1

Vendor Risk Management Jobs in Austin, TX (NOW HIRING)

Participate in due diligence on insurance and other risk management areas for M&A activity * Work with legal and procurement on insurance elements in customer and vendor contracts; develop insurance ...

... vendors, and senior leaders. Minimum Qualifications * Bachelor's degree in Risk Management, Insurance, Finance, Accounting, Business, Data Analytics, or related field; equivalent experience may be ...

... vendors, and senior leaders. Minimum Qualifications * Bachelor's degree in Risk Management, Insurance, Finance, Accounting, Business, Data Analytics, or related field; equivalent experience may be ...

... vendors, and senior leaders. Minimum Qualifications * Bachelor's degree in Risk Management, Insurance, Finance, Accounting, Business, Data Analytics, or related field; equivalent experience may be ...

next page

Showing results 1-20

Vendor Risk Management information

See Austin, TX salary details

$43.1K

$102.8K

$166K

How much do vendor risk management jobs pay per year?

As of Jul 26, 2026, the average yearly pay for vendor risk management in Austin, TX is $102,768.00, according to ZipRecruiter salary data. Most workers in this role earn between $71,800.00 and $130,800.00 per year, depending on experience, location, and employer.

What is the highest paying risk management job?

In risk management, senior roles such as Chief Risk Officer (CRO) or Director of Risk Management tend to have the highest salaries, often exceeding six figures annually. These positions require extensive experience, advanced certifications like FRM or CRM, and strong leadership skills, especially in financial services, insurance, or large corporations.

What is a vendor risk management job description?

A vendor risk management job involves assessing and monitoring the risks associated with third-party vendors to ensure compliance with security, legal, and operational standards. Responsibilities include conducting risk assessments, developing mitigation strategies, and maintaining vendor relationships, often using tools like risk management software. Strong analytical skills and knowledge of regulatory requirements are essential for this role.

What are the key skills and qualifications needed to thrive in the Vendor Risk Management position, and why are they important?

To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.

How much does a risk manager get paid?

A risk manager's salary typically ranges from $70,000 to $130,000 annually, depending on experience, industry, and location. Professionals with certifications like CRM or FRM and strong analytical skills tend to earn higher salaries, especially in financial services and corporate sectors.

What is vendor risk management?

Vendor risk management is a process used by organizations to identify, assess, and mitigate risks associated with third-party vendors. It involves evaluating vendors' security, compliance, and operational practices to ensure they do not pose threats to the organization’s data, reputation, or operations, often supported by tools like risk assessment frameworks and requiring ongoing monitoring.

What is a Vendor Risk Management job?

A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.

What are some common challenges faced in a Vendor Risk Management role?

Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

What are the most commonly searched types of Vendor Risk Management jobs in Austin, TX? The most popular types of Vendor Risk Management jobs in Austin, TX are:
What are popular job titles related to Vendor Risk Management jobs in Austin, TX? For Vendor Risk Management jobs in Austin, TX, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Management jobs in Austin, TX look for? The top searched job categories for Vendor Risk Management jobs in Austin, TX are:
What cities near Austin, TX are hiring for Vendor Risk Management jobs? Cities near Austin, TX with the most Vendor Risk Management job openings:
Infographic showing various Vendor Risk Management job openings in Austin, TX as of July 2026, with employment types broken down into 1% As Needed, 82% Full Time, 13% Part Time, 1% Temporary, and 3% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $102,768 per year, or $49.4 per hour.
Cybersecurity Governance & Risk Analyst

Cybersecurity Governance & Risk Analyst

Texas Health and Human Services Commission

Austin, TX • On-site

$7.0K - $10K/mo

Full-time

Medical, Retirement, PTO

Posted 4 days ago


Texas Health and Human Services rating

7.1

Company rating: 7.1 out of 10

Based on 31 frontline employees who took The Breakroom Quiz

636th of 832 rated public administrative organizations


Job description

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage.
Functional Title: Cybersecurity Governance & Risk Analyst Job Title: Cybersecurity Analyst III Agency: Health & Human Services Comm Department: IT Security Posture EI Posting Number: 18992 Closing Date: 08/22/2026 Posting Audience: Internal and External Occupational Category: Computer and Mathematical Salary Range: $7,015.16- $10,472.33 Pay Frequency: MonthlySalary Group: TEXAS-B-27 Shift: Day Additional Shift: Telework: Not Eligible for Telework Travel: Regular/Temporary: Regular Full Time/Part Time: Full time FLSA Exempt/Non-Exempt: Exempt Facility Location: Job Location City: AUSTIN Job Location Address: 701 W 51ST ST Other Locations: Austin MOS Codes: 0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A
170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D
26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT
CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS
This position is open to permanent residents or US citizens only.
The Cybersecurity Analyst III performs senior-level security work with emphasis on cloud security, web application protection, and governance, risk, and compliance (GRC). The role supports on-premises and cloud environments by evaluating, implementing, and monitoring security controls to protect agency systems and data.
Governance & Risk role is responsible for leading the enterprise cybersecurity governance framework and enterprise risk-management activities to ensure full alignment with legislative mandates, NIST 800-53, HIPAA, and State of Texas DIR mandates. This position provides senior-level expertise in secure architecture standards, vendor risk management, and data governance. Ensuring that cybersecurity policies, controls, and risk-management practices are upheld and aligned with State of Tx DIR, NIST 800-53, agency objectives, and regulatory requirements.
The Governance & Risk Analyst advises on regulatory changes, develops the enterprise system risk posture, stays current with industry's best practices and emerging technologies, participates in compliance and regulatory audits, and supports the implementation of enterprise security improvements. This position serves as a critical architect of the agency's security policy framework, ensuring that every vendor, system architecture, and data flow aligns with legislative requirements and adheres to agency governance standards.
This position performs highly complex information security and cybersecurity analysis work. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment. May research and implement new security risk and mitigation strategies, tools, techniques, and solutions for the prevention, detection, containment, and correction of data security breaches. Reviews penetration testing results, supports vulnerability remediation efforts, and uses security tools to evaluate and track risk.
The Analyst also provides expert guidance on HHS Security Policy, TAC 202, HIPAA, and other applicable regulations; partners with program, security, project managers, and technical teams; and supports staff on security, risk, and compliance matters.
Essential Job Functions (EJFs):
Attends work on a regular and predictable schedule following agency leave policy and performs other duties as assigned.
Cyber Governance - 30%
  • Performs reviews and risk management for vendors, system architectures, and data flows to advise and help teams comply with governance and regulatory standards.
  • Reviews regulatory and legislative changes and develops roadmaps for required updates to policy and governance structures. Ensures alignment with NIST 800-53, State of Texas DIR mandates, HIPAA, TAC 202, and agency legislative requirements.
  • Using established risk management methodologies, identifies enterprise policy or control needs, and evaluates the effectiveness of security solutions across assigned governance areas.

Enterprise Risk Management - 25%
  • Develops and maintains the enterprise system risk posture, including risk identification, assessment, metrics, and documentation.
  • Oversees vendor risk management activities, including third-party assessments, contract security requirements, and ongoing monitoring.
  • Ensures risk-management practices are aligned with agency objectives and federal/state requirements.
  • Develop vendor, procurement, or supply chain training. Promotes secure system and data safeguards.

Security Architecture, Advisory, & Collaboration - 25%
  • Provides senior-level guidance on secure architecture, cloud security, and application protection; evaluates and monitors security controls to protect agency systems and data.
  • Advises programs and technical teams on security technical compliance, governance requirements; supports enterprise security improvement initiatives.
  • Uses established standards and processes to adequately protect Health and Human Services (HHS) personnel, facilities, cloud infrastructure, information, and business operations.
  • Provide leadership and mentorship to other security analysts, offering guidance in performing assessments, implementing controls, and carrying out security functions.

Program Oversight & Strategy - 10%
  • Incorporates audit findings and identified security gaps into remediation planning; assists with special projects, documentation updates, and process improvements as assigned.
  • Reviews project charters, provides input on strategic initiatives, and assists with planning activities that strengthen the agency's cybersecurity posture.

Other duties - 10%
Performs additional cybersecurity, governance, and risk-related tasks as assigned, including supporting special projects, contributing to process improvements, and assisting with agency initiatives that enhance overall security posture.
Knowledge Skills Abilities (KSAs):
Knowledge of:
  • Information security risk assessment and security assessment methodologies, processes, and audit practices.
  • Security program policies, standards, controls, and procedural requirements.
  • Networking, operating systems, applications, databases, and related technologies, including wireless and mobile environments.
  • Incident response concepts, practices, and procedures.
  • Secure Software/System Development Lifecycle (S-SDLC) methodologies.
  • Regulatory and compliance requirements, including HIPAA/HITECH, PCI, SOX, TAC 202, IRS Publication 1075, Texas Business and Commerce Code, and Texas Health and Safety Code.
  • Security and risk management frameworks such as NIST, SANS, HITRUST, ISO, and COBIT.

Skill in:
  • Written and verbal communication.
  • Analyzing and solving complex problems and quickly understanding technical concepts.
  • Developing, implementing, and maintaining information security policies, standards, and controls.
  • Performing risk assessments, security assessments, and audits.
  • Evaluating risks and identifying mitigation strategies, including defining compensating controls.

Ability to:
  • Interpret and apply regulatory, policy, and security framework requirements.
  • Communicate technical information to both technical and non-technical audiences.
  • Work collaboratively with diverse teams and guide others in information security practices.

Registrations, Licensure Requirements, or Certifications:
Prefer one or more of the following certifications:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Systems Manager (CISM)
  • Global Information Assurance Certification (GIAC)
  • Project Management Professional (PMP)

Initial Screening Criteria:
  • Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, management information systems, or a related field is strongly preferred. Education and experience may be substituted for one another.
  • At least 5+ years of experience in information technology, security risk, management, assessment, auditing, project management, or consulting.
  • Experience in researching, authoring, or supporting the development of information security policies and standards.
  • Experience developing security and risk performance metrics and reporting dashboards for executive, business, and technical audiences.

Additional Information:
Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.
This is an onsite position in Austin Tx.
Any employment offer is contingent upon available budgeted funds and background check. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual.
Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC.
Active Duty, Military, Reservists, Guardsmen, and Veterans:
Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active-duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor's Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditor's Office - Job Descriptions.
ADA Accommodations:
In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on-line application, contact the HHS Employee Service Center at 1-888-894-4747. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview.
Pre-Employment Checks and Work Eligibility:
Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks.
HHSC uses E-Verify. You must bring your I-9 documentation with you on your first day of work. Download the I-9 Form
Telework Disclaimer:
This position may be eligible for telework. Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs.

What Texas Health and Human Services employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom