1

Vendor Risk Assessment Jobs in West Virginia (NOW HIRING)

Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture. * Supporting an internal ...

Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture. * Supporting an internal ...

... vendors, manage business continuity plans, and conduct the annual Risk and Control Self-Assessment (RCSA). The primary responsibilities for this role will be to provide risk coverage for the Chief ...

$85K - $117K/yr

Expert knowledge of operational audit disciplines including risk assessments, financial, compliance, and operational process audits; third-party risk/vendor audits; program management audits; and new ...

New

Treasury Manager

Weirton, WV · On-site

$110 - $170/hr

... processing vendor payments and adhoc manual requests, ensuring strict debt compliance, and ... Risk Assessment: Identify potential operational and financial risks across the organization and ...

Treasury Manager

Weirton, WV · On-site

$148K - $191K/yr

... processing vendor payments and adhoc manual requests, ensuring strict debt compliance, and ... Risk Assessment: Identify potential operational and financial risks across the organization and ...

Treasury Manager

Weirton, WV · On-site

$110 - $170/hr

... processing vendor payments and adhoc manual requests, ensuring strict debt compliance, and ... Risk Assessment: Identify potential operational and financial risks across the organization and ...

$96K - $132K/yr

The role includes identifying and qualifying new vendors, expanding incumbent supplier capacities ... Build fact-based business cases incorporating cost models, risk assessments, and value drivers.

Dev Ops Program Manager

Charleston, WV · On-site

$107K - $107K/yr

... and vendor transition. * Establish a governance and decision cadence by crafting an executive ... Proven skills in dependency management, risk assessment, and cutover controls. * Experience ...

Cyber Security Program Manager

Charleston, WV · On-site +1

$144K - $195K/yr

... vendors, internal teams, and Security leadership. * Guide the team in identifying and prioritizing improvements for NIST 800-53 control effectiveness and maturity. * Coordination of risk assessments ...

... risk assessments on applications to support modernization and technical debt reduction. * Collaborate with government technical leadership and vendor-heavy product teams to ensure that delivered ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities in West Virginia are hiring for Vendor Risk Assessment jobs?

Cities in West Virginia with the most Vendor Risk Assessment job openings:

GRC Analyst

Cast and Crew LLC

Charleston, WV • On-site

Full-time

Medical, Dental, Vision, PTO

Posted 8 days ago


Job description

About Us

At Cast & Crew, we've empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies - we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production's best ally every step of the way.#OneCastOneCrew

Position Overview:

The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.

Essential Functions

  • Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
  • Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
  • Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
  • Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
  • Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
  • Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
  • Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
  • Monitoring and reporting on internal control effectiveness and audit readiness posture.
  • Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
  • Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
  • Drafting and presenting risk reports and proposals to executive leadership and senior staff.
  • Performing other duties as directed.

Qualifications:

The following certifications are a plus, but are not expected at the time of hire:

  • CISA or CISM (compliance/audit-focused; strongly relevant to this role)
  • CRISC (risk and controls focus)
  • CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)

Requirements:

5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered. Candidates should have working knowledge of the following:

  • Compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
  • Development or maintenance of policies, procedures, and compliance documentation
  • Third-party or vendor risk processes (experience with formal TPRM programs a plus)
  • GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)

Communications:

  • Excellent oral communication skills and comfortable in group or small team settings
  • Excellent written communication skills
  • Ability to take highly technical material and present/communicate it to a non-technical audience

Relationship Building:

  • Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors

Planning, Organizing, Prioritizing, Delivering:

  • Exhibits mature organization and time management skills
  • Excellent problem-solving skills
  • Effectively planning and organizing daily work following priorities set by the Risk Manager
  • Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
  • Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product

Knowledge of:

  • SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
  • GRC and compliance automation tools, with preference for Drata
  • Security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
  • Evidence collection, reporting, and security documentation best practices

Skill In:

  • Coordinating SOC audit activities, evidence collection, and auditor communication
  • Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
  • Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
  • Writing clear, well-organized compliance documentation and communicating requirements across teams

Physical Demands:

SEDENTARY - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.

Benefits

Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.

Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.

CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at: https://www.castandcrew.com/privacy-policy/

Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $110,000.00 - $120,000.00 per year.