1

Vendor Risk Assessment Jobs (NOW HIRING)

GRC Vendor Risk Analyst

Syracuse, NY · On-site

$70 - $100/hr

Responsibilities Support CFSI's third-party risk management program by administering the vendor due ... Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in ...

ABOUT THE ROLE The Information Security Client & Vendor Risk Manager leads the firm's client due ... Lead complex vendorrisk assessments for highimpact technology and service providers, including ...

Showing results 21-40

Vendor Risk Assessment information

See salary details

$51.5K

$111.6K

$170K

How much do vendor risk assessment jobs pay per year?

As of Sep 5, 2026, the average yearly pay for vendor risk assessment in the United States is $111,556.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,000.00 and $129,000.00 per year, depending on experience, location, and employer.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

More about Vendor Risk Assessment jobs

What cities are hiring for Vendor Risk Assessment jobs?

Cities with the most Vendor Risk Assessment job openings:

What states have the most Vendor Risk Assessment jobs?

States with the most job openings for Vendor Risk Assessment jobs include:

Infographic showing various Vendor Risk Assessment job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 89% Full Time, 8% Part Time, and 2% Contract. Highlights an 85% Physical, 5% Hybrid, and 10% Remote job distribution, with an average salary of $111,556 per year, or $53.6 per hour.

Full-time

Re-posted 26 days ago


Job description

Key responsibilities

The primary responsibility of this position will be as the central contact, from a Bain perspective, in coordinating activities around the development of Business Continuity Plans and an assessment of the Disaster Recovery program, reporting to the Director of Technology Risk.

Disaster recovery tests are conducted on a quarterly basis. Working with the Project Manager, Business Users and Infrastructure team you will have a hands on role in the coordination and documentation of the tests. This will include reaching out to our third parties to understand their test strategies.

For Business Continuity planning, you will be involved in the process to create/update the Business Impact Analysis (BIA) and the Business Continuity Plans. This role will be a member of the team, working with the business, to define and document their needs.

This will also require technical knowledge to work with the BC in the Cloud application to enhance and update based on user requirements. As part of these enhancements, you will need to document the requirements, coordinate the updates with the vendor, or in many cases perform them yourself and then validate the enhancements are successful.

Your secondary responsibility within the Technology Risk Group, will be to assist the Vendor Risk Manager in supporting the Third Party Risk Assessment process.

In this role, you will review the preliminary risk assessment, interface with vendor to obtain necessary diligence details, interface with third party risk assessor, document defined risks and develop communication to the business to accept risks or create plan to mitigate risk as well as track in our risk register.

As a team member, you will support the Vendor Risk Manager in tracking the assessment of new 3rd party vendor, updating assessments for our critical vendors, provide regular reporting and update the Vendor Risk system.

As part of your responsibility, not only will you be interacting with third party vendors, you will also interface with the IT Organizations and Business counterparts.

Qualifications
  • Experience with documentation and Microsoft tools, specifically Excel and Word
  • HTML skills a plus
  • Strong analytical ability, judgment and problem analysis techniques
  • Beneficial for candidate to have experience or coursework in any of the following topics: Risk Assessments, Emergency Preparedness, Business Continuity, Business, Information Technology, and/or Information Security
  • Experience with project and/or program management, whether business experience or in group/classwork activities
  • Proven ability to be self-starter with strong communication skills, written and verbal and keen attention to detail and thoroughness