Third-Party Risk Management Analyst
Location: Remote
Compensation: Salary
Reviewed: Thu, Sep 03, 2026
This job expires in: 30 days
Job Summary
Owning the security risk assessments for critical vendors and partners, the remote Third-Party Risk Management Analyst will manage the complete lifecycle of vendor relationships, ensuring compliance with security standards while collaborating with Legal and Procurement teams.
Key responsibilities
- Lead end-to-end third-party security risk assessments and recommend risk ratings in line with the Vendor Risk Management Policy
- Oversee vendor reassessment cadence and track remediation of security gaps throughout the vendor lifecycle
- Partner with Legal and Procurement to review vendor contracts and ensure security requirements are met prior to vendor onboarding
Required qualifications
- 5+ years of experience in third-party/vendor risk management, GRC, or information security compliance
- Experience using automation, scripting, or low-code workflows to scale a vendor risk program
- Hands-on experience running vendor security assessments and managing a vendor tiering program
- Experience collaborating with Legal and Procurement on vendor contract security and privacy terms
- Must reside in the US, outside the San Francisco Bay Area, New York City, and Washington, D.C. metro areas
Complete Job Description
The complete job description is available to members. Premium membership includes:
Full access to 44,825 remote jobs from human-vetted companies, updated daily
Resume Builder - AI-powered tool to craft, enhance, and tailor your resume to a specific job
Twice-monthly live group coaching and the full Remote Career Center
20% member discount on Career Services
Backed by a 30-day money-back guarantee