1

Vendor Risk Management Analyst Jobs (NOW HIRING)

Enterprise Risk Management (ERM) and Third-Party Vendor Risk Management (TPVRM). Reporting to the ... prioritization analyses for leadership. * Maintain and update the enterprise risk register ...

The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...

The Risk Management Analyst supports the identification, assessment, and communication of discrete and overall program and project risk across cost, schedule, and performance dimensions within a ...

next page

Showing results 1-20

Vendor Risk Management Analyst information

See salary details

$36.5K

$82.3K

$138K

How much do vendor risk management analyst jobs pay per year?

As of Jul 21, 2026, the average yearly pay for vendor risk management analyst in the United States is $82,330.00, according to ZipRecruiter salary data. Most workers in this role earn between $62,500.00 and $90,500.00 per year, depending on experience, location, and employer.

What is a Vendor Risk Management Analyst?

A Vendor Risk Management Analyst is a professional responsible for assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. They evaluate vendor practices, ensure compliance with company policies and regulations, and help protect the organization from financial, operational, and reputational risks. Their work often involves conducting risk assessments, reviewing contracts, and collaborating with other departments to ensure vendors meet required security and performance standards.

What are the key skills and qualifications needed to thrive as a Vendor Risk Management Analyst, and why are they important?

To thrive as a Vendor Risk Management Analyst, you need expertise in risk assessment, third-party due diligence, and a solid understanding of compliance regulations, typically supported by a bachelor’s degree in business, finance, or a related field. Proficiency with risk management software, vendor management platforms, and knowledge of frameworks like ISO 27001 or SOC 2 are commonly required, along with certifications such as CTPRP or CISA. Strong analytical thinking, attention to detail, and effective communication skills are essential for building relationships and reporting risks clearly. These skills ensure organizations can identify, mitigate, and manage risks associated with third-party vendors, protecting operational integrity and regulatory compliance.

How does a Vendor Risk Management Analyst typically interact with other departments within an organization?

Vendor Risk Management Analysts often collaborate closely with departments such as Procurement, Legal, IT Security, and Compliance to assess and mitigate risks associated with third-party vendors. They facilitate information sharing, coordinate risk assessments, and ensure that contract terms align with the organization's risk tolerance. Regular communication and cross-functional meetings are common, as these analysts play a key role in ensuring that vendor relationships do not expose the organization to undue risk.

What is the difference between Vendor Risk Management Analyst vs Procurement Analyst?

AspectVendor Risk Management AnalystProcurement Analyst
CertificationsCertifications like CTPRP, CRISC, or vendor risk management coursesCPM, CPSM, or purchasing certifications
Work EnvironmentFocus on risk assessment, compliance, and vendor evaluationsFocus on sourcing, purchasing, and supplier negotiations
Industry UsageCommon in finance, healthcare, and technology sectorsPrevalent across manufacturing, retail, and corporate sectors

The main difference is that a Vendor Risk Management Analyst specializes in assessing and mitigating risks associated with vendors, ensuring compliance and security. In contrast, a Procurement Analyst primarily handles sourcing and purchasing activities. Both roles require analytical skills and industry knowledge but focus on different aspects of vendor and supply chain management.

More about Vendor Risk Management Analyst jobs
What cities are hiring for Vendor Risk Management Analyst jobs? Cities with the most Vendor Risk Management Analyst job openings:
What states have the most Vendor Risk Management Analyst jobs? States with the most job openings for Vendor Risk Management Analyst jobs include:
What job categories do people searching Vendor Risk Management Analyst jobs look for? The top searched job categories for Vendor Risk Management Analyst jobs are:
Infographic showing various Vendor Risk Management Analyst job openings in the United States as of July 2026, with employment types broken down into 86% Full Time, 7% Part Time, and 7% Contract. Highlights an 86% In-person, and 14% Remote job distribution, with an average salary of $82,330 per year, or $39.6 per hour.
Vendor Risk Specialist

Vendor Risk Specialist

PrincePerelson and Associates

Salt Lake City, UT • On-site

$95K/yr

Other

Medical, Retirement, PTO

This job post has expired 1 day ago. Applications are no longer accepted.


Job description

Vendor Risk Specialist

Salt Lake City, UT


A rapidly growing financial technology organization is seeking a Vendor Risk Specialist to join its Information Security team. This individual will be part of a small team responsible for evaluating and managing risks associated with third-party vendors and service providers.


The role focuses on assessing information security, operational, financial, regulatory, and business continuity risks. The successful candidate will work closely with internal stakeholders and external vendors to gather documentation, evaluate controls, identify risks, and support remediation efforts.


Responsibilities

  • Conduct third-party vendor risk assessments, including reviews of security controls, policies, procedures, and independent audit reports.
  • Partner with internal business owners and external vendors to collect required documentation and responses to due diligence questionnaires.
  • Evaluate vendor security programs and recommend mitigating or compensating controls when necessary.
  • Track identified risks and remediation activities with vendors and internal stakeholders.
  • Escalate unresolved or high-risk findings to leadership for review and acceptance.
  • Maintain reporting and metrics related to the vendor risk management program.
  • Support broader governance, risk, and compliance initiatives as needed.


Qualifications

  • 5+ years of experience in technology, information security, risk management, or a related field.
  • 2–3 years of experience specifically focused on vendor risk management, third-party risk, or security assessments.
  • Bachelor's degree in Computer Science, Information Security, Information Systems, or a related discipline.
  • Familiarity with vendor governance, risk, and compliance (GRC) platforms.
  • Understanding of security frameworks such as ISO 27001, NIST, or comparable standards.
  • Knowledge of regulatory, privacy, and compliance requirements impacting third-party risk management.
  • Experience assessing cloud-based service providers and modern technology environments.
  • Strong analytical, organizational, and communication skills.
  • Detail-oriented with the ability to manage multiple assessments simultaneously.
  • Self-motivated with a desire to continuously learn and develop expertise.


Compensation & Benefits

The organization offers a competitive compensation package that may include base salary, annual bonus opportunities, long-term incentive programs, and a comprehensive benefits package. Benefits include healthcare coverage, retirement savings programs, paid time off, parental leave, and additional wellness resources.


Work Environment

This position works in office Monday through Thursday with the option of Fridays at home.


PrincePerelson & Associates is an Equal Opportunity Employer and complies with all provisions of the EEO and ADA laws. We do not discriminate in our employment practices on the basis of race, color, religion, national origin, sex (including sexual orientation and sexual identity), age, genetic information, parental status, military status, disability, or any non-merit-based factors or other federal, state, or locally protected class. All applicants applying for U.S. job openings must be authorized to work in the United States.