $95K/yr
... risk. Together, we deliver independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions. Our ...
Assessment Analyst
Leesburg, VA · On-site +1
$87K - $95K/yr
... risk. Together, we deliver independent, third-party, vendor-agnostic regulatory assessment and advisory services, alongside advanced cybersecurity offensive and compliance technical solutions. Our ...
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Quick apply
Develop and maintain risk registers, risk heat maps, and third-party/vendor risk assessment programs * Support the integration of GRC tooling (e.g., ServiceNow GRC, Archer, OneTrust, Vanta) to ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Risk Senior Manager
Tysons Corner, VA · On-site
Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)
Risk Senior Manager
Tysons Corner, VA · On-site
Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)
Lead risk assessments for critical and operationally significant third parties (partners, vendors), identifying, tracking, and due diligence, ongoing monitoring, issue management, and exit. * Broader ...
Lead risk assessments for critical and operationally significant third parties (partners, vendors), identifying, tracking, and due diligence, ongoing monitoring, issue management, and exit. * Broader ...
Risk Analyst
Richmond, VA · On-site +1
$87K - $110K/yr
Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements * Review SOC ...
Risk Analyst
Richmond, VA · On-site +1
$87K - $110K/yr
Perform third-party security and compliance risk assessments for new and existing vendors, evaluating risk exposure, control effectiveness, business impact, and remediation requirements * Review SOC ...
Vendor Risk Assessment information
What is a vendor risk assessment?
What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?
What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What cities in Virginia are hiring for Vendor Risk Assessment jobs?
Cities in Virginia with the most Vendor Risk Assessment job openings:

Contractor
Medical, Retirement, PTO
Re-posted yesterday
Leidos rating
8.3
Based on 152 frontline employees who took The Breakroom Quiz
80th of 499 rated business services
Job description
* Conduct technical and non-technical risk scoring to compile comprehensive Vendor Risk Reports that map systemic vulnerabilities.
* Provide specialized SCRM subject matter expertise throughout the procurement lifecycle, including early-stage acquisition planning and source selections.
* Author Acquisition Security Reviews and evaluation matrices that integrate directly into the FAA Acquisition Management System (AMS) pipeline.
* Draft specific contract security language, technical security requirements, and risk acceptance recommendations to mitigate identified supply chain risks prior to contract award.
* Translate highly technical and complex risk assessment data into clear, Executive Decision Packages for a non-technical audience to enable FAA senior leadership to make rapid, fully informed decisions.
* Contribute to the development and maintenance of FAA SCRM policies, governance documentation, and standard operating procedures (SOPs).
* Formulate performance metrics and program reports for executive leadership.
* Maintain critical operational and collaborative relationships with external stakeholders, including the FAA Chief Information Officer (CIO), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), Department of Homeland Security (DHS), and the broader Intelligence Community (IC).
* Coordinate and facilitate SCRM training and awareness campaigns for acquisition personnel and program offices. Basic Qualifications: Citizenship: U.S. Citizenship required Clearance: Active Top Secret/SCI clearance is required Education: Bachelor’s degree in Supply Chain Risk Management, Intelligence Studies, National Security, Logistics, Data Science, Cybersecurity, Information Technology, Computer Science/Engineering, or a related discipline. (Equivalent professional experience or specialized training may be substituted). Experience: 8+ years of professional experience as an Intelligence Analyst (All-Source, Cyber, Counterintelligence, or OSINT) or professional experience in third-party risk management (TPRM), Cyber Supply Chain Risk Management (C-SCRM), technical risk assessments, cybersecurity risk management, or infrastructure defense. Framework Knowledge: Strong working knowledge of federal cybersecurity and risk management frameworks, specifically NIST SP 800-161 (Cybersecurity Supply Chain Risk Management Practices) and NIST SP 800-53. Technical Skills: Hands-on experience evaluating the security posture, software supply chains, and configurations of at least three of the following technology profiles: * Cloud infrastructure and service providers (SaaS, PaaS, IaaS)
* Commercial software packages and open-source dependencies
* Artificial Intelligence (AI) platforms or Machine Learning tools
* Telecommunications hardware or infrastructure frameworks
* Operational Technology (OT) or Industrial Control Systems (ICS)
* Communication Skills: Proven capability to translate complex technical vulnerabilities, software flaws, and architectural risks into clear, well-structured, non-technical written reports and executive summaries. Preferred Qualifications: * Completion of formal military or federal intelligence training courses focusing on threat network analysis or open-source collection.
* Possession of one or more of the following industry-recognized certifications:
* Certified Information Systems Security Professional (CISSP)
* Certified in Risk and Information Systems Control (CRISC)
* Certified Information Systems Auditor (CISA)
* Specialized federal SCRM or Counterintelligence training certifications (e.g., CDSE, ODNI, or defense-sponsored SCRM courses).
* Proficiency with advanced OSINT search techniques, corporate filing retrieval systems, or international trade/shipping databases.
* Demonstrated experience reviewing federal procurement mechanisms, source selection processes, or drafting contract security language. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: July 31, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $92,300.00 - $166,850.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. About Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com . Pay and Benefits Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits . Securing Your Data Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at . If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission . Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws. #Remote
About Leidos
Sourced by ZipRecruiter
At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers' success. We empower our teams, contribute to our communities, and operate sustainable practices. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community.
Industry
It services
Company size
10,000+ Employees
Headquarters location
Reston, VA, US