The Risk Mitigation programs include Risk and Control Self-Assessment ("RCSA"), Issue Management ("IM"), Vendor Risk Management ("VRM"), Business Continuity Management ("BCM"), and Internal Control ...
The Risk Mitigation programs include Risk and Control Self-Assessment ("RCSA"), Issue Management ("IM"), Vendor Risk Management ("VRM"), Business Continuity Management ("BCM"), and Internal Control ...
Senior Risk and Compliance Analyst
$96K - $148K/yr
Lead and enhancethe IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks. * Collaborate with ...
Senior Risk and Compliance Analyst
$96K - $148K/yr
Lead and enhancethe IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks. * Collaborate with ...
Third-Party Risk Management Specialist
Chicago, IL · On-site
$101K/yr
Experience conducting vendor risk assessments. * Experience with third party/vendor risk ... managementplatforms isa plus. Benefits and Perksof working for Cboe Global Markets We value the ...
Third-Party Risk Management Specialist
Chicago, IL · On-site
$101K/yr
Experience conducting vendor risk assessments. * Experience with third party/vendor risk ... managementplatforms isa plus. Benefits and Perksof working for Cboe Global Markets We value the ...
Senior Cybersecurity Risk Analyst - USA Remote
Chicago, IL · Remote
$130K - $160K/yr
Assess supply-chain and geopolitical risk (including country-of-origin and concentration concerns) and apply AI vendor risk frameworks (NIST AI RMF, ISO/IEC 42001) to AI-enabled products and services ...
Senior Cybersecurity Risk Analyst - USA Remote
Chicago, IL · Remote
$130K - $160K/yr
Assess supply-chain and geopolitical risk (including country-of-origin and concentration concerns) and apply AI vendor risk frameworks (NIST AI RMF, ISO/IEC 42001) to AI-enabled products and services ...
The Risk Mitigation programs include Risk and Control Self-Assessment ("RCSA"), Issue Management ("IM"), Vendor Risk Management ("VRM"), Business Continuity Management ("BCM"), and Internal Control ...
The Risk Mitigation programs include Risk and Control Self-Assessment ("RCSA"), Issue Management ("IM"), Vendor Risk Management ("VRM"), Business Continuity Management ("BCM"), and Internal Control ...
Senior Analyst, Compliance Testing & Third-Party Risk Management
Chicago, IL · Hybrid
$70K - $120K/yr
Conduct initial and ongoing risk assessments for vendors, focusing on areas like security practices, financial health, and compliance posture. * Support vendor onboarding by ensuring contracts and ...
Senior Analyst, Compliance Testing & Third-Party Risk Management
Chicago, IL · Hybrid
$70K - $120K/yr
Conduct initial and ongoing risk assessments for vendors, focusing on areas like security practices, financial health, and compliance posture. * Support vendor onboarding by ensuring contracts and ...
Senior Analyst, Compliance Testing & Third-Party Risk Management
Chicago, IL · On-site
$70K - $120K/yr
Conduct initial and ongoing risk assessments for vendors, focusing on areas like security practices, financial health, and compliance posture. * Support vendor onboarding by ensuring contracts and ...
Senior Analyst, Compliance Testing & Third-Party Risk Management
Chicago, IL · On-site
$70K - $120K/yr
Conduct initial and ongoing risk assessments for vendors, focusing on areas like security practices, financial health, and compliance posture. * Support vendor onboarding by ensuring contracts and ...
Security Manager
Chicago, IL · On-site
Assess AI vendors and features embedded in existing software (e.g., new AI features rolled into SaaS products) for security implications Third-Party & Vendor Risk * Conduct vendor security ...
Security Manager
Chicago, IL · On-site
Assess AI vendors and features embedded in existing software (e.g., new AI features rolled into SaaS products) for security implications Third-Party & Vendor Risk * Conduct vendor security ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Hands-on experience managing the TPRM or equivalent vendor risk lifecycle end-to-end - including due diligence, risk assessment, and stakeholder alignment. * Demonstrated familiarity with risk and ...
Senior Analyst, Compliance Testing & Third-Party Risk Management
Chicago, IL · Hybrid
$70K - $120K/yr
Conduct initial and ongoing risk assessments for vendors, focusing on areas like security practices, financial health, and compliance posture. * Support vendor onboarding by ensuring contracts and ...
Quick apply
Senior Analyst, Compliance Testing & Third-Party Risk Management
Chicago, IL · Hybrid
$70K - $120K/yr
Conduct initial and ongoing risk assessments for vendors, focusing on areas like security practices, financial health, and compliance posture. * Support vendor onboarding by ensuring contracts and ...
GRC Specialist II
Chicago, IL · On-site
$116K - $144K/yr
Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Exception & Risk Treatment: Oversee the ...
GRC Specialist II
Chicago, IL · On-site
$116K - $144K/yr
Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Exception & Risk Treatment: Oversee the ...
Security risk assessment experience:Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, CIS ... Conduct security risk assessments of applications, technologies, vendors, projects, and business ...
Quick apply
Security risk assessment experience:Working knowledge of NIST CSF, NIST SP 800-53, ISO 27001, CIS ... Conduct security risk assessments of applications, technologies, vendors, projects, and business ...
Conduct periodical GRC model surveys (especially performance monitoring processes) and vendor surveys, and work with Model Validation team to provide model risk assessment. * Participate in ...
Conduct periodical GRC model surveys (especially performance monitoring processes) and vendor surveys, and work with Model Validation team to provide model risk assessment. * Participate in ...
ServiceNow IRM Senior Developer
Chicago, IL · On-site
$55.75 - $76.50/hr
... o Vendor Risk Management o Operational Resilience (preferred) · Develop and maintain Business ... and automate risk assessments, compliance testing, audit workflows, issue management, and ...
ServiceNow IRM Senior Developer
Chicago, IL · On-site
$55.75 - $76.50/hr
... o Vendor Risk Management o Operational Resilience (preferred) · Develop and maintain Business ... and automate risk assessments, compliance testing, audit workflows, issue management, and ...
Conduct periodical GRC model surveys (especially performance monitoring processes) and vendor surveys, and work with Model Validation team to provide model risk assessment. * Participate in ...
Conduct periodical GRC model surveys (especially performance monitoring processes) and vendor surveys, and work with Model Validation team to provide model risk assessment. * Participate in ...
The reasons for vendor risk assessments and security validation * Activate stakeholders by demonstrating how these solutions reduce workload, increase accuracy, and protect student data.. Performance ...
Quick apply
The reasons for vendor risk assessments and security validation * Activate stakeholders by demonstrating how these solutions reduce workload, increase accuracy, and protect student data.. Performance ...
Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Exception & Risk Treatment: Oversee the ...
Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Exception & Risk Treatment: Oversee the ...
Experience with risk assessment tools (IRQs, DDQs) and vendor inventory tracking. Ability to identify/escalate risks, missed SLAs, and control gaps. Understanding of the Three Lines of Defense model.
Quick apply
Experience with risk assessment tools (IRQs, DDQs) and vendor inventory tracking. Ability to identify/escalate risks, missed SLAs, and control gaps. Understanding of the Three Lines of Defense model.
Lead and perform technology risk and control assessments across critical applications ... Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information ...
Lead and perform technology risk and control assessments across critical applications ... Vendor Risk Management, Technology Governance, Infrastructure and Platform Services, Information ...
Vendor Risk Assessment information
See Bolingbrook, IL salary details
$50.9K - $61.6K
4% of jobs
$61.6K - $72.2K
6% of jobs
$72.2K - $82.9K
11% of jobs
$86.9K is the 25th percentile. Wages below this are outliers.
$82.9K - $93.5K
11% of jobs
The median wage is $102K / yr.
$93.5K - $104.2K
23% of jobs
$104.2K - $114.8K
13% of jobs
$121.9K is the 75th percentile. Wages above this are outliers.
$114.8K - $125.5K
12% of jobs
$125.5K - $136.1K
8% of jobs
$136.1K - $146.8K
6% of jobs
$146.8K - $157.5K
4% of jobs
$157.5K - $168.1K
2% of jobs
$50.9K
$110.3K
$168.1K
How much do vendor risk assessment jobs pay per year?
What is a vendor risk assessment?
What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?
What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What cities near Bolingbrook, IL are hiring for Vendor Risk Assessment jobs?
Cities near Bolingbrook, IL with the most Vendor Risk Assessment job openings:

Vice President, Operational Risk Management
Chicago, IL • On-site
Full-time
Retirement, PTO
Re-posted 16 days ago
Job description
Hiring Manager:
Associate DirectorDepartment:
Operational Risk ManagementDepartment Overview
The Operational Risk Management ("ORM") Department is responsible for the Risk Mitigation Framework. The Risk Mitigation Framework provides the process, tools and approach that are needed to support and enhance the control environment required to minimize operational risks related to Golub Capital's non-investment functions. The Risk Mitigation Framework was created to minimize material losses, provide process and internal control oversight, and anticipate potential material loss events. The Risk Mitigation Framework is comprised of a set of consistent and repeatable elements that allow Golub Capital to identify, assess, mitigate, and report on the operational risk profile of the firm. The Risk Mitigation programs include Risk and Control Self-Assessment ("RCSA"), Issue Management ("IM"), Vendor Risk Management ("VRM"), Business Continuity Management ("BCM"), and Internal Control Testing ("ICT").
Position Responsibilities
The essential functions of this role include participating in the assessment of risks facing Golub Capital and supporting the development of a comprehensive plan to identify, measure, monitor and report risk components. We are seeking an individual to support the continued development of this function and help advance the program. This individual will serve as a subject matter expert for the Vendor Risk Management (VRM) and Business Continuity Management (BCM) programs and will be responsible for expanding the program's capabilities, increasing participation and driving process improvements.
This role requires strong project management skills to develop detailed plans, track progress, manage obstacles and deliver initiatives on time and within budget. This is an internal client-facing role requiring communication with users at all levels of the organization.
Responsibilities include but are not limited to:
- Overseeing the development and implementation of initiatives and tasks associated with the VRM and BCM programs
- Guiding the implementation of the VRM framework, providing strategic direction to the First and Second Line of Defense
- Managing the central vendor repository for the Firm and overseeing the automation of vendor on-boarding and off-boarding processes
- Ensuring effective vendor risk mitigation plans and providing stakeholders with visibility into current and emerging risks
- Leading VRM training initiatives to ensure effective application and awareness of the program across the Firm
- Staying informed of industry developments and regulatory requirements, ensuring compliance and proactive adaptation
- Liaising with third-party vendors, as required
- Creating and maintaining VRM and BCM-related reporting for senior management and oversight committees
- Proactively identifying, tracking and analyzing operational risks within Golub Capital and implementing critical control improvement
- Representing the ORM Team interests at internal meetings, committees and working groups
- Building and maintaining relationships with key ORM stakeholders, promoting a robust risk culture
- Delivering concise risk assessments and program insights to senior management to support informed decisionmaking
- Cultivating strong crossfunctional relationships to advance program understanding and enterprisewide adoption
Candidate Requirements
Qualifications & Experience:
- Bachelor's degree required
- 10+ years of experience in financial services risk management, management information systems or related role
- Experience and detailed knowledge of third-party risk management, financial services industry practices, internal controls and regulatory requirements
- Certifications (Preferred): Operational Risk Management Certificate, Certified Third Party Risk Management Professional (C3PRMP) or Project Management (PMP)
- Experience and knowledge with operational loss causes, measures and mitigation strategies
- Experience analyzing Excel reports with ability to leverage formulas preferred
- Experience with third-party risk management systems (Processuntiy, Aravo)
- Assertive, self-motivated, team oriented, flexible and able to multi-task
- Excellent analytical and problem-solving skills
- Exceptional written and verbal communication skills; capable of communicating effectively across all levels of the organization
- Attention to detail and strong organizational skills, including the ability to manage several projects at one time
- Highly resourceful and proven ability to work both independently and as a team member
- Ability to probe sensitive issues while maintaining high level of integrity and objectivity
- Demonstrated ability to effectively leverage AI tools in day-to-day work, with strong critical thinking to assess accuracy, limitations and appropriate use of AI generated outputs
- Enthusiastic about working in office and creating a Gold Standard hybrid work culture
Critical Competencies for Success
Our Gold Standards define key behaviors and competencies across 4 dimensions: Leadership, Achieving Results, Personal Effectiveness and Thinking Critically. These behaviors and competencies drive our ability to win together.
Leadership: Role models in this area consistently focus on the right goals and priorities and continually develop themselves and others. Always team players, they influence and engage with others to contribute to a supportive and inclusive culture where all feel welcome.
Achieving Results: Role models in this area are high achievers who develop careful plans and deliver consistently and effectively. They hold themselves and others accountable for delivering high quality results, and they remove barriers to ensure others can contribute and grow.
Personal Effectiveness: Role models in this area build strong relationships, treat others with respect and communicate effectively. They are driven to exceed expectations and are adaptable to changing circumstances.
Thinking Critically: Role models in this area understand our business, rely on analytical reasoning and seek diverse perspectives to solve problems. They are forward thinking, anticipating issues and addressing them in advance.
The department-specific competencies define the knowledge, skills and abilities that are needed to successfully perform the functional or technical work of this role.
Change Management: Communicates the benefits and the impact of refinements to internal processes or technology.
Innovative Mindset: Leverages an agile and creative mindset to drive innovative value creation, continuous process improvement and proactive learning through new technology, processes and people.
Risk Management: Identifies, forecasts and articulates ways to pursue and manage informed risks in ambiguous, complex or uncertain situations based on sound value propositions and an analysis of potential rewards and costs.
Technical Communication and Documentation: Documents and communicates technical processes and procedures in area of specialty to stakeholders. Adapts the level of detail and specificity based on the needs of the intended audience.
Industry Knowledge: Demonstrates an understanding of risk management and the Firm's position in the industry, including its complex structure and competitive advantage in the marketplace. Monitors industry trends and changes and recognizes their relevancy and implications.
Business Needs Assessment: Identifies business needs across departments within the Firm to understand the challenges, goals and problems that the business needs to solve and identifies appropriate technical solutions.
Project / Program Management: Manages projects and / or programs through planning, identifying resources, monitoring and communicating project activities and assessing impacts of project decisions.
Compensation and Benefits
For Illinois Only: It is expected that the base salary range for this position will be $115,000 to $180,000. Actual salaries may vary based on factors such as skills, experiences and qualifications for the role. The total compensation package for this position may also include other elements and discretionary awards in addition to a full range of medical, financial and / or other benefits (including 401(k) eligibility and various paid time off benefits such as vacation, sick time and parental leave) dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, the employee will be in an 'at-will position' and the Firm reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time including for reasons related to individual performance, Firm or individual department / team performance and market factors.Golub Capital is an Equal Opportunity Employer.
Due to the highly regulated nature of Golub Capital's business and because of the sensitivity of the information that all personnel have access to, Golub Capital performs extensive and thorough pre-hire screens to ensure that its personnel act with expected levels of integrity, professionalism and personal responsibility.
Please review Golub Capital's US Job Applicant privacy notice and, for California residents, the California Applicant privacy notice for information on how your personal data is collected, processed and stored.