1

Vendor Risk Management Analyst Jobs in Washington, DC

Support critical third-party vendor risk management activities * Develop, enhance, and maintain ... Support management reporting, metrics, and analysis related to model governance, AI governance, and ...

Support critical third-party vendor risk management activities * Develop, enhance, and maintain ... Support management reporting, metrics, and analysis related to model governance, AI governance, and ...

The Vendor Management Analyst II is responsible for executing vendor and partner management activities, supporting vendor performance oversight, and producing analysis and reporting to enable ...

The Vendor Management Analyst II is responsible for executing vendor and partner management activities, supporting vendor performance oversight, and producing analysis and reporting to enable ...

The Vendor Management Analyst II is responsible for executing vendor and partner management activities, supporting vendor performance oversight, and producing analysis and reporting to enable ...

Showing results 21-40

Vendor Risk Management Analyst information

See Washington, DC salary details

$41.3K

$93.2K

$156.3K

How much do vendor risk management analyst jobs pay per year?

As of Aug 5, 2026, the average yearly pay for vendor risk management analyst in Washington, DC is $93,246.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,800.00 and $102,500.00 per year, depending on experience, location, and employer.

What is a vendor risk management analyst?

A Vendor Risk Management Analyst is a professional responsible for assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. They evaluate vendor practices, ensure compliance with company policies and regulations, and help protect the organization from financial, operational, and reputational risks. Their work often involves conducting risk assessments, reviewing contracts, and collaborating with other departments to ensure vendors meet required security and performance standards.

What are the key skills and qualifications needed to thrive as a vendor risk management analyst, and why are they important?

To thrive as a Vendor Risk Management Analyst, you need expertise in risk assessment, third-party due diligence, and a solid understanding of compliance regulations, typically supported by a bachelor’s degree in business, finance, or a related field. Proficiency with risk management software, vendor management platforms, and knowledge of frameworks like ISO 27001 or SOC 2 are commonly required, along with certifications such as CTPRP or CISA. Strong analytical thinking, attention to detail, and effective communication skills are essential for building relationships and reporting risks clearly. These skills ensure organizations can identify, mitigate, and manage risks associated with third-party vendors, protecting operational integrity and regulatory compliance.

How does a vendor risk management analyst typically interact with other departments within an organization?

Vendor Risk Management Analysts often collaborate closely with departments such as Procurement, Legal, IT Security, and Compliance to assess and mitigate risks associated with third-party vendors. They facilitate information sharing, coordinate risk assessments, and ensure that contract terms align with the organization's risk tolerance. Regular communication and cross-functional meetings are common, as these analysts play a key role in ensuring that vendor relationships do not expose the organization to undue risk.

What is the difference between Vendor Risk Management Analyst vs Procurement Analyst?

AspectVendor Risk Management AnalystProcurement Analyst
CertificationsCertifications like CTPRP, CRISC, or vendor risk management coursesCPM, CPSM, or purchasing certifications
Work EnvironmentFocus on risk assessment, compliance, and vendor evaluationsFocus on sourcing, purchasing, and supplier negotiations
Industry UsageCommon in finance, healthcare, and technology sectorsPrevalent across manufacturing, retail, and corporate sectors

The main difference is that a Vendor Risk Management Analyst specializes in assessing and mitigating risks associated with vendors, ensuring compliance and security. In contrast, a Procurement Analyst primarily handles sourcing and purchasing activities. Both roles require analytical skills and industry knowledge but focus on different aspects of vendor and supply chain management.

What are popular job titles related to Vendor Risk Management Analyst jobs in Washington, DC? For Vendor Risk Management Analyst jobs in Washington, DC, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Management Analyst jobs in Washington, DC look for? The top searched job categories for Vendor Risk Management Analyst jobs in Washington, DC are:
Infographic showing various Vendor Risk Management Analyst job openings in Washington, DC as of July 2026, with employment types broken down into 85% Full Time, 8% Part Time, and 7% Contract. Highlights an 85% In-person, and 15% Remote job distribution, with an average salary of $93,246 per year, or $44.8 per hour.

Senior Cybersecurity Supply Chain Risk Management Analyst

Resilient Solutions Plus

Washington, DC • On-site

$110K - $130K/yr

Other

Medical, Dental, Vision, Life, Retirement

Re-posted yesterday


Job description

Job Openings >> Senior Cybersecurity Supply Chain Risk Management Analyst
Senior Cybersecurity Supply Chain Risk Management Analyst
Summary
Title: Senior Cybersecurity Supply Chain Risk Management Analyst ID: 1024 Location: Washington, DC Department: Information Technology
More about this job >
Description
G3 Innovative Solutions, LLC is an IT Services company founded to create innovative solutions to enhance the capabilities of our customers.  G3 employees have successfully satisfied the technology needs of the U.S. Government and we continue to maintain relationships with those who have specialized expertise in the federal market.  G3's broad experience, focus toward desired outcomes, and commitment to Innovation ensures responsive and long-lasting results.
Job Description: G3 Innovative Solutions is currently seeking a Senior Cybersecurity Supply Chain Risk Management Analyst to supports OCIO's focus on the information, communications, and operational technology (ICT/OT) users who rely on a complex, globally distributed, and interconnected supply chain ecosystem to provide highly refined, cost-effective, and reusable solutions. The position requires adept utilization of multiple FBI systems used to gather and analyze moderate to complex procurement documentation and justifications for high-risk ICT/OT products and services. The position requires tiered supply chain risk management determinations that result in procurement or redirection of assets.
Duties and responsibilities:
 
  •   Provides analytical support to manage the increasing risk of supply chain compromise related to cybersecurity, whether intentional or unintentional.
  •  Identifies, assesses, and mitigates the risks associated with the distributed and interconnected nature of ICT/OT product and service supply chains.
  •  Ensures the integrity, security, quality and resilience of the supply chain and its products and services.
  •  Creates detailed technical vulnerability reports for ICT products and assigned technical "as a service" procurements.
  •  Recognizes and identifies potential areas where existing security policies and procedures require change, or where new ones need to be developed,
    especially regarding future business expansion Provides information security matter expertise to technology teams and projects.
  •  Creates security architecture standards for adoption of new technology
  •  Identifies, quantifies, and recommends mitigation actions for security risks as they relate to enterprise projects.
  •  Produces management reporting, including appropriate metrics that inform senior leadership as to the state of information risk and exposure.
  •  Understands security product/service cost drivers and industry and business trends impacting the Agency information security program.
  •  Recognizes and identifies potential areas where existing security policies and procedures require change, or where new ones need to be developed,
    especially regarding future business expansion. Provides information security matter expertise to technology teams and projects.
Requirements:
  • B.S. degree in Computer Science, Business Management, or IT related discipline strongly preferred or an additional 4 years of experience in lieu of degree.
  • A minimum of 8 or more years of experience
Location:
  • Washington, DC
Clearance:
  • Top Secret

Compensation:    $110,000 - $130,000 annually depending on experience and candidate qualifications
Benefits Offered:  401K, Medical, Dental, Life, Medical, Vision, and more
Employment Type: Full-Time
Clearance (Required): Must currently possess a Top Secret Clearance
G3 Innovative Solutions, LLC provides equal employment opportunity to all individuals regardless of race, color, creed, religion, gender, age, sexual orientation, national origin or ancestry.
 
Apply Now
 
Refer to a Friend
Copyright 2026 Resilient Solutions Plus. All rights reserved.
Powered by ApplicantStack Hiring Automation Software
Privacy Policy | Terms of Use