Maintain vendor risk inventory and supporting documentation * Assist in preparing reports for management and regulatory exams * Escalates overdue remediation items and unresolved control gaps.
Maintain vendor risk inventory and supporting documentation * Assist in preparing reports for management and regulatory exams * Escalates overdue remediation items and unresolved control gaps.
Senior Cybersecurity Risk Analyst - USA Remote
Phoenix, AZ · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Senior Cybersecurity Risk Analyst - USA Remote
Phoenix, AZ · Remote
$130K - $160K/yr
Execute the third-party risk management (TPRM) lifecycle end-to-end, including vendor intake, inherent-risk tiering, security and privacy questionnaire administration, evidence collection and review ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Senior Consultant, Ongoing Monitoring, Alerts & Triggers - Third Party Risk Management
Tempe, AZ · On-site
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Senior Consultant, Ongoing Monitoring, Alerts & Triggers - Third Party Risk Management
Tempe, AZ · On-site
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Senior Consultant, Ongoing Monitoring, Alerts & Triggers - Third Party Risk Management
Tempe, AZ · On-site
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Senior Consultant, Ongoing Monitoring, Alerts & Triggers - Third Party Risk Management
Tempe, AZ · On-site
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Engage with risk domain SME's, vendors and vendor relationship managers * Serve as the point of contact for program performance updates, risk issue escalations, and regulatory reviews * Responsible ...
Work closely with the IT department and external vendors to enhance and optimize the RMIS system ... Support Risk Management team on various tasks required and cover on team members while out of ...
Quick apply
Work closely with the IT department and external vendors to enhance and optimize the RMIS system ... Support Risk Management team on various tasks required and cover on team members while out of ...
Work closely with the IT department and external vendors to enhance and optimize the RMIS system ... Support Risk Management team on various tasks required and cover on team members while out of ...
Work closely with the IT department and external vendors to enhance and optimize the RMIS system ... Support Risk Management team on various tasks required and cover on team members while out of ...
Sr. Specialist, Risk Management Litigation
Phoenix, AZ · On-site
$97K/yr
Work closely with the IT department and external vendors to enhance and optimize the RMIS system ... Support Risk Management team on various tasks required and cover on team members while out of ...
Sr. Specialist, Risk Management Litigation
Phoenix, AZ · On-site
$97K/yr
Work closely with the IT department and external vendors to enhance and optimize the RMIS system ... Support Risk Management team on various tasks required and cover on team members while out of ...
Overseas Contractor
Scottsdale, AZ · On-site
Risk Management * Audit Management * Vendor Risk Management * Customize UI elements (forms, fields, lists, dashboards, portals) and automate workflows using client/server scripts. * Integrate ...
Overseas Contractor
Scottsdale, AZ · On-site
Risk Management * Audit Management * Vendor Risk Management * Customize UI elements (forms, fields, lists, dashboards, portals) and automate workflows using client/server scripts. * Integrate ...
GRC Analyst
Phoenix, AZ · On-site
Strong experience in SaaS assessments, vendor risk management, or cloud security. * Good understanding of shared responsibility models across cloud providers. * Knowledge of regulatory and control ...
Quick apply
GRC Analyst
Phoenix, AZ · On-site
Strong experience in SaaS assessments, vendor risk management, or cloud security. * Good understanding of shared responsibility models across cloud providers. * Knowledge of regulatory and control ...
... risk management strategies, audits, and ensure regulatory compliance. - Manage budgets of up to ... vendor governance and contract management. - Strong knowledge of risk management, audits, and ...
New
... risk management strategies, audits, and ensure regulatory compliance. - Manage budgets of up to ... vendor governance and contract management. - Strong knowledge of risk management, audits, and ...
New
Vendor Oversight & Risk Management * Provide ongoing monitoring and oversight of critical/high-priority vendors, ensuring adherence to contractual obligations, KPIs, SLAs, and financial targets.
Vendor Oversight & Risk Management * Provide ongoing monitoring and oversight of critical/high-priority vendors, ensuring adherence to contractual obligations, KPIs, SLAs, and financial targets.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
Own the third-party risk framework and partner across Procurement, Finance, Legal, Cyber, Risk, and Technology to strengthen vendor governance, manage risk, and inform long-term investment decisions.
As Risk Director, you'll lead the enterprise-wide risk management program -- from insurance ... Oversee subcontractor and vendor Certificate of Insurance (COI) compliance and manage OCIP/CCIP ...
Quick apply
As Risk Director, you'll lead the enterprise-wide risk management program -- from insurance ... Oversee subcontractor and vendor Certificate of Insurance (COI) compliance and manage OCIP/CCIP ...
Vendor Risk Management information
See Arizona salary details
$40.5K - $51K
8% of jobs
$51K - $61.5K
14% of jobs
$66.4K is the 25th percentile. Wages below this are outliers.
$61.5K - $72.1K
6% of jobs
$72.1K - $82.6K
8% of jobs
$82.6K - $93.1K
11% of jobs
The median wage is $95.3K / yr.
$93.1K - $103.6K
13% of jobs
$103.6K - $114.1K
11% of jobs
$117.3K is the 75th percentile. Wages above this are outliers.
$114.1K - $124.6K
15% of jobs
$124.6K - $135.1K
8% of jobs
$135.1K - $145.6K
4% of jobs
$145.6K - $156.1K
2% of jobs
$40.5K
$96.6K
$156.1K
How much do vendor risk management jobs pay per year?
What is the highest paying risk management job?
What is a vendor risk management job description?
What are the key skills and qualifications needed to thrive in the Vendor Risk Management position, and why are they important?
To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.
How much does a risk manager get paid?
What is vendor risk management?
What is a Vendor Risk Management job?
A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.
What are some common challenges faced in a Vendor Risk Management role?
Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.
Other
Medical, Dental, Vision, Retirement, PTO
Posted 14 days ago
OneAZ Credit Union rating
8.1
Based on 5 frontline employees who took The Breakroom Quiz
Job description
Join Us in Making an Impact
At OneAZ Credit Union, our success is measured only by yours. We're here to create lasting change in the lives of our members, our communities, and our team. If you're looking for a career with purpose, where your work truly matters-you've found it!
Who You Are
You're impactful, compassionate, and fearless, ready to embrace new challenges and shape the future of financial well-being. You take accountability for our success and thrive in an environment where curiosity is celebrated. If this sounds like you, let's build something great together.
What You'll Do
This position will be located at our Corporate Office: 2355 W Pinnacle Peak Rd, Phoenix, AZ 85027
- Perform risk-based due diligence and ongoing monitoring of third-party vendors
- Review and analyze Security questionnaires
- Review and analyze SOC 1 / SOC 2 reports
- Review and analyze Business continuity and disaster recovery documentation
- Document vendor risk assessments and identify control gaps
- Drive remediation efforts and follow up with business owners and vendors
- Maintain vendor risk inventory and supporting documentation
- Assist in preparing reports for management and regulatory exams
- Escalates overdue remediation items and unresolved control gaps.
- Support coordination of incident response activities (cybersecurity, and security/operational incidents)
- Track incidents from identification through resolution
- Manage incident documentation, evidence tracking, and record maintenance
- Assist in post-incident reviews, including root cause analysis and lessons learned
- Support development and maintenance of incident response procedures and playbooks
- Participate in incident response testing and tabletop exercises
- Compile and maintain reporting on Vendor risk assessments and outstanding issues
- Compile and maintain reporting on Incident trends and metrics
- Coordinate with IT and compliance teams to ensure timely execution of security operational requirements.
- Ensure documentation is complete, organized, and audit-ready
- Identify and deliver security training programs to employees, promoting best practices and enhancing the organization's security posture.
- Review penetration testing and security. Perform ongoing analysis of security systems logs and intrusion detection tools/procedures.
- Monitor changes in the security industry including new vulnerabilities, viruses, intrusions, fraud schemes, and best practices and tools available for system/network protection. Recommend appropriate technical changes to maintain designated security protection levels
What You Bring
- High School Diploma or GED Required
- Bachelors Degree in Business, Information Security, Risk Management, or related field (or equivalent experience)
- 3-5 years similar or related experience in one or more areas: Vendor/Third-Party Risk Management, Information Security or IT Risk, Incident Management or Incident Response
- Understanding of vendor risk management and due diligence practices
- Familiarity with SOC reports and basic control frameworks
- Working knowledge of incident response lifecycle and documentation
- Strong attention to detail and documentation discipline
- Ability to manage multiple priorities and meet deadlines
- Effective written and verbal communication skills
- Demonstrated ability to independently manage operational security tasks and drive follow-through across stakeholders.
- Strong written and verbal communication with consistent escalation and status reporting discipline.
Compensation & Benefits
- Generous paid time off: paid holidays, floating holidays, personal days, vacation days, plus sick time, Low-cost Medical, Dental & Vision plans
- Paid childcare assistance
- Award-winning 401K
- Gym fee reimbursement
- Tuition Reimbursement
- Student loan repayment
- ...and much more. Explore all the details in our comprehensive Benefits Booklet
- Target hiring range $84,149.19 - $105,186.49 (Depending on experience and prior to any incentives this position is eligible for)
Why Join OneAZ?
At OneAZ, we're not just a credit union; we're a financial trailblazer that passionately cares about inspiring dreams and driving prosperity in the communities we serve. We exist to clear the way for dreamers and doers, aspiring to be the bank for new pioneers.
We are driving change in our communities, constantly improving our products and services so our members and their families can relentlessly pursue their dreams. By embodying our values and living our promise, you'll be part of a team committed to exceeding expectations and redefining what's possible.
Additional Notes:
Knowingly submitting false information will result in disqualification for consideration of future positions, termination of employment and forfeiture of other rights. Candidates for this position will be required to sign an authorization for OneAZ to conduct a credit and criminal background check, pursuant to procedures in the Fair Credit Reporting Act and any other applicable laws. All candidates will be considered for this position on an individualized basis, in compliance with all applicable equal employment opportunity laws. Any individual who meets the definition of a mortgage loan originator (MLO) and is employed by a federal agency-regulated institution will need to be registered on the Nationwide Mortgage Licensing System (NMLS). Ensures compliance with applicable policies, laws, and regulations, including the Bank Secrecy Act (BSA), Anti-Money Laundering (AML) compliance, USA Patriot Act, and Office of Foreign Assets Control (OFAC). This job description should not be considered all-inclusive. It is merely a guide of expected duties. The associate understands that the job description is neither complete, nor permanent and may be modified at any time. At the request of their supervisor, an associate may be asked to perform additional duties or take on additional responsibilities without notice. Complies with all policies and standards. Position grades could fluctuate based on market value.
What OneAZ Credit Union employees say
Pay
Hours and flexibility
Workplace
Get the full story on Breakroom
About OneAZ Credit Union
Sourced by ZipRecruiter
Industry
Commercial banking
Company size
201 - 500 Employees
Headquarters location
Phoenix, AZ, US
Year founded
1951