1

Vendor Risk Resilience Analyst Jobs (NOW HIRING)

Maintain visibility into critical vendor resilience and BC/DR posture for high-impact suppliers ... Build, lead, and develop a high-performing team of vendor risk analysts; set objectives, coach ...

ABOUT THE ROLE The Information Security Client & Vendor Risk Manager leads the firm's client due ... Mentor junior analysts and contribute to the professional development of the broader Risk and ...

As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle-from tiering and onboarding to ...

$150 - $200/hr

... resilience capabilities, including Business Impact Analysis (BIA) and foundational BCDR program ... Vendor intake and risk tiering * Security assessments and due diligence * Ongoing monitoring and ...

... monitoring of vendor controls across multiple risk domains -including information security, privacy, business continuity, operational resilience, and compliance. The analyst leverages risk ...

As a Third-Party Risk Management Analyst, you will own security risk assessments for critical Samsara vendors and partners. You will oversee the complete lifecycle-from tiering and onboarding to ...

Vendor Analyst

Cleveland, OH ยท On-site

$60 - $80/hr

Conduct vendor due diligence reviews, risk assessments, and ongoing vendor monitoring activities ... Excellent analytical, organizational, and problem-solving skills.* Ability to manage multiple ...

Risk Analyst LOCATION: South Jordan or Spanish Fork, Utah GRADE: 11 (salary range 57,283-85,681 ... Vendor Risk Management program, including vendor due diligence, risk assessments, ongoing ...

Conduct vendor due diligence reviews, risk assessments, and ongoing vendor monitoring activities ... Excellent analytical, organizational, and problem-solving skills. * Ability to manage multiple ...

Showing results 41-60

Vendor Risk Resilience Analyst information

See salary details

$15

$40

$65

How much do vendor risk resilience analyst jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for vendor risk resilience analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What are popular job titles related to Vendor Risk Resilience Analyst jobs?

For Vendor Risk Resilience Analyst jobs, the most frequently searched job titles are:

Client & Vendor Risk Manager

Houston, TX โ€ข On-site

Baker Botts Llp
Law Firmsย โ€ขย 1 - 5K employees

Full-time

Re-posted 2 days ago


Job description

ABOUT BAKER BOTTS

Baker Botts is a leading international law firm recognized for its deep understanding of the industries it serves. With offices across major global markets, the firm delivers sophisticated legal services while cultivating a collaborative, inclusive culture where both attorneys and professional staff contribute to client success and organizational excellence.

ABOUT THE ROLE

The Information Security Client & Vendor Risk Manager leads the firmโ€™s client due diligence program and oversees all information security vetting for third party vendors across the firm. This role requires deep expertise in security frameworks, strong riskassessment judgment, and the ability to influence senior stakeholders, including internal stakeholders, and client security teams. The Manager acts as a key liaison between the firmโ€™s clients, internal leadership, IT Security, Procurement, and Risk Management, ensuring the firm meets the heightened expectations of our clients.

WHAT YOU'LL DO

Primary Responsibilities

  • Own and mature the firmwide client and vendor duediligence program, ensuring consistency, accuracy, and alignment with the firmโ€™s security posture and regulatory obligations.
  • Serve as the firmโ€™s subjectmatter expert on informationsecurity controls, certifications, and risk posture during client audits, RFPs, and reviews or client engagement terms.
  • Lead complex vendorrisk assessments for highimpact technology and service providers, including review of SOC 2 reports, ISO 27001 certifications, penetrationtest results, cloudsecurity controls, dataprotection, privacy, and retention practices.
  • Develop and maintain the firmโ€™s vendorrisk management framework, including riskscoring methodologies, onboarding workflows, and continuousmonitoring processes.
  • Partner with Procurement, IT, and Office of General Counsel to evaluate vendor contracts, negotiate security requirements, and recommend riskmitigation strategies.
  • Prepare the firm for client audits and regulatory reviews, coordinating evidence collection, documentation, and SME participation across multiple departments.
  • Represent the firm in clientfacing security discussions, including responding to escalated inquiries from corporate counsel, privacy officers, and client security teams.
  • Monitor emerging risks and regulatory developments relevant to the legal industry (e.g., SEC cybersecurity rules, state privacy laws, international datatransfer requirements).
  • Mentor junior analysts and contribute to the professional development of the broader Risk and Compliance team.
  • Drive continuous improvement, identifying opportunities to streamline duediligence workflows, enhance tracking and remediation of client-identified risks, and strengthen the firmโ€™s security posture.

Additional Responsibilities

  • Provide management with periodic reports & briefings on evolving topics within their area of responsibility.
  • Other related projects and duties as assigned by the Director of Information Security.

WHAT YOU'LL BRING

Required

  • 6+ years of experience in information security, vendor risk management, compliance, or legalindustry operations, ideally within an Am Law 200 firm or similarly regulated environment.
  • Deep understanding of security frameworks and standards (SOC 2, ISO 27001, NIST CSF, HIPAA, GLBA, state privacy laws).
  • Experience conducting or leading vendorrisk assessments for enterpriselevel technology providers.
  • Strong communication skills, including the ability to brief partners, respond to client security teams, and translate technical concepts for nontechnical audiences.
  • Demonstrated ability to work independently, manage sensitive information, and lead crossfunctional initiatives in a highpressure environment.
  • Professional certifications such as CTPRA, ISO 27001 Lead Implementer or Lead Auditor and CISSP, CISM, CRISC, or CISA required.
  • Experience with legalindustry technologies (DMS, ediscovery platforms, cloudbased practicemanagement tools) is a plus.

HOW YOU'LL WORK

Extent of Contact

This position requires contact with individuals within the firms as follows:

  • Daily contact with staff from the Firmโ€™s Information Technology, Client Development and Office of the General Counsel teams.
  • Moderate contact with Firmโ€™s attorneys and client representatives.
  • Occasional contact with Firm Management.

This position requires contact with individuals outside the firm as follows:

  • Moderate contact with Firm vendors or potential vendors.
  • Moderate contact with Firm clients

Physical Requirements

  • Must be able to routinely lift and carry event materials and other items up to 10 pounds.
  • Must be able to work at a computer for extensive periods of time.
  • Position requires extensive telephone use.
  • Must be able to lift, squat, kneel and bend.
  • Position requires the ability to visit face-to-face and on the phone with firm lawyers.

Working Conditions and Environment

  • Position is full-time and requires a five-day work week and standard hours as outlined in the Firm policy manual. Additional hours, including weekend and evening hours may be required to perform the essential functions of the job.
  • Must be able to perform essential duties of the position with time constraints and frequent interruptions.ย 
  • Ability to work well in high pressure environments.
  • 24x7 communication access is required.
  • This position is fully remote. You will be required to come to the office periodically for team meetings or when there is a business or client need.
  • There is potential for travel when needed for team meetings, onsite assessments etc. when there is a business or client need.
  • When working remotely, you must have secure and reliable internet service and a safe, private workspace from which to work.

Baker Botts L.L.P. is an equal opportunity employer and considers all qualified applicants for employment without regard to race, color, gender, sex, age, religion, creed, national origin, citizenship, marital status, sexual orientation, disability, medical condition, military and veteran status, gender identity or expression, genetic information, or any other basis protected by federal, state, or local law.