1

Vendor Risk Jobs in Virginia (NOW HIRING)

Risk Manager

Mclean, VA · On-site

$55 - $60/hr

Provide strategic thinking on next levels of maturity in Technology & Vendor Risk management * Act as a cross functional partner in the deployment of our information security program within the ...

Support critical third-party vendor risk management activities * Develop, enhance, and maintain critical technology solutions to support corporate-wide AI adoptions * Execute risk mitigant processes ...

Support critical third-party vendor risk management activities * Develop, enhance, and maintain critical technology solutions to support corporate-wide AI adoptions * Execute risk mitigant processes ...

Strong understanding of security and IT risk domains (identity and access, change/configuration, secure engineering, vendor risk, cloud controls, incident response, logging/monitoring, data ...

next page

Showing results 1-20

Vendor Risk information

What is the difference between Vendor Risk vs Vendor Compliance?

AspectVendor RiskVendor Compliance
FocusIdentifying and mitigating risks associated with vendorsEnsuring vendors meet regulatory and contractual requirements
CertificationsRisk management certifications (e.g., CRISC, FAIR)Compliance certifications (e.g., ISO 27001, SOC 2)
Work EnvironmentRisk assessment teams, procurement, security departmentsLegal, compliance, audit teams
Industry UsageFinancial, healthcare, technology sectorsFinancial services, healthcare, regulated industries

Vendor Risk and Vendor Compliance roles often overlap but serve different purposes. Vendor Risk focuses on identifying and mitigating potential risks posed by vendors, while Vendor Compliance ensures vendors adhere to legal and contractual standards. Both are essential for managing vendor relationships effectively and maintaining organizational security and compliance.

What cities in Virginia are hiring for Vendor Risk jobs? Cities in Virginia with the most Vendor Risk job openings:
Infographic showing various Vendor Risk job openings in Virginia as of August 2026, with employment types broken down into 1% As Needed, 88% Full Time, 8% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Procurement Risk & Compliance Lead

S&P Global

Centreville, VA • On-site

$155K/yr

Full-time

Re-posted 7 days ago


S&P Global rating

7.3

Company rating: 7.3 out of 10

Based on 10 frontline employees who took The Breakroom Quiz


Job description

The Role:
Mobility Global is developing and building its third-party governance framework to support regulatory compliance, information security, and enterprise risk management.
Reporting to the Global Head of Procurement, the Procurement Risk & Compliance Lead, will lead a small team responsible for the operational implementation of the Company's vendor risk management process within Procurement. While Legal Risk & Compliance will design and maintain the enterprise risk framework, this role will be responsible for developing and building the third-party risk management function inside of procurement, aligning with enterprise risk domain owners (information security, HR, ethics and compliance, and finance), monitoring and mitigating supplier risk, and ensure proper governance across the procurement function.
This role serves as the operational bridge between Procurement, Legal, Risk & Compliance, and Information Security.
Responsibility and Impact:
Vendor Risk Process Operationalization
  • Translate the enterprise vendor risk framework into scalable procurement processes and policies.
  • Work with risk domain owners to define intake requirements and risk-tiering triggers for vendor engagements.
  • Monitor the TPRM process and ensure timely completeness of the risk reviews by the applicable risk domain owners.
  • Drive continuous improvement in vendor risk governance processes.
  • Maintain vendor risk attributes, classifications, and documentation repositories.
  • Partner with Finance Systems and IT to enhance automation and reporting.
  • Develop dashboards and reporting to monitor review completion, SLAs, and compliance trends.

Policy & Documentation Development
  • Draft and maintain procurement-facing vendor risk policies and SOPs.
  • Conduct training sessions for business stakeholders.

Risk Review Coordination & Enforcement
  • Monitor review timelines and escalate exceptions.
  • Maintain documentation of approvals, conditions, and remediation requirements.
  • Track and report compliance metrics to Procurement and Finance leadership.

Audit & Compliance Support
  • Maintain audit-ready documentation of vendor risk approvals and workflows.
  • Support SOX-related vendor governance controls where applicable.
  • Partner with Internal Audit on third-party risk assessments.
  • Support remediation efforts tied to vendor governance findings.
  • Promote a culture of governance and risk awareness.

What We're Looking For:
Basic Required Qualifications:
  • Bachelor's degree in Business, Supply Chain, Risk Management, Finance, or related field or equivalent relevant experience.
  • 7 to 10+ years of experience in Procurement, Third-Party Risk, Compliance, or Governance.
  • Experience in a publicly traded organization required.
  • Strong understanding of third-party risk domains, including:
    • Information security
    • Data privacy
    • Regulatory and compliance risk
    • Operational and financial risk
  • Experience developing policy documentation and process controls.
  • Strong systems and workflow configuration experience.
  • Must be a results-focused team player and adapt well to a multitasking, fast paced environment with changing priorities and challenges
  • Strong organizational, presentation and communication skills.
  • Experience working cross-functionally with Technology, Legal, Finance, and Risk teams.

Additional Preferred Qualifications:
  • Experience with LogicGate or similar TPRM tool
  • Governance-oriented with strong attention to detail.
  • Systems-minded and process-driven.
  • Confident cross-functional influencer.
  • Able to enforce controls in a collaborative but firm manner.
  • Comfortable operating in a transformation-oriented, post-spin environment.

If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
It is the policy of Mobility to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Mobility will provide reasonable accommodations for qualified individuals with disabilities.

What S&P Global employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom