1

Vendor Risk Management Analyst Jobs in Michigan (NOW HIRING)

Certified Professional in Patient Safety (CPPS), Certified Professional in Healthcare Risk Management (CPHRM), Certified Professional in Healthcare Quality (CPHQ) or other patient safety training ...

ServiceNow IRM Specialist

Lansing, MI · On-site +1

$58 - $65/hr

... Risk Management, Audit Management, Vendor Risk, Business Continuity). - Partner with stakeholders to gather requirements and translate them into ServiceNow IRM solutions. - Develop and maintain ...

Certified Professional in Patient Safety (CPPS), Certified Professional in Healthcare Risk Management (CPHRM), Certified Professional in Healthcare Quality (CPHQ) or other patient safety training ...

next page

Showing results 1-20

Vendor Risk Management Analyst information

See Michigan salary details

$31.8K

$71.8K

$120.3K

How much do vendor risk management analyst jobs pay per year?

As of Jun 28, 2026, the average yearly pay for vendor risk management analyst in Michigan is $71,758.00, according to ZipRecruiter salary data. Most workers in this role earn between $54,500.00 and $78,900.00 per year, depending on experience, location, and employer.

What is a Vendor Risk Management Analyst?

A Vendor Risk Management Analyst is a professional responsible for assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. They evaluate vendor practices, ensure compliance with company policies and regulations, and help protect the organization from financial, operational, and reputational risks. Their work often involves conducting risk assessments, reviewing contracts, and collaborating with other departments to ensure vendors meet required security and performance standards.

What are the key skills and qualifications needed to thrive as a Vendor Risk Management Analyst, and why are they important?

To thrive as a Vendor Risk Management Analyst, you need expertise in risk assessment, third-party due diligence, and a solid understanding of compliance regulations, typically supported by a bachelor’s degree in business, finance, or a related field. Proficiency with risk management software, vendor management platforms, and knowledge of frameworks like ISO 27001 or SOC 2 are commonly required, along with certifications such as CTPRP or CISA. Strong analytical thinking, attention to detail, and effective communication skills are essential for building relationships and reporting risks clearly. These skills ensure organizations can identify, mitigate, and manage risks associated with third-party vendors, protecting operational integrity and regulatory compliance.

How does a Vendor Risk Management Analyst typically interact with other departments within an organization?

Vendor Risk Management Analysts often collaborate closely with departments such as Procurement, Legal, IT Security, and Compliance to assess and mitigate risks associated with third-party vendors. They facilitate information sharing, coordinate risk assessments, and ensure that contract terms align with the organization's risk tolerance. Regular communication and cross-functional meetings are common, as these analysts play a key role in ensuring that vendor relationships do not expose the organization to undue risk.

What is the difference between Vendor Risk Management Analyst vs Procurement Analyst?

AspectVendor Risk Management AnalystProcurement Analyst
CertificationsCertifications like CTPRP, CRISC, or vendor risk management coursesCPM, CPSM, or purchasing certifications
Work EnvironmentFocus on risk assessment, compliance, and vendor evaluationsFocus on sourcing, purchasing, and supplier negotiations
Industry UsageCommon in finance, healthcare, and technology sectorsPrevalent across manufacturing, retail, and corporate sectors

The main difference is that a Vendor Risk Management Analyst specializes in assessing and mitigating risks associated with vendors, ensuring compliance and security. In contrast, a Procurement Analyst primarily handles sourcing and purchasing activities. Both roles require analytical skills and industry knowledge but focus on different aspects of vendor and supply chain management.

What are popular job titles related to Vendor Risk Management Analyst jobs in Michigan? For Vendor Risk Management Analyst jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Management Analyst jobs in Michigan look for? The top searched job categories for Vendor Risk Management Analyst jobs in Michigan are:
Infographic showing various Vendor Risk Management Analyst job openings in Michigan as of June 2026, with employment types broken down into 1% As Needed, 83% Full Time, 15% Part Time, and 1% Temporary. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $71,758 per year, or $34.5 per hour.
Compliance and Risk Management Senior Specialist

Compliance and Risk Management Senior Specialist

FastTek

Dearborn, MI

$90K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago


Job description

Compliance and Risk Management Senior Specialist #1052955
Job Description:
  • Employees part of this job function review cybersecurity laws and policies and analyze its impact on organization.
  • They develop security policies and procedures, review security y controls and their efficiency, , and monitor processes for compliance risk and vulnerabilities.
  • They also specialize in managing third party security risk programs

Key Responsibilities:
  • Advance company policy priorities on cybersecurity, cybercrime, lawful access, encryption, and related issues through legislative proposals, administrative, and regulatory actions
  • Review and assess cybersecurity and cybercrime laws, policies, and initiatives and analyze impact on organization
  • Develop security policies and procedures, drive development of technical solutions to implement policies, and manage third party security risk program including risk standards and processes.
  • Advise, review, and ensure security controls and their efficiency for IT infrastructure deployed globally.
  • Monitor processes for compliance risk and vulnerabilities and escalate non-compliance issues to key stakeholders.
  • Establish and maintain good working relationships with government affairs and public policy representatives of other companies to achieve objectives

Skills Required:
Risk Assessment, Risk Management, Compliance Professional, Auditing, Information Security
  • Risk Assessment - Candidates must be able to perform targeted risk assessments that compare the company's current security posture against the specific requirements mandated by various state agencies. This involves evaluating the risk of non-compliance and determining if the organization can meet security standards (such as NIST or CSF) often found in state-level questionnaires.
  • Risk Management - Candidates will manage the lifecycle of identified security deficiencies. If a questionnaire reveals a gap in state-mandated controls, you are expected to facilitate the development of a remediation plan. You must be able to document compensating controls and articulate the organization's risk-handling strategy to state regulators to ensure business continuity and contract eligibility.
  • Compliance Professional - You will serve as the primary interpreter of diverse state cybersecurity regulations and frameworks (e.g., NYDFS, or CCPA/CPRA).
  • Auditing - You are expected to adopt an "audit-ready" approach to every questionnaire submission. This means you will not only provide answers but also identify and organize the necessary "artifacts" (evidence) to support those answers 5. Information Security - You are expected to translate complex technical architectures—such as zero-trust models, encryption protocols, and incident response procedures—into clear, concise responses that satisfy state-level security inquiries.

Experience Required:
  • Senior Specialist Exp: 7+ experience in relevant field.

Education Required:
  • Bachelor's Degree

Additional Information:
  • Regulatory Response Leadership: Lead the end-to-end management of regulatory cybersecurity assessments and questionnaires from local, state, and national government entities
  • Quality: Strategic Consolidation of Global IT Regulatory Requirements
  • Strategic Consulting: Act as a subject matter expert (SME) for teams, providing guidance on IT security, risk mitigation, and control implementation
  • Legal & Privacy Partnership: Collaborate closely with Credit Privacy and Compliance Attorneys to interpret and execute IT-related regulatory requirements
  • Audit & Assessment Oversight: Facilitate and support internal/external audits, third-party consulting engagements, and comprehensive risk assessments
  • Agile Governance: Maintain transparency and momentum by managing user stories and backlogs within JIRA, ensuring compliance activities are integrated into the broader technology roadmap

Additional Info:
At FastTek Global, Our Purpose is Our People and Our Planet. We come to work each day and are reminded we are helping people find their success stories. Also, Doing the right thing is our mantra. We act responsibly, give back to the communities we serve and have a little fun along the way.
We have been doing this with pride, dedication and plain, old-fashioned hard work for 24 years!
FastTek Global is financially strong, privately held company that is 100% consultant and client focused.
We've differentiated ourselves by being fast, flexible, creative and honest. Throw out everything you've heard, seen, or felt about every other IT Consulting company. We do unique things and we do them for Fortune 10, Fortune 500, and technology start-up companies.
Our benefits are second to none and thanks to our flexible benefit options you can choose the benefits you need or want, options include:
  • Medical and Dental (FastTek pays majority of the medical program)
  • Vision
  • Personal Time Off (PTO) Program
  • Long Term Disability (100% paid)
  • Life Insurance (100% paid)
  • 401(k) with immediate vesting and 3% (of salary) dollar-for-dollar match

Plus, we have a lucrative employee referral program and an employee recognition culture.
FastTek Global was named one of the Top Work Places in Michigan by the Detroit Free Press in 2013, 2014, 2015, 2016, 2017, 2018, 2019, 2020, 2021, 2022, and 2023!
To view all of our open positions go to: https://www.fasttek.com/fastswitch/findwork
Follow us on Twitter: https://twitter.com/fasttekglobal
Follow us on Instagram: https://www.instagram.com/fasttekglobal
Find us on LinkedIn: https://www.linkedin.com/company/fasttek
You can become a fan of FastTek on Facebook: https://www.facebook.com/fasttekglobal/
AI & Hiring Disclosure
We use AI tools to support parts of our hiring process, such as reviewing applications and identifying potential matches. These tools are designed to promote efficiency, consistency, and fairness, and they are always used under human oversight.
All personal data collected is used solely for recruitment purposes, and you have the right to know, access, or request deletion of your data at any time, subject to legal limits.
If AI will be used in a video interview, you'll be informed in advance and asked for your consent, with the option to opt out.
Our tools are regularly reviewed to detect potential bias and to ensure compliance with all applicable laws and our commitment to inclusive hiring.
To learn more or exercise your rights, please contact us at info@fasttek.com.