Third-Party Risk Management Analyst
JobgetherRemote · US
At a glance
- Location
- Remote · US
- Workplace
- Remote
- Pay
- $111K – $167K (from listing text)
- Employment type
- Full time
- Experience
- 5+ years
- Education
- No degree requirement stated
- Job family
- Data and analytics
- Seniority
- Not stated
- Posted by employer
- 4 September 2026
- Last verified open
- 7 September 2026
- Work from
- US
- Region and country
- US
- Listed via
- Lever
What the employer wrote
Accountabilities: • Lead end-to-end third-party security risk assessments using qualitative and quantitative methodologies, including vendor risk ratings and tiering in accordance with established Vendor Risk Management policies.
• Own the vendor reassessment cadence and monitor remediation of security gaps throughout the full vendor lifecycle.
• Partner with Legal, Procurement, and system or relationship owners to review vendor onboarding requests and contracts, ensuring appropriate security and privacy requirements are established before vendors go live.
• Evaluate and support requirements related to incident notification, data security and training, compliance obligations, security addenda, and other relevant contractual protections.
• Escalate unresolved or significant vendor risks to Security leadership, Legal, Procurement, and appropriate business owners.
• Support internal and external audits of the third-party risk management program, including assessments aligned with ISO, SOC, FedRAMP, and similar standards.
• Build and maintain metrics, dashboards, and reporting that provide leadership with visibility into the organization’s third-party risk posture and program performance.
• Support the implementation of automation and AI-enabled capabilities within vendor risk workflows, including security questionnaire triage, identification of high-risk contract terms, and integration of relevant industry intelligence.
• Mentor junior third-party risk team members and help ensure the program evolves effectively alongside organizational growth and innovation.
• Promote a strong culture of security, collaboration, continuous improvement, customer focus, long-term thinking, inclusion, and team success.
Requirements
• 5+ years of experience in third-party or vendor risk management, Governance, Risk, and Compliance (GRC), or information security compliance.
• Hands-on experience conducting vendor security assessments and administering vendor risk tiering programs.
• Experience using automation, scripting, or low-code workflows to improve and scale vendor risk processes.
• Demonstrated experience partnering with Legal and Procurement on vendor security and privacy requirements, including security addenda and Data Processing Agreements (DPAs).
• Familiarity with risk assessment frameworks such as NIST CSF, ISO 27001, or SOC 2.
• Experience using GRC or vendor risk management platforms such as Vanta, ServiceNow, OneTrust, Archer, or similar technologies.
• Strong analytical and problem-solving skills, with the ability to evaluate complex risks and translate findings into clear recommendations.
• Excellent communication and collaboration skills, with the ability to work effectively across Security, Legal, Procurement, and business teams.
• Strong organizational skills and the ability to manage multiple assessments, remediation activities, stakeholders, and deadlines in a fast-paced environment.
• Ability to work independently while exercising sound judgment around risk escalation and prioritization.
• A relevant professional certification such as CTPRP, CISA, CRISC, or CISSP is preferred.
• Must reside in the United States, excluding the San Francisco Bay Area, New York City, and Washington, D.C. metropolitan areas.
Benefits
• Annual base salary of $110,670–$167,400 USD , with actual compensation varying based on factors such as location, knowledge, skills, and experience.
• Eligibility for an initial RSU grant with no vesting cliff , subject to applicable plan terms and conditions.
• Ongoing equity refresh opportunities tied to performance, subject to plan terms and conditions.
• Potential performance-based bonus and variable compensation as part of a broader total rewards program.
• Flexible, employee-led remote work model.
• Comprehensive health and parental leave plans.
• Professional development stipend to support continued learning and career growth.
• Opportunity to work in a high-growth environment with significant ownership and career development opportunities.
• Inclusive and collaborative culture focused on long-term impact, innovation, and team success.
• Fully remote U.S. position, with geographic restrictions excluding the San Francisco Bay Area, New York City, and Washington, D.C. metro areas.
How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1
Where this record came from
Read from Jobgether's own Lever job board on , and last confirmed still open on . The employer published it on 4 September 2026. Jobsearch.ing did not write, edit or rank this posting, and does not vet the employer. View the original posting.
More roles like this one
Marketing Analytics & Data Visualization Architect (Remote, USA)
Saviynt
Remote · US
$140K – $169K2 days ago