1

Vendor Security Risk Assessor Jobs (NOW HIRING)

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

The IT Risk Assessor is responsible for assisting with meeting security and compliance requirements per state and federal standards. The risk assessor will review information system security controls ...

Proficiency in Third-Party Risk Management (TPRM) and vendor security evaluations. * Experience with cloud security assessments across AWS implementations, SaaS applications, and AI platforms.

Vendor Security Analyst

Washington, DC ยท On-site

$120K - $146K/yr

The Vendor Security Analystperforms evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...

Consultant tier --- JOB SUMMARY Judit Inc. is seeking Cybersecurity Risk Assessors to join a field assessment team executing a large-scale government IT security risk assessment across more than 30 ...

Vendor Security Analyst

Louisville, KY ยท On-site

$120K - $146K/yr

The Vendor Security Analystperforms evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...

Vendor Security Analyst

Louisville, KY ยท On-site

$120K - $146K/yr

The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...

Vendor Security Analyst

Washington, DC ยท On-site

$125 - $150/hr

The Vendor Security Analyst performs evaluation of third party and vendor engagements to identify and manage vendor risk which may include completion of risk assessments. They will also conduct the ...

next page

Showing results 1-20

Vendor Security Risk Assessor information

See salary details

$19

$38

$67

How much do vendor security risk assessor jobs pay per hour?

As of Sep 9, 2026, the average hourly pay for vendor security risk assessor in the United States is $38.68, according to ZipRecruiter salary data. Most workers in this role earn between $23.80 and $54.33 per hour, depending on experience, location, and employer.

What are popular job titles related to Vendor Security Risk Assessor jobs?

For Vendor Security Risk Assessor jobs, the most frequently searched job titles are:

Infographic showing various Vendor Security Risk Assessor job openings in the United States as of July 2026, with employment types broken down into 7% Locum Tenens, 67% Full Time, 4% Part Time, 1% Temporary, 2% Contract, and 19% Nights. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution, with an average salary of $80,460 per year, or $38.7 per hour.

Information Security Risk Assessor

Richmond, VA โ€ข On-site

vTech Solution
IT Servicesย โ€ขย 51 - 200 employees

Contractor

Re-posted 25 days ago


Job description

Job Summary:

The Senior Information Security Risk Assessor – PeopleSoft FSCM will lead comprehensive SEC530 risk assessments for PeopleSoft Financials and related business functions. This role involves identifying and evaluating risks, controls, and impacts to ensure the confidentiality, integrity, and availability of sensitive financial and operational data. The assessor will develop risk methodologies, risk registers, and corrective action plans while collaborating closely with IT security auditors and stakeholders.

Responsibilities:
  • Develop SEC530 risk-assessment methodology, scoring criteria, and risk-treatment categories.
  • Define system boundaries, critical business processes, sensitive data, technical dependencies, and third-party services.
  • Conduct interviews and risk workshops with technical, security, fiscal, system-owner, and executive stakeholders.
  • Identify and evaluate risks related to access control, segregation of duties, unauthorized changes, legacy customizations, and interface security.
  • Assess risks involving PeopleSoft roles, permissions, custom code, database privileges, and environment separation.
  • Review control-testing results and assign inherent and residual risk ratings.
  • Develop and maintain a detailed risk register documenting threats, vulnerabilities, controls, and treatment recommendations.
  • Prioritize corrective actions and support development of remediation plans and risk acceptance statements.
  • Prepare and present draft and final risk-assessment reports to leadership and system owners.
  • Participate in onsite kickoff, draft-review, and final wrap-up meetings.
Required Skills & Certifications:
  • Active CISSP or CISA certification.
  • Minimum three years of relevant cybersecurity or IT risk-assessment experience.
  • Experience leading formal application, system, or enterprise technology risk assessments.
  • Proficiency in identifying threats, vulnerabilities, business impacts, and risk levels.
  • Experience developing risk registers and formal risk-assessment reports.
  • Knowledge of systems handling sensitive financial, tax, payment, vendor, or personally identifiable information.
  • Ability to provide a reference from another state government agency.
  • Availability for onsite meetings in Richmond and ability to work from approved U.S.-based locations.
  • Understanding of SEC530 or comparable government risk-assessment standards.
Preferred Skills & Certifications:
  • Five or more years of cybersecurity risk-assessment experience.
  • Prior experience with SEC530, Commonwealth of Virginia, or VITA risk assessments.
  • Expertise in PeopleSoft FSCM, PeopleSoft Financials, Oracle ERP, and financial-system risk assessments.
  • Familiarity with Oracle 19c, PeopleTools, WebLogic, Windows, and Linux environments.
  • Experience assessing Active Directory/LDAP, SFTP, PowerShell, BizTalk, Integration Broker, and database links.
  • Knowledge of vendor, payment, tax, procurement, accounting, or billing system risks.
  • Experience evaluating shared and inherited controls in government-hosted environments.
  • Additional certifications such as CRISC, CISM, CCSP, CGEIT, or ISO 27001 Lead Auditor.
Special Considerations:
  • Mandatory background check and key-personnel status under the SOR.
  • Must be able to perform all work from approved U.S.-based locations.
  • Reference from another state government agency required.
  • Availability for required onsite meetings in Richmond, VA.
Scheduling:
  • Work schedule includes participation in onsite kickoff, draft-review, and final wrap-up meetings.
  • Typical work performed remotely with required onsite presence as specified.

vTech Solution Inc. is a Managed IT Services firm headquartered in Washington, DC. They specialize in a range of services including cloud computingmanaged network security, and cybersecurity. Their primary focus is on providing human-centered IT solutions for government and business sectors, including federal, state, local, and education (SLED) groups, as well as commercial organizations.

vTech Solution offers services such as:

  • Managed Security Services: Implementing zero-trust security frameworks to prevent cyber threats in real-time.
  • Multi-cloud Management Services: Helping businesses digitally transform with smart cloud technologies.
  • Infrastructure Managed Services: Creating resilient and secure infrastructure management.
  • Professional Services: Providing expertise for mission-critical programs.
  • Productivity and Communications: Ensuring secure and confident business connectivity from anywhere

vTech Solution logo

About vTech Solution

Sourced by ZipRecruiter

vTech is a Managed IT Services firm based out of Washington DC with a primary focus on Cloud Computing and Managed Network Security.

Industry

It services

Company size

51 - 200 Employees

Headquarters location

Washington, DC, US

Year founded

2006

Social media