1

Vendor Risk Assessment Jobs (NOW HIRING)

Define and operationalize vendor onboarding risk assessments, including security questionnaires, compliance validations, and contractual risk controls (e.g., SLAs, right-to-audit clauses, data ...

WM Vendor Risk Associate

New York, NY · On-site

$58K - $115K/yr

... of risk assessments conducted by due diligence and control groups, escalating issues for ... vendor-related incidents (e.g., data breaches), including tracking action items, preparing ...

... of risk assessments conducted by due diligence and control groups, escalating issues for ... vendor-related incidents (e.g., data breaches), including tracking action items, preparing ...

Assess AI model risk exposure, including bias, explainability, and regulatory considerations. * Partner with Security to detect and mitigate Shadow AI usage across the organization. * Track vendor ...

next page

Showing results 1-20

Vendor Risk Assessment information

See salary details

$51.5K

$111.6K

$170K

How much do vendor risk assessment jobs pay per year?

As of Jun 12, 2026, the average yearly pay for vendor risk assessment in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a Vendor Risk Assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
More about Vendor Risk Assessment jobs
What cities are hiring for Vendor Risk Assessment jobs? Cities with the most Vendor Risk Assessment job openings:
What states have the most Vendor Risk Assessment jobs? States with the most job openings for Vendor Risk Assessment jobs include:
Infographic showing various Vendor Risk Assessment job openings in the United States as of June 2026, with employment types broken down into 81% Full Time, 17% Part Time, and 2% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

Supervisor, IT Security Vendor Risk Management

Raymondjames

Saint Petersburg, FL • Hybrid

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 12 days ago


Job description

Job Description Summary

This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and riskbased prioritization. Dedicated supervision will drive measurable time reduction through operational efficiencies, reduce rework and process overhead, and enable senior leaders to focus on program strategy and regulatory readiness.

Job Description

This position follows our hybrid workstyle policy: Expected to be in a Raymond James office location a minimum of 10-12 days a month.

Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.

Technical Skills/Experience:

  • Foundational experience in IT security, vendor risk management, third party risk, or similar risk functions

  • Working knowledge of core information security and technology risk domains sufficient to review assessments, identify gaps, and escalate complex issues appropriately.

  • Familiarity with internal policies, standards, and common regulatory expectations impacting third party risk management, with the ability to follow established procedures and recognize potential non compliance trends for escalation.

  • Ability to apply basic risk concepts (inherent risk, control effectiveness, residual risk) to support consistent risk ratings and clear, defensible assessment outcomes.

  • Experience reviewing and validating the work of others for completeness, accuracy, and adherence to standards, and providing constructive feedback to improve assessment quality and consistency.

  • Developing people leadership skills, including task prioritization, workload coordination, coaching junior team members, and tracking team deliverables against defined timelines and objectives.

  • Strong written and verbal communication skills, with the ability to summarize assessment results and risks in clear, business appropriate language for stakeholders and management.

Responsibilities:

  • Leads a team responsible for conducting risk based due diligence assessments for third party supplier engagements

  • Oversees the evaluation of information security and technology risks associated with vendors, products, and services

  • Ensures vendor risk outcomes align with the firm's risk appetite and regulatory obligations

  • Accountable for the quality, consistency, and timeliness of vendor risk assessments

  • Translates technical and regulatory findings into clear risk conclusions and actionable recommendations

  • Provides guidance and risk insights to business and technology stakeholders

  • Partners closely with Procurement, Legal, IT, and business owners throughout the vendor lifecycle

  • Ensures adherence to internal policies and external regulatory expectations

  • Drives continuous improvement of the vendor risk management program

  • Manages team performance, development, and day to day execution

Education

High School (HS) (Required)

Work Experience

General Experience - 3 to 6 years, Manager Experience - 13 months to 3 years

Certifications

Travel

Less than 25%

Workstyle

Hybrid

The total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.

At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view.
We expect our associates at all levels to:
Grow professionally and inspire others to do the same
Work with and through others to achieve desired outcomes
Make prompt, pragmatic choices and act with the client in mind
Take ownership and hold themselves and others accountable for delivering results that matter
Contribute to the continuous evolution of the firm

At Raymond James - as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.

#LI-TC1