1

Vendor Risk Management Jobs in Raleigh, NC (NOW HIRING)

Conduct third-party vendor risk assessments and internal risk evaluations; identify, document, and ... Bachelor's degree in information security assurance, business management, or a related field * 3+ ...

Conduct third-party vendor risk assessments and internal risk evaluations; identify, document, and ... Bachelor's degree in information security assurance, business management, or a related field * 3+ ...

... vendors and third-party service providers, and (c) ensuring compliance with regulatory requirements ... Leverage industry insights to influence enterprise technology talent management through ...

Risk Analyst

Raleigh, NC · On-site

$110 - $140/hr

... wealth management, and insurance sectors. If you're passionate about AI and eager to make a ... Act as liaison with onsite, offshore, and vendor teams to document project requirements, ensuring ...

Showing results 21-40

Vendor Risk Management information

See Raleigh, NC salary details

$42.3K

$100.8K

$162.8K

How much do vendor risk management jobs pay per year?

As of Sep 6, 2026, the average yearly pay for vendor risk management in Raleigh, NC is $100,803.00, according to ZipRecruiter salary data. Most workers in this role earn between $70,500.00 and $128,300.00 per year, depending on experience, location, and employer.

What is vendor risk management?

A Vendor Risk Management (VRM) job involves assessing, monitoring, and mitigating risks associated with third-party vendors and suppliers. Professionals in this role evaluate vendor security, compliance, and operational risks to protect their organization from potential disruptions, data breaches, or regulatory violations. They work closely with procurement, legal, and IT teams to establish risk management frameworks and ensure vendors meet contractual and security standards. Their responsibilities often include conducting risk assessments, reviewing vendor contracts, and developing risk mitigation strategies. Effective VRM helps organizations reduce exposure to risks while maintaining productive vendor relationships.

What are some common challenges faced in vendor risk management?

Professionals in Vendor Risk Management often encounter the challenge of assessing and monitoring a wide range of vendors, each with unique risk profiles and compliance requirements. Balancing multiple projects, managing deadlines, and ensuring clear communication between internal stakeholders and vendors can also be demanding. Staying updated on evolving regulatory standards and quickly adapting to new risks is essential in this role. Overcoming these challenges requires strong organizational skills, continual learning, and proactive relationship management.

What are the key skills and qualifications needed to thrive in vendor risk management?

To thrive in Vendor Risk Management, you need a solid background in risk assessment, contract analysis, and supply chain management, often supported by a degree in business, finance, or a related field. Familiarity with risk management software, vendor management systems, and relevant certifications such as Certified Third Party Risk Professional (CTPRP) are highly valued. Strong attention to detail, excellent communication, and negotiation skills help build effective vendor relationships and navigate complex scenarios. These capabilities are crucial for ensuring organizational compliance, minimizing third-party risks, and maintaining strong supplier performance.

How to do vendor risk management?

Vendor risk management involves identifying, assessing, and mitigating risks associated with third-party vendors to ensure they meet security, compliance, and performance standards. It typically includes conducting due diligence, evaluating vendor controls, and monitoring ongoing performance using tools like risk assessment frameworks and audits. Strong communication and documentation are essential for effective management.

What does a vendor risk management do?

A vendor risk management professional assesses and monitors the risks associated with third-party vendors to ensure compliance, security, and operational integrity. They evaluate vendor security practices, contractual obligations, and potential vulnerabilities, often using risk assessment tools and frameworks to mitigate potential threats to the organization.

What are the most commonly searched types of Vendor Risk Management jobs in Raleigh, NC?

The most popular types of Vendor Risk Management jobs in Raleigh, NC are:

What are popular job titles related to Vendor Risk Management jobs in Raleigh, NC?

For Vendor Risk Management jobs in Raleigh, NC, the most frequently searched job titles are:

What job categories do people searching Vendor Risk Management jobs in Raleigh, NC look for?

The top searched job categories for Vendor Risk Management jobs in Raleigh, NC are:

What cities near Raleigh, NC are hiring for Vendor Risk Management jobs?

Cities near Raleigh, NC with the most Vendor Risk Management job openings:

Infographic showing various Vendor Risk Management job openings in Raleigh, NC as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, and 2% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $100,803 per year, or $48.5 per hour.

HCS Info Security Analyst Sr

UNC Health Careers

Morrisville, NC • On-site

$44.56 - $64.06/hr

Full-time

Posted 5 days ago


Key responsibilities

  • Conduct security reviews of research projects, applications, and data environments.

  • Assess vendor security questionnaires, attestations, and compliance documentation.

  • Review data flows, access controls, authentication methods, and encryption practices.


UNC Health rating

7.0

Company rating: 7.0 out of 10

Based on 321 frontline employees who took The Breakroom Quiz

421st of 898 rated healthcare providers


Job description

Description

Your passion belongs at UNC Health. Join more than 56,000 teammates working together to improve the health and well-being of the communities we serve across North Carolina.

Summary:
The Information Security Analyst Sr. supports research and Trusted Research Environment (TRE) initiatives by ensuring that research systems, data, and third-party services meet organizational security, privacy, and compliance requirements. This role partners with research teams, IT, legal, privacy, and vendors to assess risks, implement security controls, and support secure handling of sensitive data.

Responsibilities:

  • Conduct security reviews of research projects, applications, and data environments. This can include software packages, In-house developed applications, Cloud architecture proposals. 
  • Assess vendor security questionnaires, attestations, and compliance documentation. 
  • Evaluate research systems for compliance with organizational security standards and regulatory requirements. 
  • Collaborate with researchers, project managers, infrastructure teams, and compliance stakeholders. 
  • Review data flows, access controls, authentication methods, and encryption practices. 
  • Document risks, recommendations, and mitigation plans. 
  • Assist with incident response activities involving research systems or sensitive data. 
  • Track remediation activities and provide security consultation throughout project lifecycles. 
  • Support audits and reporting related to HIPAA, NIST, ISO 27001, SOC 2, and other applicable frameworks. 

Preferred Qualifications:

  • Strong hands-on experience in Azure Cloud Security and Information Security. 
  • Practical experience with Microsoft Defender for Cloud and Azure security services. 
  • Knowledge of healthcare data compliance frameworks (HIPAA, HITECH, NIST 800-53, SOC, HITRUST, CIS Benchmarks). 
  • Understanding cloud security concepts (Azure, AWS, or GCP). 
  • Strong written and verbal communication skills. 
  • Deep understanding of Azure TRE architecture, enclave boundaries, airlock mechanisms, and isolated cloud workspaces. 
  • Advanced proficiency in Microsoft Purview (DLP, Information Protection, eDiscovery, Insider Risk Management). 
  • Understanding of KQL log analytics and scripting (PowerShell/Python) for security automation. 
  • Embed security into DevSecOps and Secure SDLC, including threat modelling, security requirements, code/IaC/container scanning, secrets management, vulnerability remediation, and CI/CD security gates.
  • Experience supporting healthcare, academic, or research environments. 
  • Familiarity with research governance and handling of sensitive or regulated data. 
  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent. 
  • Experience with vendor risk management and third-party security reviews. 
Other Information

Education Requirements:
Bachelor's degree in Computer Science, Information Systems Management or a related field (or an equivalent combination of education, training and experience) required.
Licensure/Certification Requirements:

  • No licensure or certification required.
  • Security certifications such as CISSP, CISM, CRISC, Security+, HCISPP, or equivalent are preferred.

Professional Experience Requirements:
If a Bachelor's degree: Eight (8) years in professional IT positions, with 4 years of experience in related job functions required.
If an Associate's degree: Twelve (12) years in professional IT positions, with 4 years of experience in related job functions required.
If a high school diploma or GED: Sixteen (16) years in professional IT positions, with 4 years of experience in related job functions required.
Knowledge/Skills/and Abilities Requirements:

Key Competencies: 

  • Risk assessment and analysis 
  • Security governance and compliance 
  • Vendor and third-party risk management 
  • Research data protection 
  • Stakeholder communication 
  • Documentation and reporting 
  • Project coordination 

Success Measures:

  •  Timely completion of security reviews and risk assessments. 
  • Effective identification and mitigation of security risks. 
  • High-quality documentation and stakeholder engagement. 
  • Compliance with organizational and regulatory requirements. 
  • Successful support of research and TRE initiatives while maintaining security standards. 

Job Details

Legal Employer: NCHEALTH

Entity: Shared Services

Organization Unit: ISD Information Security

Work Type: Full Time

Standard Hours Per Week: 40.00

Salary Range: $44.56 - $64.06 per hour (Hiring Range)

Pay offers are determined by experience and internal equity

Work Assignment Type: Hybrid

Work Schedule: Day Job

Location of Job: US:NC:Morrisville

Exempt From Overtime: Exempt: Yes


This position is employed by NC Health (Rex Healthcare, Inc., d/b/a NC Health), a private, fully-owned subsidiary of UNC Health Care System, in a department that provides shared services to operations across UNC Health Care; except that, if you are currently a UNCHCS State employee already working in a designated shared services department, you may remain a UNCHCS State employee if selected for this job.


Qualified applicants will be considered without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, disability, status as a protected veteran or political affiliation.
UNC Health makes reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as applicants and employees with disabilities. All interested applicants are invited to apply for career opportunities. Please email applicant.accommodations@unchealth.unc.edu if you need a reasonable accommodation to search and/or to apply for a career opportunity.

Employment Type:

What UNC Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom