1

Vendor Risk Assessment Jobs in Virginia (NOW HIRING)

... vendors through structured cybersecurity risk assessments to determine cyber clearance eligibility before contract execution or system access. • Serve as the primary SME and platform administrator ...

Risk Manager

Mclean, VA · On-site

$55 - $60/hr

... assessment. * Recommend enhancements to the business/technology processes and controls to improve effectiveness of technology & vendor risk management capabilities * Perform risk tracking, trending ...

Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)

Lead ISO/IEC 27001 implementations (ISMS design, risk assessment, controls, internal audits ... vendor risk, cloud controls, incident response, logging/monitoring, data governance, AI governance)

In this role, the specialist integrates automated supply chain risk tooling, Software Bill of Materials governance, vendor security assessment programs, and threat intelligence monitoring to reduce ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a Vendor Risk Assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
What are popular job titles related to Vendor Risk Assessment jobs in Virginia? For Vendor Risk Assessment jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Assessment jobs in Virginia look for? The top searched job categories for Vendor Risk Assessment jobs in Virginia are:
What cities in Virginia are hiring for Vendor Risk Assessment jobs? Cities in Virginia with the most Vendor Risk Assessment job openings:
Third Party Risk Management Analyst

Third Party Risk Management Analyst

Burke & Herbert Bank & Trust

Alexandria, VA • On-site

Full-time

Posted 24 days ago


Burke & Herbert Bank rating

5.6

Company rating: 5.6 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

136th of 144 rated banks


Job description

CLASSIFICATION: Non-exempt

REPORTS TO: Program Manager, Third Party Risk Management

JOB DESCRIPTION

Summary/Objective


Under the direction of the Program Manager, Third Party Risk Management, the Third‑Party Vendor Risk Analyst supports the execution of the Bank’s Third‑Party Risk Management (TPRM) Program by performing day‑to‑day operational, analytical, and facilitation activities. In partnership with the Program Manager, the Analyst helps strengthen and sustain effective vendor review cadence by coordinating stakeholder inputs, producing complete and traceable documentation, and preparing exam‑ready artifacts. This role ensures vendor risk activities—including due diligence, ongoing monitoring, documentation, and issue tracking—are executed in a timely, consistent, and examination‑defensible manner.


Essential Functions
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.


  • Execute day‑to‑day third‑party risk management activities for new and existing vendors in accordance with the Bank’s TPRM Program, with heightened focus on critical and GLBA‑High risk relationships. Support initial due diligence and ongoing risk assessments by collecting, validating, and documenting required artifacts and supporting materials for higher‑risk vendors to facilitate effective review, challenge, and approval by the Program Manager.


  • Maintain and manage the rolling vendor review schedule established by the Program Manager, ensuring critical and high‑risk third‑party relationships are prioritized and reviewed in accordance with established cadence and monitoring requirements. Coordinate with internal stakeholders, including Information Security, IT, Compliance, Finance, and Accounting, to obtain required risk assessment inputs and documentation necessary to support vendor reviews, providing enhanced facilitation for critical and GLBA‑High risk vendors.


  • Track vendors review progress, outstanding action items, and remediation activities, maintaining visibility into reviews, documentation gaps, and issue resolution. Proactively escalate aging, overdue, or at‑risk items to the Program Manager to support timely awareness, decision‑making, and risk mitigation.


  • Prepare, maintain, and organize comprehensive vendor review documentation, including executive summaries, evidence inventories, and issue tracking materials, with enhanced rigor applied to files associated with critical and GLBA‑High risk vendors. Ensure that vendor risk conclusions and assigned risk ratings are clearly, consistently, and defensibly supported by documented evidence prior to Program Manager review and sign‑off.


  • Assist in documenting risk acceptance decisions and remediation status under the direction of the Program Manager, ensuring alignment with TPRM program standards, internal governance expectations, and applicable regulatory requirements.


  • Identify procedural gaps, workflow inefficiencies, and documentation issues encountered during third‑party risk management execution, particularly those impacting oversight of critical and GLBA‑High risk vendors. Escalate observations and improvement opportunities to the Program Manager for program‑level evaluation and continuous improvement.


  • Support ad hoc projects, process enhancements, and targeted initiatives led by the Program Manager to strengthen third‑party risk governance, operational effectiveness, and overall program maturity.


Other Duties

  • Contract and Procurement Support

Support the Program Manager by tracking vendor‑related review milestones (including onboarding, renewals, and amendments). Ensure required vendor review documentation is complete, accurate, and available to support informed contractual decisions prior to execution.


  • Governance, Metrics, and Reporting Support

Compile and maintain program metrics, status reports, and supporting materials used to measure and monitor Third‑Party Risk Management (TPRM) program performance. Assist, as directed by the Program Manager, in preparing materials for internal governance forums, audits, and regulatory examinations.


  • Audit and Examination Readiness

Support internal and external audits and regulatory examinations by organizing vendor files, maintaining evidence mappings, and assembling response documentation under Program Manager guidance. Maintain vendor records in an exam‑ready state to support Program Manager interactions with auditors, regulators, and risk committees.

Skills/Abilities

  • Working knowledge of third-party risk management practices and regulatory expectations within a regulated financial services environment.
  • Strong analytical skills with the ability to assess risk data, identify trends, and support informed decision-making.
  • Excellent organizational and documentation skills with high attention to detail.
  • Ability to collaborate effectively with cross‑functional stakeholders while operating under Program Manager direction.
  • Strong written and verbal communication skills to support clear documentation, issue analysis, and timely escalation.
  • Proficiency with Microsoft Office (Excel, Word, PowerPoint) and risk management or workflow tracking tools.

Supervisory Responsibility

This position does not have supervisory responsibilities.


Work Environment

This job operates in an office setting, the opportunity to telework is not available. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. Office environment with job duties conducted via telephone, face to face meetings, and on the computer.


Physical Demands

This position requires manual dexterity, the ability to lift files and open cabinets. This position requires bending, stooping, or standing, as necessary.


Travel

Limited local travel may be required for this position.


For Applicants located in Northern Viriginia (VA): The anticipated salary range for this position is $25.00-$30.00 per hour.

For Applicants from all other locations: The salary will be based on experience, qualifications, and geographic location.

The ranges listed above for Viriginia represent the good-faith compensation the Company reasonably expects to pay for the position at the time of posting. Actual compensation will be determined based on factors including, but not limited to, the candidate's skills, qualifications, experience, education, certifications, internal equity, and business needs. This position may also be eligible for additional compensation, such as bonuses or incentive pay, where applicable.

Education and Experience

Education

  • Requires a bachelor’s degree in business, Finance, Risk Management, Information Systems, Compliance, or a related field or equivalent professional experience supporting risk management functions in a regulated environment.

Experience

  • Requires a minimum of 1 year of experience supporting third‑party vendor management, operational risk, compliance, information security, or a related risk discipline within a regulated industry.
  • Requires hands‑on experience supporting vendor due diligence, ongoing monitoring, documentation, and issue tracking activities.
  • Experience coordinating with cross‑functional stakeholders (e.g., Information Security, IT, Compliance, Finance) to collect and organize risk assessment inputs.
  • Experience producing or maintaining clear, well‑organized, and evidence‑based documentation to support management review, audit, or regulatory examination.



Equal Employment Opportunity/M/F/disability/protected veteran status.



Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.


What Burke & Herbert Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom