Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Vendor Risk Analyst

$100k - $130k

Fortress Information Security

Senior Vendor Risk Analyst

Location: Hybrid – Candidates must be based in one of the following areas Naperville, IL / Birmingham, AL / Atlanta, GA. You will work out of the client site closest to your location three days per week, with an expectation of four days per week later in 2026.

Compensation: $100,000 - $130,000 per year, depending on experience and qualifications. Employment Type: Full-Time Travel: Less than 15%, occasional travel for industry collaboration or professional development

What You Can Expect As The Senior Vendor Risk Analyst At Fortress

The Senior Vendor Risk Analyst plays a pivotal role within the Supply Chain Risk Management (SCRM) team, leading third-party vendor risk assessments and shaping how a major energy organization manages supply chain cyber risk. Working directly with vendor relationship owners and cross-functional stakeholders across Legal, Supply Chain, Cybersecurity, and Technology, this role drives continuous improvement of the Third-Party Risk Management (TPRM) program and directly influences leadership-level business decisions. This position provides meaningful exposure to critical infrastructure protection under NERC CIP standards and offers a mission-driven opportunity to help secure systems that society depends on. This is an ideal role for an experienced risk professional seeking broad organizational influence, visibility, and impact. This role offers the opportunity to work closely with a major energy sector client in a highly integrated capacity. Based on performance, business needs, and client discretion, there may be future opportunities to transition into direct employment with the client organization.

Job Responsibilities

  • In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls.
  • Communicate remediation options to the vendors
  • Collaborate with TPRM team members and business partners to complete assessments and determine risk mitigation strategies
  • Become an expert of the TPRM platform to identify and direct necessary customizations, enhancements, and record maintenance to a vendor-supported platform that enable relevant reporting and Program maturation
  • Develop an appreciation and understanding of various business units while employing your knowledge of security fundamentals to effectively communicate customer risk resulting from assessment findings
  • Proactively propose and implement changes to customer Program policy/practice to ensure a risk-informed approach to vendor/supply chain management
  • Collaborate across Supply Chain, Legal, Cybersecurity, and the Technology Organizations to create a shared picture of supplier risk
  • Support cross-functional teams to investigate, analyze, and make recommendations to leadership or process owners regarding technology solutions, security architecture, or security vulnerabilities
  • When appropriate, collaborate across Cyber org to identify compensating controls for significant vendor-specific risks to the company and its customers
  • Review vendor-proposed modifications to Master Service Agreements or Application Service Provider Agreements on behalf of customer to identify any unacceptable security risks associated with new language
  • Understand, relate, and transform regulatory requirements into information security policy, standards, procedures, and guidelines
  • Maintain current knowledge of information security concepts, technologies, and practices
  • Apply deep cybersecurity expertise to assess vendors' security controls, identify cyber risk gaps, and translate technical findings into actionable business recommendations.

Required Qualifications

  • United States citizenship is required
  • 7-10 years experience in security risk assessment, risk management, compliance or auditing
  • Strong knowledge of cybersecurity control frameworks (e.g., NIST SP 800-53, ISO/IEC 27001:2013), with direct cybersecurity experience conducting or overseeing security assessments, control design reviews, or cybersecurity audits
  • Ability to communicate clearly, confidently, and knowledgeably to internal and external stakeholders regarding the Program and assessment results
  • Demonstrated history of critical, independent, and creative thinking to enable continuous improvement or business success within the constraints of security imperatives
  • Ability to holistically assess the risk of a third party engagement, considering control gaps, the nature of the vendor relationship, and the way a vendor's products/services are leveraged
  • Must have demonstrated history of critical, independent, and creative thinking with high attention to detail; this will enable continuous improvement and ensure auditable record trail for all assessment data
  • Prior experience overseeing one or more people in support of a technology solution or program
  • Demonstrated ability to work with and in cross-functional teams
  • One or more of the following certifications: TPCRA, C3PRMP, CTPRA CISSP, CASP, CISA, CISM, GIAC, PMP
  • Must be able to pass NERC CIP and Insider Threat Program background screening due to access to sensitive critical infrastructure and information regarding security capabilities
  • Occasional travel for industry collaboration/influence or professional development is expected
  • This is a hybrid role but three days per week in the office (Naperville, IL, Birmingham, AL or Atlanta, GA) is expected initially but will grow to four days per week in office during 2026. In-office expectations may change over time depending on organizational policy and supervisor's requirements.
  • Education: Bachelor's degree or equivalent experience in a related field required

Preferred Qualifications

  • Experience working in a highly regulated industry
  • Prior experience advocating security policies, practices, controls, and standards to business and IT teams
  • Familiarity with basic requirements for architecting secure information systems
  • Familiarity with NERC's Critical Infrastructure Protection (CIP) standards
  • Experience with non-IT risk such as operational, financial, Compliance and Regulatory, Strategic Risk, Legal Risk, and ESG risk (Environmental, Social, and Governance)

Employee Benefits

  • Remote and Hybrid working environment
  • Competitive pay structure
  • Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
  • Company paid life, short- and long-term disability insurance
  • Employee Assistance Program
  • 401(k) match
  • Flexible Paid Time Off
  • Parental Leave

Employment Perks

  • We provide each employee with professional growth opportunities through succession planning, up-skilling, and certifications
  • Tuition and certification reimbursement
  • Employee Referral Programs
  • Company Sponsored Events

Foretress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E-Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis.

Vacancy posted 19 hours ago
Similar jobs that could be interesting for youBased on the Senior Vendor Risk Analyst in Atlanta, GA vacancy
  • $85k - $110k

    The Mutual Group in Atlanta, GA is seeking an individual contributor for AI and Technology Risk Governance. This hands-on role focuses on vendor AI governance, ensuring compliance across insurance carriers. Responsibilities include tracking AI usage and supporting various... 
    Suggested
    Flexible hours

    The Mutual Group

    Atlanta, GA
    19 hours ago
  • Cooper Lighting Solutions is seeking a Technical Risk Assessment Analyst in Atlanta, GA. This on-site role involves evaluating risks from third-party suppliers and managing vendor connectivity for enhanced security. The candidate should have a Bachelor's degree and over... 
    Senior

    Cooper Lighting Solutions

    Atlanta, GA
    4 days ago
  •  ...The Sr. Underwriting Risk Specialist will utilize strong underwriting, data analysis,...  ...companies, internal data scientists, business analysts, and other underwriters to develop and...  ...implement appropriate solutions. Engage with vendors and our legal team to unlock... 
    Senior
    Shift work

    Munich Re

    Atlanta, GA
    1 day ago
  •  ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Atlanta, GA The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer...  ...TPRM) and Governance and Risk functions in conducting vendor due diligence (initial, reassessments and ongoing... 
    Senior
    Work experience placement

    Next Step Systems LTD

    Atlanta, GA
    2 days ago
  •  ...reviews. Provides guidance to less experienced Collateral Risk Analysts in Collateral Services department policies, procedures, and...  ...Bank's collateral policies. Conducts exit meetings with senior management of member institutions summarizing collateral verification... 
    Senior
    For contractors
    Work experience placement
    Work at office
    Remote work
    Visa sponsorship
    Work visa
    Night shift

    Federal Home Loan Bank of Atlanta

    Atlanta, GA
    3 days ago
  • $34.55 - $55.19 per hour

     ...RISK ANALYST USMB WHAT IS THE OPPORTUNITY? This role will primarily be responsible for the execution of the first line of defense Risk...  ...of actions taken. Prepare reports of results for senior management. Support state, federal and agency examinations,... 
    Hourly pay
    Remote work

    City National Bank

    Atlanta, GA
    1 day ago
  • $94.2k

     ..., privacy, business teams and other areas necessary to identify risks to the business and drive solutions ranging from education and awareness...  ...model lifecycle security, data privacy, and third-party AI/vendor risk considerations Understanding of automation opportunities... 
    Senior
    For contractors
    Local area
    Remote work

    Highmark Health

    Atlanta, GA
    1 day ago
  • Overview Public Entity Risk Management Authority (PERMA), a California Joint Powers Authority (JPA), is seeking a Senior Risk Control Specialist to manage PERMA’s risk control program...  ...Risk Control Specialist will oversee vendors responsible for risk control services, be... 
    Senior
    Remote job
    Full time

    AGRiP (Association of Governmental Risk Pools)

    Atlanta, GA
    19 hours ago
  • The Federal Home Loan Bank of Atlanta is seeking a qualified individual to conduct collateral verification reviews and analyze pledges to support lending. This role includes preparing evaluations of mortgage loans, interacting with member institutions, and offering guidance...
    Senior
    Remote work
    Flexible hours

    Federal Home Loan Bank of Atlanta

    Atlanta, GA
    19 hours ago
  •  ...team and culture and contribute to our core mission which is enhancing our customer's experience. Position Summary: The Senior Risk Analyst, Business Analytics, will be responsible for utilizing advanced analytical techniques and tools to provide data and reporting... 
    Senior
    Work at office
    Monday to Friday
    Weekend work

    Stellantis

    Atlanta, GA
    4 days ago
  • $85k - $110k

    Overview Execute day‑to‑day operations of AI and Technology Risk Governance, with primary responsibility for vendor AI governance and detection across The Mutual Group and its member insurance carriers. This is a fully hands‑on individual contributor role responsible for... 
    Temporary work
    Work at office
    Remote work
    Home office
    Flexible hours

    The Mutual Group

    Atlanta, GA
    1 day ago
  •  ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering...  ...Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    Clayco

    Atlanta, GA
    12 days ago
  • $179k - $268.4k

    Monograph is seeking an experienced Data Analyst to drive the data strategy for their risk product offering. This role involves defining metrics and analytical frameworks, partnering with teams, and mentoring junior analysts. Candidates should have over 10 years in Data... 
    Senior
    Remote job
    Work at office

    Monograph

    Atlanta, GA
    2 days ago
  •  ...second-line-of-defense (LoD2) Technology Risk team responsible for independent risk oversight...  ...Truist environment. The Technology Risk Senior Specialist - TEMPO Cost & Supplier...  ...contract provisions, third-party due diligence, vendor assessments, service commitment... 
    Senior
    Full time
    Contract work
    Part time
    Work at office
    Shift work
    Day shift

    Truist

    Atlanta, GA
    1 day ago
  •  ...Supplier Medical Process Specialist in Atlanta. This fully remote role is ideal for experienced nursing professionals with skills in vendor management and operational excellence. Key responsibilities include managing supplier performance, analyzing operational data for... 
    Senior
    Remote work

    Zurich NA

    Atlanta, GA
    1 day ago
  • Fortress in Atlanta is hiring a Senior Vendor Risk Analyst to lead vendor risk assessments and drive third-party risk management. This role involves collaboration with various teams to enhance security practices and ensure compliance within the supply chain. Candidates... 
    Senior

    Fortress

    Atlanta, GA
    4 days ago
  • $120k - $150k

     ...Risk Manager / Senior Risk Analyst Location: Atlanta, Orlando or Tampa (Hybrid) — Remote flexibility available for the right candidate Division : Dealer General Warranty About CV Family & Dealer General Warranty The CV Family Organization is a privately... 
    Senior
    Contract work
    Remote work

    Integro Professional Services, LLC

    Atlanta, GA
    5 days ago
  • $100.2k - $164.1k

     ...Senior Risk Engineering Consultant 130237 Zurich's Middle Markets Risk Engineering team is seeking a Risk Engineering Consultant with...  ...Zurich does not accept unsolicited CVs from agencies. Preferred vendors should use our Recruiting Agency Portal. Location(s): AM -... 
    Senior
    Full time
    Temporary work
    Apprenticeship
    Work at office
    Local area
    Remote work
    Work from home
    Visa sponsorship

    Zurich NA

    Atlanta, GA
    19 hours ago
  •  ...Transaction Fraud Analytics (Senior Fraud Risk Analyst) Atlanta, GA Description Job Description Title: Senior Analyst/Associate Transaction Fraud Analytics (Senior Fraud Risk Analyst) Location: Atlanta, GA (Hybrid) Department: Risk Management/Fraud... 
    Senior

    Atlanticus

    Atlanta, GA
    3 days ago
  • Acuity Inc. in Atlanta, GA is seeking a Senior Talent Acquisition Advisor to manage outsourced recruiting services. This role focuses on optimizing vendor-managed recruiting, ensuring alignment with business objectives and compliance with local practices. The ideal candidate... 
    Senior
    Hourly pay
    Local area

    Acuity Inc

    Atlanta, GA
    19 hours ago
  • Reserv Claims Analysis, LLC in Atlanta, Georgia, is hiring a Vendor Manager to enhance vendor relationships and streamline processes. The role involves overseeing vendor lifecycle, compliance, and strategic partnerships. Candidates should have a Bachelor's degree and over... 
    Senior
    Remote job

    Reserv Claims Analysis, LLC

    Atlanta, GA
    2 days ago
  • $45 - $52 per hour

     ...Global is seeking a highly analytical Sr. Financial & Contract Analyst to join a major healthcare system in Atlanta. This role focuses...  ...supporting complex budgeting and financial oversight while managing vendor-related financial activities. The ideal candidate should have... 
    Senior
    Hourly pay
    Contract work

    Insight Global

    Atlanta, GA
    19 hours ago
  • $91.66k - $120.3k

     ...Hi, we're Oscar. We're hiring a Senior Actuarial Analyst to join our Actuarial team. Oscar is the...  ...valuation function, focusing specifically on risk adjustment across all Affordable Care...  ...across plan designs, providers, vendors, and markets. Stakeholder Engagement... 
    Senior
    Full time
    Work at office
    Remote work

    Oscar Health

    Atlanta, GA
    4 days ago
  •  ...experienced, self-directed IT Project Manager to oversee a critical vendor engagement for the Small Commercial Underwriting team. You will...  .... • Stakeholder Management: Communicate project status, risks, and issues clearly to the IT Director and other stakeholders. Prepare... 
    Senior
    Work at office
    Remote work

    TriOptus LLC

    Atlanta, GA
    19 hours ago
  • $80k

    Fulton County is seeking a qualified candidate for an IT position focused on vendor management and contract negotiation. The role requires a Bachelor's degree in a relevant field along with five years of experience in strategic partnerships management. Candidates will... 
    Senior
    Contract work

    Fulton County

    Atlanta, GA
    2 days ago
  •  ...A financial technology firm based in Atlanta is seeking a Senior Analyst for IT Internal Control. In this role, you will develop and maintain...  ...and a Bachelor's degree in a related field. Strong skills in risk assessment and information security management are required,... 
    Senior

    Insight Global

    Atlanta, GA
    2 days ago
  • $143k - $243k

     ...A healthcare company seeking a Senior Principal Actuary to lead actuarial direction and create innovative pricing strategies. This fully remote role requires 10 years of actuarial experience and a Bachelor's degree in Math or related fields. The ideal candidate will have... 
    Senior
    Remote work

    Prime Therapeutics

    Atlanta, GA
    3 days ago
  • $150.5k - $301k

     ...Senior Pharmacy Benefits Actuarial Or Financial Consultant We are seeking a talented...  ...negotiations with benefits carriers and vendors. We will count on you to: Manage...  ...a business of Marsh, a global leader in risk, reinsurance and capital, people and investments... 
    Senior
    Minimum wage
    Work at office
    Local area
    Remote work
    Flexible hours
    3 days per week
    1 day per week

    Marsh & McLennan

    Atlanta, GA
    4 days ago
  •  ...Georgia is looking for an individual with expertise in underwriting and financial analysis to enhance business models and support credit risk management. This role involves collaborating with internal departments and providing mentorship to junior staff while ensuring... 
    Senior

    0011 Checkout LLC

    Atlanta, GA
    19 hours ago
  • A global consulting firm is seeking a Senior Consultant for their Risk Technology practice. You will use your expertise with ServiceNow IRM to help clients optimize their risk and compliance programs. Candidates should have relevant degrees and at least 2 years of experience... 
    Senior
    Flexible hours

    Ernst & Young Oman

    Atlanta, GA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Vendor Risk Analyst. Be the first to apply!