1

Vendor Risk Management Analyst Jobs (NOW HIRING)

RISK MANAGEMENT ANALYST

Beverly Hills, CA · On-site

$38.46 - $43.27/hr

We are seeking a Risk Management Analyst to join our Global Risk Management team in Beverly Hills, CA. This is an exciting opportunity to support a range of risk management activities across ...

Overview We are seeking a detail-oriented and analytical Risk Management Analyst to support our ... vendors or customers based on race, color, religion, creed, gender (including pregnancy status ...

New

Job Summary * - Provide support to risk managers for ongoing monitoring and reporting risk exposures * - Analyze existing and new business models and find out risks needed to be addressed * - Monitor ...

next page

Showing results 1-20

Vendor Risk Management Analyst information

See salary details

$36.5K

$82.3K

$138K

How much do vendor risk management analyst jobs pay per year?

As of Jun 28, 2026, the average yearly pay for vendor risk management analyst in the United States is $82,330.00, according to ZipRecruiter salary data. Most workers in this role earn between $62,500.00 and $90,500.00 per year, depending on experience, location, and employer.

What is a Vendor Risk Management Analyst?

A Vendor Risk Management Analyst is a professional responsible for assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. They evaluate vendor practices, ensure compliance with company policies and regulations, and help protect the organization from financial, operational, and reputational risks. Their work often involves conducting risk assessments, reviewing contracts, and collaborating with other departments to ensure vendors meet required security and performance standards.

What are the key skills and qualifications needed to thrive as a Vendor Risk Management Analyst, and why are they important?

To thrive as a Vendor Risk Management Analyst, you need expertise in risk assessment, third-party due diligence, and a solid understanding of compliance regulations, typically supported by a bachelor’s degree in business, finance, or a related field. Proficiency with risk management software, vendor management platforms, and knowledge of frameworks like ISO 27001 or SOC 2 are commonly required, along with certifications such as CTPRP or CISA. Strong analytical thinking, attention to detail, and effective communication skills are essential for building relationships and reporting risks clearly. These skills ensure organizations can identify, mitigate, and manage risks associated with third-party vendors, protecting operational integrity and regulatory compliance.

How does a Vendor Risk Management Analyst typically interact with other departments within an organization?

Vendor Risk Management Analysts often collaborate closely with departments such as Procurement, Legal, IT Security, and Compliance to assess and mitigate risks associated with third-party vendors. They facilitate information sharing, coordinate risk assessments, and ensure that contract terms align with the organization's risk tolerance. Regular communication and cross-functional meetings are common, as these analysts play a key role in ensuring that vendor relationships do not expose the organization to undue risk.

What is the difference between Vendor Risk Management Analyst vs Procurement Analyst?

AspectVendor Risk Management AnalystProcurement Analyst
CertificationsCertifications like CTPRP, CRISC, or vendor risk management coursesCPM, CPSM, or purchasing certifications
Work EnvironmentFocus on risk assessment, compliance, and vendor evaluationsFocus on sourcing, purchasing, and supplier negotiations
Industry UsageCommon in finance, healthcare, and technology sectorsPrevalent across manufacturing, retail, and corporate sectors

The main difference is that a Vendor Risk Management Analyst specializes in assessing and mitigating risks associated with vendors, ensuring compliance and security. In contrast, a Procurement Analyst primarily handles sourcing and purchasing activities. Both roles require analytical skills and industry knowledge but focus on different aspects of vendor and supply chain management.

More about Vendor Risk Management Analyst jobs
What cities are hiring for Vendor Risk Management Analyst jobs? Cities with the most Vendor Risk Management Analyst job openings:
What states have the most Vendor Risk Management Analyst jobs? States with the most job openings for Vendor Risk Management Analyst jobs include:
What job categories do people searching Vendor Risk Management Analyst jobs look for? The top searched job categories for Vendor Risk Management Analyst jobs are:
Infographic showing various Vendor Risk Management Analyst job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 83% Full Time, 15% Part Time, and 1% Temporary. Highlights an 90% Physical, 3% Hybrid, and 7% Remote job distribution, with an average salary of $82,330 per year, or $39.6 per hour.

Vendor Analyst, AI & Technology Risk

The Mutual Group

Dallas, TX • Hybrid

$85K - $110K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


Job description

Department:

Information Technology

Job Description:

Execute day-to-day operations of AI and Technology Risk Governance, with primary responsibility for vendor AI governance and detection across The Mutual Group and its member insurance carriers.

This is a fully hands-on individual contributor role responsible for ensuring vendor AI usage is identified, tracked, and routed through the AIS Program governance process. The role also supports broader governance activities across AI Systems, Cyber Security, Data Privacy (IT lens), and IT Controls.

Work Arrangement:

  • Employees who live within 30 miles of the TMG home office are expected to follow a hybrid or in-office schedule. The initial training period may require additional inoffice days.

Accountabilities:

Vendor AI Governance (Primary Focus)

  • Execute the vendor-wide AI detection process across the full vendor portfolio:

    • Conduct periodic vendor attestations

    • Track vendor disclosures, updates, and AI usage changes

  • Ensure vendors using AI are:

    • Identified promptly

    • Routed through the AIS Program review framework

  • Maintain and track:

    • Vendor AI inventory

    • FactSheet submissions and updates

  • Support Vendor Management in aligning with third-party risk requirements

AI Governance Operations

  • Support execution of AI intake and governance workflows:

    • Track AIA Forms and FactSheets

    • Ensure completeness and follow-ups

  • Perform initial triage for low-risk AI use cases

  • Support activities of the AIS / Security Governance Team, including documentation and workflow tracking

Monitoring & Validation Support

  • Support twice-annual AI system and vendor review cycles

  • Track:

    • Vendor AI changes

    • Model updates requiring re-review

  • Assist in ensuring monitoring outputs are captured and documented

Documentation & Controls

  • Maintain:

    • AI system inventory

    • Vendor AI tracking logs

    • Governance documentation and audit trails

  • Support:

    • Evidence collection for audits and regulatory reviews

    • Control documentation for IT and security governance

Broader Technology Risk Support (Secondary)

  • Support tracking and documentation for:

    • Cyber security governance activities (NIST CSF, NYDFS)

    • Data privacy controls (CCPA, IT lens)

    • IT general controls and risk register inputs

Reporting & Coordination

  • Assist with preparation of:

    • AIS Committee materials

    • Governance and vendor risk reports

  • Coordinate with:

    • Vendor Management

    • AI / Technology teams

    • Risk and Compliance teams


Qualifications:

  • 3+ years in risk, compliance, IT, security, or vendor risk management

  • Experience with TPRM and GRC tools (like Archer, ServiceNow, OneTrust, Upguard)

  • Experience supporting third-party risk or audit processes preferred

  • Familiarity with:

    • Vendor risk management practices

    • AI governance concepts (preferred)

    • NIST CSF, SOC 2, or similar frameworks

    • Data privacy concepts (CCPA preferred)

  • Strong attention to detail and process discipline

  • Ability to manage multiple workflows and follow-ups

Pay Range:

Anticipated Hiring Range:

  • $85,000 - $110,000 annual base salary depending on experience, qualifications, and geographic location

Benefits:

We are proud to offer our full-time regular employees a robust benefits suite that includes:

  • Competitive base salary plus incentive plans for eligible team members

  • 401(K) retirement plan that includes a company match of up to 6% of your eligible salary

  • Free basic life and AD&D, long-term disability and short-term disability insurance

  • Medical, dental and vision plans to meet your unique healthcare needs

  • Wellness incentives

  • Generous time off program that includes personal, holiday and volunteer paid time off

  • Flexible work schedules and hybrid/remote options for eligible positions

  • Educational assistance

Equal Opportunity Employer

The Mutual Groupis an Equal Opportunity Employer. It is our policy to recruit, hire, train and promote individuals in all job classifications without regard to race, color, religion, sex, national origin, age, veteran status, disability, sexual orientation, gender identity or any other characteristic protected by law.

  • Know Your Rights: Workplace Discrimination is Illegal

  • Your Rights Under USERRA

Applicants requiring a reasonable accommodation due to a disability at any stage of the employment application process should contactTalent@themutualgroup.com.

Employment Verification

The Mutual Group participates in theE-Verifyprogram and will provide the federal government with your Form I-9 information to confirm that you are authorized to work in the U.S. You are protected fromemployment discriminationbased on your citizenship status and national origin.

E-Verify Program Overview

E-Verify Participation Poster

All offers of employment are contingent upon the successful completion of a background check.

#TMG