1

Vendor Risk Assessment Jobs (NOW HIRING)

The Risk Advisor also supports and helps drive our client's third-party risk management (TPRM) program, contributing to vendor risk assessments, escalations, and remediation across the vendor ...

Perform New Vendor Risk Assessments and Reassessments. * Serve as backup to the Sr. Risk Analyst. Manage Metrics and Reporting (5%) * Provides weekly and monthly reporting for the Risk Register and ...

Risk Assessment Manager

Atlanta, GA · On-site

$80K - $100K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead risk assessments related to resident safety, property operations, vendor management, cybersecurity, and business continuity. * Analyze claims, incidents, and operational trends to identify risks ...

Vendor Analyst

Cleveland, OH · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

Conduct vendor due diligence reviews, risk assessments, and ongoing vendor monitoring activities. * Manage the Vendor Management inbox, triaging and assigning requests to appropriate team members.

Showing results 21-40

Vendor Risk Assessment information

See salary details

$51.5K

$111.6K

$170K

How much do vendor risk assessment jobs pay per year?

As of Aug 16, 2026, the average yearly pay for vendor risk assessment in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
More about Vendor Risk Assessment jobs

What cities are hiring for Vendor Risk Assessment jobs?

Cities with the most Vendor Risk Assessment job openings:

What states have the most Vendor Risk Assessment jobs?

States with the most job openings for Vendor Risk Assessment jobs include:

Infographic showing various Vendor Risk Assessment job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

GRC Vendor Risk Analyst

Community Financial System, Inc.

Syracuse, NY • On-site

Full-time

Posted 15 days ago


Job description

Overview

At Community Financial System, Inc. (CFSI), we are dedicated to providing our customers with friendly, personalized, high-quality financial services and products. Our retail division, Community Bank, N.A., operates more than 200 customer facilities across Upstate New York, Northeastern Pennsylvania, Vermont and Western Massachusetts. Beyond retail banking, we also offer commercial banking, wealth management, investment management, insurance and risk management, and benefit plan administration.

Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.

To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.


Responsibilities

Support CFSI’s third-party risk management program by administering the vendor due diligence portal, responding to inquiries and completing questionnaires provided by our customers and prospects regarding our information security controls, conducting information security due diligence assessments of new and existing vendors, and partnering with Enterprise Risk Management to strengthen the overall third-party risk framework. This role also supports AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved relationships, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.

Essential Duties:

  • Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
  • Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
  • Partner with stakeholders across various business lines to gather responses and supporting evidence.
  • Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
  • Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
  • Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
  • Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
  • Support identity and access management governance, review, and related coordination activities as assigned.
  • Track remediation items, follow-up actions, and review outcomes to support timely resolution.
  • Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
  • Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
  • Perform other Information Security, third-party risk, and related governance duties as assigned by management.

Ancillary Duties:

As an integral member of CFSI, this position is responsible to provide assistance wherever necessary to help the Branches and the Bank in achieving their annual goals. This may include traveling to other branches in the area to provide support as needed and to ensure proper staffing and service levels.


Qualifications

Education, Training & Requirements:

  • Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered

Skills:

  • Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.

Experience:

  • 4+ years of experience in Information Security; OR
  • 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
  • 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
  • Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
  • Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
  • All applicants must be 18 years of age or older.