Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and riskbased ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and riskbased ...
Execute vendor risk assessments as part of the onboarding and periodic review lifecycle, including security questionnaire administration, documentation review, and risk scoring. * Maintain the vendor ...
Execute vendor risk assessments as part of the onboarding and periodic review lifecycle, including security questionnaire administration, documentation review, and risk scoring. * Maintain the vendor ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and risk ...
Summary This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and risk ...
The role involves performing vendor risk assessments, analyzing security controls, and ensuring compliance with security frameworks such as SOC 2 and ISO 27001 . The ideal candidate will work closely ...
The role involves performing vendor risk assessments, analyzing security controls, and ensuring compliance with security frameworks such as SOC 2 and ISO 27001 . The ideal candidate will work closely ...
Director Vendor Risk Management
Honolulu, HI · On-site
$142K - $255K/yr
Serves as the primary liaison for internal and external audits, assessments, and regulatory ... Risk Intelligence & Strategic Reporting: Synthesizes complex vendor data into actionable insights ...
Director Vendor Risk Management
Honolulu, HI · On-site
$142K - $255K/yr
Serves as the primary liaison for internal and external audits, assessments, and regulatory ... Risk Intelligence & Strategic Reporting: Synthesizes complex vendor data into actionable insights ...
Senior Enterprise Risk Manager
Denver, CO · On-site
Define and operationalize vendor onboarding risk assessments, including security questionnaires, compliance validations, and contractual risk controls (e.g., SLAs, right-to-audit clauses, data ...
Senior Enterprise Risk Manager
Denver, CO · On-site
Define and operationalize vendor onboarding risk assessments, including security questionnaires, compliance validations, and contractual risk controls (e.g., SLAs, right-to-audit clauses, data ...
Senior Analyst - Third Party Risk Management
Norfolk, VA · On-site +1
Vendor Risk Assessment (VRA): * Conduct thorough risk assessments for potential and existing vendors, focusing on various risk types, including cybersecurity, operational, financial, and compliance ...
Senior Analyst - Third Party Risk Management
Norfolk, VA · On-site +1
Vendor Risk Assessment (VRA): * Conduct thorough risk assessments for potential and existing vendors, focusing on various risk types, including cybersecurity, operational, financial, and compliance ...
Vendor Risk Assessment (VRA): * Conduct thorough risk assessments for potential and existing vendors, focusing on various risk types, including cybersecurity, operational, financial, and compliance ...
Vendor Risk Assessment (VRA): * Conduct thorough risk assessments for potential and existing vendors, focusing on various risk types, including cybersecurity, operational, financial, and compliance ...
Define and operationalize vendor onboarding risk assessments, including security questionnaires, compliance validations, and contractual risk controls (e.g., SLAs, right-to-audit clauses, data ...
Define and operationalize vendor onboarding risk assessments, including security questionnaires, compliance validations, and contractual risk controls (e.g., SLAs, right-to-audit clauses, data ...
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Procurement Risk & Compliance Lead
Centreville, VA · On-site
$155K/yr
Support SOX-related vendor governance controls where applicable. * Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings.
Senior Manager, Vendor Risk & Procurement Governance - Mobility
Centreville, VA · On-site
$94K - $127K/yr
Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings. Cross-Functional Collaboration * Serve as key liaison between ...
Senior Manager, Vendor Risk & Procurement Governance - Mobility
Centreville, VA · On-site
$94K - $127K/yr
Partner with Internal Audit on third-party risk assessments. * Support remediation efforts tied to vendor governance findings. Cross-Functional Collaboration * Serve as key liaison between ...
WM Vendor Risk Associate
New York, NY · On-site
$58K - $115K/yr
... of risk assessments conducted by due diligence and control groups, escalating issues for ... vendor-related incidents (e.g., data breaches), including tracking action items, preparing ...
WM Vendor Risk Associate
New York, NY · On-site
$58K - $115K/yr
... of risk assessments conducted by due diligence and control groups, escalating issues for ... vendor-related incidents (e.g., data breaches), including tracking action items, preparing ...
JOB SUMMARY The candidate will be responsible for executing third-party risk assessments, including evaluating vendor control environments, documenting risk findings, and supporting risk-based ...
JOB SUMMARY The candidate will be responsible for executing third-party risk assessments, including evaluating vendor control environments, documenting risk findings, and supporting risk-based ...
Operational Risk and Control Analyst
New York, NY · On-site
$75K - $110K/yr
Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment. * Conduct analyses of risk data to identify trends and potential ...
Operational Risk and Control Analyst
New York, NY · On-site
$75K - $110K/yr
Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment. * Conduct analyses of risk data to identify trends and potential ...
Operational Risk and Control Analyst
New York, NY · On-site
$75K - $110K/yr
Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment. * Conduct analyses of risk data to identify trends and potential ...
Quick apply
Operational Risk and Control Analyst
New York, NY · On-site
$75K - $110K/yr
Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment. * Conduct analyses of risk data to identify trends and potential ...
WM Vendor Risk Associate
$58K - $115K/yr
... of risk assessments conducted by due diligence and control groups, escalating issues for ... vendor-related incidents (e.g., data breaches), including tracking action items, preparing ...
WM Vendor Risk Associate
$58K - $115K/yr
... of risk assessments conducted by due diligence and control groups, escalating issues for ... vendor-related incidents (e.g., data breaches), including tracking action items, preparing ...
Vendor Manager
Malvern, PA · On-site
Assess AI model risk exposure, including bias, explainability, and regulatory considerations. * Partner with Security to detect and mitigate Shadow AI usage across the organization. * Track vendor ...
Vendor Manager
Malvern, PA · On-site
Assess AI model risk exposure, including bias, explainability, and regulatory considerations. * Partner with Security to detect and mitigate Shadow AI usage across the organization. * Track vendor ...
Operational Risk and Control Analyst
New York, NY · Hybrid
$75K - $110K/yr
Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment. * Conduct analyses of risk data to identify trends and potential ...
Operational Risk and Control Analyst
New York, NY · Hybrid
$75K - $110K/yr
Coordinate and conduct Vendor Risk Assessment, Model Risk Assessment, and Operational Risk Event (Business Continuity) Assessment. * Conduct analyses of risk data to identify trends and potential ...
Assess AI model risk exposure, including bias, explainability, and regulatory considerations. * Partner with Security to detect and mitigate Shadow AI usage across the organization. * Track vendor ...
Quick apply
Assess AI model risk exposure, including bias, explainability, and regulatory considerations. * Partner with Security to detect and mitigate Shadow AI usage across the organization. * Track vendor ...
Risk Management Specialist
Villa Park, IL · On-site
$70K - $85K/yr
Conduct pre-contract due diligence and ongoing vendor risk assessments. * Facilitate annual vendor reviews and ensure timely remediation of identified issues. * Administer and maintain vendor risk ...
Quick apply
Risk Management Specialist
Villa Park, IL · On-site
$70K - $85K/yr
Conduct pre-contract due diligence and ongoing vendor risk assessments. * Facilitate annual vendor reviews and ensure timely remediation of identified issues. * Administer and maintain vendor risk ...
Vendor Risk Assessment information
See salary details
$51.5K - $62.3K
4% of jobs
$62.3K - $73K
6% of jobs
$73K - $83.8K
11% of jobs
$87.9K is the 25th percentile. Wages below this are outliers.
$83.8K - $94.6K
11% of jobs
The median wage is $103.2K / yr.
$94.6K - $105.4K
23% of jobs
$105.4K - $116.1K
13% of jobs
$123.2K is the 75th percentile. Wages above this are outliers.
$116.1K - $126.9K
12% of jobs
$126.9K - $137.7K
8% of jobs
$137.7K - $148.5K
6% of jobs
$148.5K - $159.2K
4% of jobs
$159.2K - $170K
2% of jobs
$51.5K
$111.6K
$170K
How much do vendor risk assessment jobs pay per year?
What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?
| Aspect | Vendor Risk Assessment | Vendor Compliance Analyst |
|---|---|---|
| Primary Focus | Evaluating risks associated with vendors and third-party providers | Ensuring vendors comply with policies, regulations, and contractual obligations |
| Certifications | Certifications like CISSP, CISA, or vendor risk management courses | Certifications such as CCEP, CISA, or compliance-specific credentials |
| Work Environment | Risk management teams, procurement, cybersecurity departments | Compliance teams, legal, procurement, and audit departments |
| Industry Usage | Common in finance, healthcare, and IT sectors | Prevalent in regulated industries like finance, healthcare, and manufacturing |
Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.
What are the key skills and qualifications needed to thrive as a Vendor Risk Assessment professional, and why are they important?
What are some common challenges faced in a Vendor Risk Assessment role, and how can I prepare to address them?
What is a Vendor Risk Assessment?

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Posted 12 days ago
Job description
Job Description Summary
This role provides essential leadership oversight to ensure consistent coverage and quality of IT Security Vendor Risk Assessments while improving coordination, standardization, and riskbased prioritization. Dedicated supervision will drive measurable time reduction through operational efficiencies, reduce rework and process overhead, and enable senior leaders to focus on program strategy and regulatory readiness.Job Description
This position follows our hybrid workstyle policy: Expected to be in a Raymond James office location a minimum of 10-12 days a month.
Please note: This role is not eligible for Work Visa sponsorship, either currently or in the future.
Technical Skills/Experience:
Foundational experience in IT security, vendor risk management, third party risk, or similar risk functions
Working knowledge of core information security and technology risk domains sufficient to review assessments, identify gaps, and escalate complex issues appropriately.
Familiarity with internal policies, standards, and common regulatory expectations impacting third party risk management, with the ability to follow established procedures and recognize potential non compliance trends for escalation.
Ability to apply basic risk concepts (inherent risk, control effectiveness, residual risk) to support consistent risk ratings and clear, defensible assessment outcomes.
Experience reviewing and validating the work of others for completeness, accuracy, and adherence to standards, and providing constructive feedback to improve assessment quality and consistency.
Developing people leadership skills, including task prioritization, workload coordination, coaching junior team members, and tracking team deliverables against defined timelines and objectives.
Strong written and verbal communication skills, with the ability to summarize assessment results and risks in clear, business appropriate language for stakeholders and management.
Responsibilities:
Leads a team responsible for conducting risk based due diligence assessments for third party supplier engagements
Oversees the evaluation of information security and technology risks associated with vendors, products, and services
Ensures vendor risk outcomes align with the firm's risk appetite and regulatory obligations
Accountable for the quality, consistency, and timeliness of vendor risk assessments
Translates technical and regulatory findings into clear risk conclusions and actionable recommendations
Provides guidance and risk insights to business and technology stakeholders
Partners closely with Procurement, Legal, IT, and business owners throughout the vendor lifecycle
Ensures adherence to internal policies and external regulatory expectations
Drives continuous improvement of the vendor risk management program
Manages team performance, development, and day to day execution
Education
High School (HS) (Required)Work Experience
General Experience - 3 to 6 years, Manager Experience - 13 months to 3 yearsCertifications
Travel
Less than 25%Workstyle
HybridThe total compensation for this position includes base salary or wages, and may include components such as additional compensation (cash or equity), discretionary bonuses, or commissions. This position is eligible for a benefits package that may include medical, dental, and vision; life insurance; critical illness insurance and accident insurance; disability benefits; retirement savings; paid time off (including vacation, holidays, and sick leave); and parental leave. Eligibility for benefits and specific offerings may vary based on position and employment status. To view more details of the benefits offered, visit Myrjbenefits.com.
At Raymond James our associates use five guiding behaviors (Develop, Collaborate, Decide, Deliver, Improve) to deliver on the firm's core values of client-first, integrity, independence and a conservative, long-term view.
We expect our associates at all levels to:
Grow professionally and inspire others to do the same
Work with and through others to achieve desired outcomes
Make prompt, pragmatic choices and act with the client in mind
Take ownership and hold themselves and others accountable for delivering results that matter
Contribute to the continuous evolution of the firm
At Raymond James - as part of our people-first culture, we honor, value, and respect the uniqueness, experiences, and backgrounds of all of our Associates. When associates bring their best authentic selves, our organization, clients, and communities thrive. The Company is an equal opportunity employer and makes all employment decisions on the basis of merit and business needs.
#LI-TC1