1

Vendor Risk Assessment Jobs in Chicago, IL (NOW HIRING)

Senior Cybersecurity Risk Analyst - USA Remote

Chicago, IL · Remote

$130K - $160K/yr

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

Assess supply-chain and geopolitical risk (including country-of-origin and concentration concerns) and apply AI vendor risk frameworks (NIST AI RMF, ISO/IEC 42001) to AI-enabled products and services ...

GRC Specialist II

Chicago, IL · On-site

$116K - $144K/yr

Vendor Risk Management: Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Exception & Risk Treatment: Oversee the ...

next page

Showing results 1-20

Vendor Risk Assessment information

See Chicago, IL salary details

$53.1K

$114.9K

$175.1K

How much do vendor risk assessment jobs pay per year?

As of Aug 14, 2026, the average yearly pay for vendor risk assessment in Chicago, IL is $114,919.00, according to ZipRecruiter salary data. Most workers in this role earn between $92,700.00 and $132,900.00 per year, depending on experience, location, and employer.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What cities near Chicago, IL are hiring for Vendor Risk Assessment jobs?

Cities near Chicago, IL with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Chicago, IL as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 9% Part Time, and 3% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution, with an average salary of $114,919 per year, or $55.2 per hour.

Vice President, Operational Risk Management

Golubcapital

Chicago, IL • On-site

Full-time

Retirement, PTO

Re-posted 6 days ago


Job description

Position Information

Hiring Manager:

Associate Director

Department:

Operational Risk Management

Department Overview

The Operational Risk Management ("ORM") Department is responsible for the Risk Mitigation Framework. The Risk Mitigation Framework provides the process, tools and approach that are needed to support and enhance the control environment required to minimize operational risks related to Golub Capital's non-investment functions. The Risk Mitigation Framework was created to minimize material losses, provide process and internal control oversight, and anticipate potential material loss events. The Risk Mitigation Framework is comprised of a set of consistent and repeatable elements that allow Golub Capital to identify, assess, mitigate, and report on the operational risk profile of the firm. The Risk Mitigation programs include Risk and Control Self-Assessment ("RCSA"), Issue Management ("IM"), Vendor Risk Management ("VRM"), Business Continuity Management ("BCM"), and Internal Control Testing ("ICT").

Position Responsibilities

The essential functions of this role include participating in the assessment of risks facing Golub Capital and supporting the development of a comprehensive plan to identify, measure, monitor and report risk components. We are seeking an individual to support the continued development of this function and help advance the program. This individual will serve as a subject matter expert for the Vendor Risk Management (VRM) and Business Continuity Management (BCM) programs and will be responsible for expanding the program's capabilities, increasing participation and driving process improvements.

This role requires strong project management skills to develop detailed plans, track progress, manage obstacles and deliver initiatives on time and within budget. This is an internal client-facing role requiring communication with users at all levels of the organization.

Responsibilities include but are not limited to:

  • Overseeing the development and implementation of initiatives and tasks associated with the VRM and BCM programs
  • Guiding the implementation of the VRM framework, providing strategic direction to the First and Second Line of Defense
  • Managing the central vendor repository for the Firm and overseeing the automation of vendor on-boarding and off-boarding processes
  • Ensuring effective vendor risk mitigation plans and providing stakeholders with visibility into current and emerging risks
  • Leading VRM training initiatives to ensure effective application and awareness of the program across the Firm
  • Staying informed of industry developments and regulatory requirements, ensuring compliance and proactive adaptation
  • Liaising with third-party vendors, as required
  • Creating and maintaining VRM and BCM-related reporting for senior management and oversight committees
  • Proactively identifying, tracking and analyzing operational risks within Golub Capital and implementing critical control improvement
  • Representing the ORM Team interests at internal meetings, committees and working groups
  • Building and maintaining relationships with key ORM stakeholders, promoting a robust risk culture
  • Delivering concise risk assessments and program insights to senior management to support informed decisionmaking
  • Cultivating strong crossfunctional relationships to advance program understanding and enterprisewide adoption

Candidate Requirements

Qualifications & Experience:

  • Bachelor's degree required
  • 10+ years of experience in financial services risk management, management information systems or related role
  • Experience and detailed knowledge of third-party risk management, financial services industry practices, internal controls and regulatory requirements
  • Certifications (Preferred): Operational Risk Management Certificate, Certified Third Party Risk Management Professional (C3PRMP) or Project Management (PMP)
  • Experience and knowledge with operational loss causes, measures and mitigation strategies
  • Experience analyzing Excel reports with ability to leverage formulas preferred
  • Experience with third-party risk management systems (Processuntiy, Aravo)
  • Assertive, self-motivated, team oriented, flexible and able to multi-task
  • Excellent analytical and problem-solving skills
  • Exceptional written and verbal communication skills; capable of communicating effectively across all levels of the organization
  • Attention to detail and strong organizational skills, including the ability to manage several projects at one time
  • Highly resourceful and proven ability to work both independently and as a team member
  • Ability to probe sensitive issues while maintaining high level of integrity and objectivity
  • Demonstrated ability to effectively leverage AI tools in day-to-day work, with strong critical thinking to assess accuracy, limitations and appropriate use of AI generated outputs
  • Enthusiastic about working in office and creating a Gold Standard hybrid work culture

Critical Competencies for Success

Our Gold Standards define key behaviors and competencies across 4 dimensions: Leadership, Achieving Results, Personal Effectiveness and Thinking Critically. These behaviors and competencies drive our ability to win together.

  • Leadership: Role models in this area consistently focus on the right goals and priorities and continually develop themselves and others. Always team players, they influence and engage with others to contribute to a supportive and inclusive culture where all feel welcome.

  • Achieving Results: Role models in this area are high achievers who develop careful plans and deliver consistently and effectively. They hold themselves and others accountable for delivering high quality results, and they remove barriers to ensure others can contribute and grow.

  • Personal Effectiveness: Role models in this area build strong relationships, treat others with respect and communicate effectively. They are driven to exceed expectations and are adaptable to changing circumstances.

  • Thinking Critically: Role models in this area understand our business, rely on analytical reasoning and seek diverse perspectives to solve problems. They are forward thinking, anticipating issues and addressing them in advance.

The department-specific competencies define the knowledge, skills and abilities that are needed to successfully perform the functional or technical work of this role.

  • Change Management: Communicates the benefits and the impact of refinements to internal processes or technology.

  • Innovative Mindset: Leverages an agile and creative mindset to drive innovative value creation, continuous process improvement and proactive learning through new technology, processes and people.

  • Risk Management: Identifies, forecasts and articulates ways to pursue and manage informed risks in ambiguous, complex or uncertain situations based on sound value propositions and an analysis of potential rewards and costs.

  • Technical Communication and Documentation: Documents and communicates technical processes and procedures in area of specialty to stakeholders. Adapts the level of detail and specificity based on the needs of the intended audience.

  • Industry Knowledge: Demonstrates an understanding of risk management and the Firm's position in the industry, including its complex structure and competitive advantage in the marketplace. Monitors industry trends and changes and recognizes their relevancy and implications.

  • Business Needs Assessment: Identifies business needs across departments within the Firm to understand the challenges, goals and problems that the business needs to solve and identifies appropriate technical solutions.

  • Project / Program Management: Manages projects and / or programs through planning, identifying resources, monitoring and communicating project activities and assessing impacts of project decisions.

Compensation and Benefits

For Illinois Only: It is expected that the base salary range for this position will be $115,000 to $180,000. Actual salaries may vary based on factors such as skills, experiences and qualifications for the role. The total compensation package for this position may also include other elements and discretionary awards in addition to a full range of medical, financial and / or other benefits (including 401(k) eligibility and various paid time off benefits such as vacation, sick time and parental leave) dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, the employee will be in an 'at-will position' and the Firm reserves the right to modify base salary (as well as any other discretionary payment or compensation program) at any time including for reasons related to individual performance, Firm or individual department / team performance and market factors.

Golub Capital is an Equal Opportunity Employer.

Due to the highly regulated nature of Golub Capital's business and because of the sensitivity of the information that all personnel have access to, Golub Capital performs extensive and thorough pre-hire screens to ensure that its personnel act with expected levels of integrity, professionalism and personal responsibility.

Please review Golub Capital's US Job Applicant privacy notice and, for California residents, the California Applicant privacy notice for information on how your personal data is collected, processed and stored.