Senior Vendor Risk Analyst
$100k - $130kFortress Information Security
Senior Vendor Risk Analyst
Location: Hybrid – Candidates must be based in one of the following areas Naperville, IL / Birmingham, AL / Atlanta, GA. You will work out of the client site closest to your location three days per week, with an expectation of four days per week later in 2026.
Compensation: $100,000 - $130,000 per year, depending on experience and qualifications. Employment Type: Full-Time Travel: Less than 15%, occasional travel for industry collaboration or professional development
What You Can Expect As The Senior Vendor Risk Analyst At Fortress
The Senior Vendor Risk Analyst plays a pivotal role within the Supply Chain Risk Management (SCRM) team, leading third-party vendor risk assessments and shaping how a major energy organization manages supply chain cyber risk. Working directly with vendor relationship owners and cross-functional stakeholders across Legal, Supply Chain, Cybersecurity, and Technology, this role drives continuous improvement of the Third-Party Risk Management (TPRM) program and directly influences leadership-level business decisions. This position provides meaningful exposure to critical infrastructure protection under NERC CIP standards and offers a mission-driven opportunity to help secure systems that society depends on. This is an ideal role for an experienced risk professional seeking broad organizational influence, visibility, and impact. This role offers the opportunity to work closely with a major energy sector client in a highly integrated capacity. Based on performance, business needs, and client discretion, there may be future opportunities to transition into direct employment with the client organization.
Job Responsibilities
- In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls.
- Communicate remediation options to the vendors
- Collaborate with TPRM team members and business partners to complete assessments and determine risk mitigation strategies
- Become an expert of the TPRM platform to identify and direct necessary customizations, enhancements, and record maintenance to a vendor-supported platform that enable relevant reporting and Program maturation
- Develop an appreciation and understanding of various business units while employing your knowledge of security fundamentals to effectively communicate customer risk resulting from assessment findings
- Proactively propose and implement changes to customer Program policy/practice to ensure a risk-informed approach to vendor/supply chain management
- Collaborate across Supply Chain, Legal, Cybersecurity, and the Technology Organizations to create a shared picture of supplier risk
- Support cross-functional teams to investigate, analyze, and make recommendations to leadership or process owners regarding technology solutions, security architecture, or security vulnerabilities
- When appropriate, collaborate across Cyber org to identify compensating controls for significant vendor-specific risks to the company and its customers
- Review vendor-proposed modifications to Master Service Agreements or Application Service Provider Agreements on behalf of customer to identify any unacceptable security risks associated with new language
- Understand, relate, and transform regulatory requirements into information security policy, standards, procedures, and guidelines
- Maintain current knowledge of information security concepts, technologies, and practices
- Other duties as assigned
Required Qualifications
- United States citizenship is required
- 7-10 years experience in security risk assessment, risk management, compliance or auditing
- Strong knowledge of security control frameworks (e.g., NIST SP 800-53, ISO/IEC 27001:2013)
- Ability to communicate clearly, confidently, and knowledgeably to internal and external stakeholders regarding the Program and assessment results
- Demonstrated history of critical, independent, and creative thinking to enable continuous improvement or business success within the constraints of security imperatives
- Ability to holistically assess the risk of a third party engagement, considering control gaps, the nature of the vendor relationship, and the way a vendor's products/services are leveraged required
- Must have demonstrated history of critical, independent, and creative thinking with high attention to detail; this will enable continuous improvement and ensure auditable record trail for all assessment data
- Prior experience overseeing one or more people in support of a technology solution or program
- Demonstrated ability to work with and in cross-functional teams
- One or more of the following certifications: TPCRA, C3PRMP, CTPRA CISSP, CASP, CISA, CISM, GIAC, PMP
- Must be able to pass NERC CIP and Insider Threat Program background screening due to access to sensitive critical infrastructure and information regarding security capabilities
- Occasional travel for industry collaboration/influence or professional development is expected
- This is a hybrid role but three days per week in the office (Naperville, IL, Birmingham, AL or Atlanta, GA) is expected initially but will grow to four days per week in office during 2026. In-office expectations may change over time depending on organizational policy and supervisor's requirements.
Education
- Bachelor's degree or equivalent experience in a related field required
Preferred Qualifications
- Experience working in a highly regulated industry
- Prior experience advocating security policies, practices, controls, and standards to business and IT teams
- Familiarity with basic requirements for architecting secure information systems
- Familiarity with NERC's Critical Infrastructure Protection (CIP) standards
- Experience with non-IT risk such as operational, financial, Compliance and Regulatory, Strategic Risk, Legal Risk, and ESG risk (Environmental, Social, and Governance)
Employee Benefits
- Remote and Hybrid working environment
- Competitive pay structure
- Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
- Company paid life, short- and long-term disability insurance
- Employee Assistance Program
- 401(k) match
- Flexible Paid Time Off
- Parental Leave
Employment Perks
- We provide each employee with professional growth opportunities through succession planning, up-skilling, and certifications
- Tuition and certification reimbursement
- Employee Referral Programs
- Company Sponsored Events
Foretress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E-Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis.
- ...Description Insight Global is seeking a Senior TPM Analyst to join a client in the regulatory... ...the insurance industry and are seeking a risk and compliance subject matter expert to... ...product teams. This role covers the AI vendor onboarding and ongoing oversight angle....SeniorContract work
- ...divh2Senior TPM Analyst/h2pInsight Global is seeking a Senior TPM Analyst to join a client in the regulatory technology... ...industry and are seeking a risk and compliance subject matter expert... ...product teams. This role covers the AI vendor onboarding and ongoing oversight angle...Senior
$85k - $100k
...and requests, completing an annual client review with thorough risk assessment of current and future exposures. Required to perform... ...beautification and restoration projects – to partnering with eco-conscious vendors and taking steps to reduce our own environmental footprint – we'...SeniorTemporary workLocal areaFlexible hours- Job Opportunity This position is located in Division of Decommissioning, Uranium Recovery, and Waste Programs. This job opportunity announcement may be used to fill additional vacancies within the agency. The supervisor is Michelle Sutherland. This position is subject...Senior
- ...Sr. Risk Analyst Duties The successful candidate will perform the full range of Sr. Risk Analyst duties. Such duties include but are not limited to: Performs and evaluates risk analyses, including performance assessments, and provides risk insights to support the development...Senior
$77.12k - $115.68k
...discrimination and/or harassment. Position Summary The Senior Supervisor - Vendor Performance manages vendor partnerships by overseeing... ...plans. Monitor vendor performance trends and escalate risks, gaps, and opportunities to leadership with recommended...SeniorContract workTemporary workWork at officeLocal areaRemote workFlexible hours- ...Personal Lines Sales Executive At Gallagher, we help clients face risk with confidence because we believe that when businesses are... ...prohibits any form of discrimination by its managers, employees, vendors or customers based on race, color, religion, creed, gender (...Full timeInternshipLive outWork at officeLocal areaFlexible hours
$96.56k - $150k
...Senior Business Systems Analyst The Sr Business Systems Analyst leads business and technology teams in designing and implementing JD Edwards... ...Responsible for system architecture, project leadership, vendor management, advanced troubleshooting, and strategic process...SeniorTemporary workFor contractorsLocal areaWorldwide$77.2k - $96.5k
...dynamic role as an Information Security (InfoSec) Governance, Risk, and Compliance (GRC) Analyst within Audit and Compliance, where you will be at the... ..., and catering arrangements. Administer audit vendor requirements and manage document repositories through vendor...Permanent employmentFull timeH1bVisa sponsorshipShift work$77.2k - $96.5k
...dynamic role as an Information Security (InfoSec) Governance, Risk, and Compliance (GRC) Analyst within Audit and Compliance, where you will be at the... ..., and catering arrangements. Administer audit vendor requirements and manage document repositories through vendor...Permanent employmentFull timeH1bVisa sponsorshipShift work- ...About the job Senior Internal Controls Analyst Our ideal candidate will work closely with Management to create/update process documentation, update the Risk and Control Matrix in Audit Board and monitor remediation plans for control deficiencies identified by...SeniorWork experience placement
- ...including routers, switches, firewall, VPN & wireless Maintain, monitor, optimize, patch and update the network equipment Manage vendor relationship for infrastructure services Maintain Compliance in accordance with GDPR, ITAR and other regulations Drive...Senior
- ...duties, and audit readiness. Oversee a team of five business analysts, providing mentorship and guidance Act as a liaison with... ...tools, including Hyperion and other platforms Collaborate with vendors for system support, performance management, licensing, and new...Senior
$110k - $135k
...Invesco Sr. Analyst As one of the world's leading independent global investment firms, Invesco is dedicated to rethinking possibilities... ...Project manage and lead research projects as assigned by senior leaders Execute on actions needed to maintain and improve product...Senior$88.4k - $110.7k
...The Senior Marketing Analyst provides analytical support and strategic insights to the Consumer Marketing and Ace Rewards teams. This position... ...frequent campus events like Employee Appreciation Week, vendor demos, cookouts, and merchandise sales ~ We bring them to...SeniorTemporary workLocal areaImmediate start- ...Sr. Actuarial Consultant Edgewater Actuarial Insights is seeking a Senior Actuarial Consultant to support our growing actuarial consulting practice. This position requires the candidate to work as part of a team of professionals to independently analyze complex problems...Senior
$66.2k - $84.5k
...autonomy and professional ownership. At Ulta Beauty, our Legal, Risk & Governance team provides clarity and continuity in ways that have... .... THE IMPACT YOU CAN HAVE The Risk Management Analyst supports the organization's workers' compensation, general liability...Full timePart timeLocal areaShift work- ...Reporting directly to the Director of Total Rewards, we are seeking a highly disciplined and detail-oriented Senior Benefits Analyst to manage complex, large-scale datasets supporting our benefits operations. This role requires advanced Excel expertise, a strong focus...Senior
$160k - $185k
...Senior Principal, Bank Loan And Private Credit Markets The Senior Principal will serve as a highly experienced subject matter expert... ...and external stakeholders to ensure superior service delivery and risk mitigation. You Will Be Responsible For: Lead and...SeniorWork at office- **$5,000 sign-on bonus** This position is in-person with the possibility of hybrid after 6 months. Responsible for examining and evaluating reporting requirements for various business units across the organization. Utilizes proven knowledge of specialized reporting...SeniorRelocation package
$123k - $140k
...Can Grow - Where You Can Have An Impact Senior Manager, Marketing Operations Salary:... ...across the marketing organization Vendor & Invoicing Management Own end-to-end... ...market, channel, and time period Surface risks and constraints that may impact marketing...SeniorContract work- ...Day to day: The Senior Facility Manager provides strategic and operational leadership across data center facilities, ensuring reliable... ...Operations Director, this role oversees daily facility operations, vendor performance, customer implementations, and incident management...Senior
- In this role, you will facilitate technology-driven transformations across supply chain and manufacturing operations. You will collaborate closely with business leaders to design and implement solutions on the JD Edwards platform, greatly impacting efficiency and operational...SeniorFull time
$110k - $130k
...Senior Data Analyst Reporting directly to the Director of Total Rewards, we are seeking a highly disciplined and detail-oriented Senior Data Analyst to manage complex, large-scale datasets supporting our Benefits operations. This role requires advanced Excel expertise...SeniorFull time$110k - $120k
...approval drawings, schematics, BOMs, and supporting documents, ensuring accuracy and timely release. Work closely with purchasing, vendors, engineering, manufacturing, and service teams to resolve design-related challenges and implement improvements. Conduct root...Senior$150k - $200k
...Global transportation company seeking a Senior Risk Manager to lead enterprise-wide insurance and risk financing programs. This role owns... ...strategies to reduce claim costs and improve outcomes Vendor Management: - Manage relationships with brokers, insurers, and...SeniorImmediate start- ...Position Overview: We are seeking an experienced and hands-on Senior HR Manager to lead and strengthen core HR operations within a fast... ...and HR recommendations. Support benefits administration, vendor coordination, and annual enrollment processes. Oversee payroll...SeniorLocal area
- ...Senior Manufacturing Engineer We are seeking a highly skilled and experienced Senior Manufacturing Engineer to join our dynamic engineering... ...Collaborate with Quality, Operations, Tooling, and external vendors to implement effective and scalable production solutions....Senior
- ...Job Summary: We are seeking a seasoned Functional Analyst with a strong background in IT QA and functional testing to join our team. The ideal candidate will have a minimum of 5 years of experience in functional testing, HP ALM, and JIRA, with a proven track record...Senior
- ...Under the direction of the Director of Risk Management, the Senior Risk Manager will lead the design, placement, and ongoing management of our... ...events, new business initiatives, real estate matters, and vendor/contract risk; review, negotiate, and manage approximately...SeniorContract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Vendor Risk Analyst. Be the first to apply!
- senior manager customer operations Naperville, IL
- senior vmware engineer Naperville, IL
- senior performance engineer Naperville, IL
- senior software design engineer Naperville, IL
- senior tableau developer Naperville, IL
- senior magento developer Naperville, IL
- senior sas developer Naperville, IL
- senior dynamics crm developer Naperville, IL
- senior grant accountant Naperville, IL
- senior property accountant Naperville, IL


