1

Vendor Risk Assessment Jobs in Coppell, TX (NOW HIRING)

Lead complex vendor-risk assessments for high-impact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetration-test results, cloud-security controls ...

Vendor Risk Manager

Westlake, TX · On-site

$36.78 - $40.87/hr

Consistently apply established risk assessment methodologies to evaluate third-party vendors across key areas such as criticality, compliance, cybersecurity, operational resilience, and financial ...

Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with ...

Security Manager

Dallas, TX · On-site

$150K - $165K/yr

Manage third-party vendor risk assessments and ongoing monitoring activities. * Evaluate vendor security controls, certifications, and risk posture. * Review SOC 2 reports, ISO 27001 certifications ...

Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with ...

Senior Security Engineer

Dallas, TX · On-site

$113K - $155K/yr

Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA ...

Senior Security Engineer

Dallas, TX

$113K - $155K/yr

Conduct recurring vendor risk and compliance assessments covering AI system performance, data quality, algorithmic bias, and security controls; monitor pre-trained/foundation model drift and SLA ...

next page

Showing results 1-20

Vendor Risk Assessment information

See Coppell, TX salary details

$47.5K

$103K

$156.9K

How much do vendor risk assessment jobs pay per year?

As of Aug 19, 2026, the average yearly pay for vendor risk assessment in Coppell, TX is $102,985.00, according to ZipRecruiter salary data. Most workers in this role earn between $83,100.00 and $119,100.00 per year, depending on experience, location, and employer.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What cities near Coppell, TX are hiring for Vendor Risk Assessment jobs?

Cities near Coppell, TX with the most Vendor Risk Assessment job openings:

Infographic showing various Vendor Risk Assessment job openings in Coppell, TX as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 11% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $102,985 per year, or $49.5 per hour.

Client & Vendor Risk Manager

Baker Botts

Dallas, TX • On-site

Full-time

Re-posted 12 days ago


Job description

ABOUT BAKER BOTTS
Baker Botts is a leading international law firm recognized for its deep understanding of the industries it serves. With offices across major global markets, the firm delivers sophisticated legal services while cultivating a collaborative, inclusive culture where both attorneys and professional staff contribute to client success and organizational excellence.
ABOUT THE ROLE
The Information Security Client & Vendor Risk Manager leads the firm's client due diligence program and oversees all information security vetting for third party vendors across the firm. This role requires deep expertise in security frameworks, strong risk-assessment judgment, and the ability to influence senior stakeholders, including internal stakeholders, and client security teams. The Manager acts as a key liaison between the firm's clients, internal leadership, IT Security, Procurement, and Risk Management, ensuring the firm meets the heightened expectations of our clients.
WHAT YOU'LL DO
Primary Responsibilities
  • Own and mature the firm-wide client and vendor due-diligence program, ensuring consistency, accuracy, and alignment with the firm's security posture and regulatory obligations.
  • Serve as the firm's subject-matter expert on information-security controls, certifications, and risk posture during client audits, RFPs, and reviews or client engagement terms.
  • Lead complex vendor-risk assessments for high-impact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetration-test results, cloud-security controls, data-protection, privacy, and retention practices.
  • Develop and maintain the firm's vendor-risk management framework, including risk-scoring methodologies, onboarding workflows, and continuous-monitoring processes.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts, negotiate security requirements, and recommend risk-mitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection, documentation, and SME participation across multiple departments.
  • Represent the firm in client-facing security discussions, including responding to escalated inquiries from corporate counsel, privacy officers, and client security teams.
  • Monitor emerging risks and regulatory developments relevant to the legal industry (e.g., SEC cybersecurity rules, state privacy laws, international data-transfer requirements).
  • Mentor junior analysts and contribute to the professional development of the broader Risk and Compliance team.
  • Drive continuous improvement, identifying opportunities to streamline due-diligence workflows, enhance tracking and remediation of client-identified risks, and strengthen the firm's security posture.

Additional Responsibilities
  • Provide management with periodic reports & briefings on evolving topics within their area of responsibility.
  • Other related projects and duties as assigned by the Director of Information Security.

WHAT YOU'LL BRING
Required
  • 6+ years of experience in information security, vendor risk management, compliance, or legal-industry operations, ideally within an Am Law 200 firm or similarly regulated environment.
  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendor-risk assessments for enterprise-level technology providers.
  • Strong communication skills, including the ability to brief partners, respond to client security teams, and translate technical concepts for non-technical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead cross-functional initiatives in a high-pressure environment.
  • Professional certifications such as CTPRA, ISO 27001 Lead Implementer or Lead Auditor and CISSP, CISM, CRISC, or CISA required.
  • Experience with legal-industry technologies (DMS, e-discovery platforms, cloud-based practice-management tools) is a plus.

HOW YOU'LL WORK
Extent of Contact
This position requires contact with individuals within the firms as follows:
  • Daily contact with staff from the Firm's Information Technology, Client Development and Office of the General Counsel teams.
  • Moderate contact with Firm's attorneys and client representatives.
  • Occasional contact with Firm Management.

This position requires contact with individuals outside the firm as follows:
  • Moderate contact with Firm vendors or potential vendors.
  • Moderate contact with Firm clients

Physical Requirements
  • Must be able to routinely lift and carry event materials and other items up to 10 pounds.
  • Must be able to work at a computer for extensive periods of time.
  • Position requires extensive telephone use.
  • Must be able to lift, squat, kneel and bend.
  • Position requires the ability to visit face-to-face and on the phone with firm lawyers.

Working Conditions and Environment
  • Position is full-time and requires a five-day work week and standard hours as outlined in the Firm policy manual. Additional hours, including weekend and evening hours may be required to perform the essential functions of the job.
  • Must be able to perform essential duties of the position with time constraints and frequent interruptions.
  • Ability to work well in high pressure environments.
  • 24x7 communication access is required.
  • This position is fully remote. You will be required to come to the office periodically for team meetings or when there is a business or client need.
  • There is potential for travel when needed for team meetings, onsite assessments etc. when there is a business or client need.
  • When working remotely, you must have secure and reliable internet service and a safe, private workspace from which to work.

Baker Botts L.L.P. is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, gender, sex, age, religion, creed, national origin, citizenship, marital status, sexual orientation, disability, medical condition, military and veteran status, gender identity or expression, genetic information, or any other basis protected by federal, state, or local law.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.