1

Vendor Risk Management Jobs in Connecticut (NOW HIRING)

Director, Treasury

Hartford, CT · On-site

$170K - $200K/yr

This role partners closely with Finance, Investments, Risk Management, Actuarial, Corporate ... Lead periodic treasury service provider reviews and vendor governance activities. Capital Markets ...

Showing results 21-40

Vendor Risk Management information

See Connecticut salary details

$41.4K

$98.7K

$159.3K

How much do vendor risk management jobs pay per year?

As of Aug 22, 2026, the average yearly pay for vendor risk management in Connecticut is $98,652.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,000.00 and $125,600.00 per year, depending on experience, location, and employer.

What is vendor risk management?

A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.

What are some common challenges faced in vendor risk management?

Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

What are the key skills and qualifications needed to thrive in vendor risk management?

To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.

How to do vendor risk management?

Vendor risk management involves identifying, assessing, and mitigating risks associated with third-party vendors to ensure they meet security, compliance, and performance standards. It typically includes conducting due diligence, evaluating vendor controls, and monitoring ongoing performance using tools like risk assessment frameworks and audits. Strong communication and documentation are essential for effective management.

What does a vendor risk management do?

A vendor risk management professional assesses and monitors the risks associated with third-party vendors to ensure compliance, security, and operational integrity. They evaluate vendor security practices, contractual obligations, and potential vulnerabilities, often using risk assessment tools and frameworks to mitigate potential threats to the organization.

What are the most commonly searched types of Vendor Risk Management jobs in Connecticut?

The most popular types of Vendor Risk Management jobs in Connecticut are:

What are popular job titles related to Vendor Risk Management jobs in Connecticut?

For Vendor Risk Management jobs in Connecticut, the most frequently searched job titles are:

What job categories do people searching Vendor Risk Management jobs in Connecticut look for?

The top searched job categories for Vendor Risk Management jobs in Connecticut are:

Infographic showing various Vendor Risk Management job openings in Connecticut as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 13% Part Time, 2% Temporary, and 4% Contract. Highlights an 84% Physical, 3% Hybrid, and 13% Remote job distribution, with an average salary of $98,652 per year, or $47.4 per hour.

Senior Cyber Security & GRC Engineer

Emergent Software

Hartford, CT • On-site

$140 - $180/hr

Other

Posted 23 days ago


Job description

**This position is a direct hire for one of our clients. Our ideal candidates live in the Hartford, Connecticut metro area. East coast & TX candidates will be considered with expectations of occasional travel to Connecticut. Eligible candidates must currently reside in the US and authorized to work in the US without visa sponsorship.**

Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations. This is a senior-level, hands‑on leadership role responsible for developing a unified security and compliance framework that supports NIST CSF 2.0, GDPR, and SOX IT General Controls requirements.

The ideal candidate combines strategic leadership with technical expertise, comfortably engaging executive stakeholders and auditors while also administering security tools, managing risks, implementing controls, and driving compliance initiatives. This role will serve as the owner of the enterprise GRC platform, Vanta, ensuring continuous monitoring, audit readiness, and program maturity across all entities.

Responsibilities
  • Own and mature the enterprise cybersecurity and risk management program across a multi-entity organization.
  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.
  • Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings.
  • Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters.
  • Administer and optimize Vanta as the enterprise GRC system of record.
  • Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta.
  • Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes.
  • Lead SOX ITGC readiness and compliance efforts.
  • Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response.
  • Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
  • Manage enterprise risk assessments, risk registers, third‑party vendor risk programs, and remediation initiatives.
  • Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on‑premises environments.
  • Lead incident response activities, including preparation, detection, containment, recovery, and post‑incident reviews.
  • Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms.
  • Build and manage security awareness, phishing simulation, and employee training programs.
  • Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.
  • 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities.
  • Hands‑on experience administering a GRC platform, preferably Vanta.
  • Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements.
  • Demonstrated success developing and implementing security policies, controls, and governance programs.
  • One or more of the following certifications: CISSP, CISM, CRISC, or CISA.
  • Strong technical knowledge of cloud security, identity and access management, endpoint security, vulnerability management, logging, and security operations.
  • Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives.
  • Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders.
Nice to Have Experience
  • Direct Vanta administration experience.
  • Experience supporting a publicly traded company and SOX Section 404 compliance requirements.
  • Experience leading security programs across multiple organizations or business entities.
  • ISO 27001 Lead Implementer or Lead Auditor certification.
  • SANS/GIAC certifications.
  • Construction, engineering, energy, power generation, or EPC industry experience.
  • Familiarity with AI/ML governance, data security, and secure AI deployment practices.
Our Vetting Process

At Emergent Staffing, we work hard to find the best tech candidates capable of developing high quality results for our clients. If you think you're one of those, please understand that the effort put into this by people like yourself helps us be successful in surrounding you with other top‑notch engineers. Here are the steps of our vetting process for this position:

  • Application (5 minutes)
  • Online Assessment (60 minutes)
  • Initial Phone Interview (30-45 minutes)
  • Virtual Interview with Hiring Manager (30 minutes)
  • Onsite Interview
  • Leadership Team Meeting (if needed)
  • Job Offer!

#EmergentStaffing

#IND99


#J-18808-Ljbffr