Vendor Risk & Compliance Specialist
American Institute for Chartered Propert
Job Description
Job Description
About The Institutes
Located in beautiful Malvern, Pennsylvania, The Institutes® are a not-for-profit comprised of diverse affiliates that educate, elevate, and connect people in the essential disciplines of risk management and insurance. Through products and services offered by our nearly 20 affiliated business units, people and organizations are empowered to help those in need with a focus on understanding, predicting, and preventing losses to create a more resilient world.
Additionally, we understand the importance of work-life balance—in 2025 Philly.com named us a Top Workplace for the tenth year and USA Today named us a USA Top Workplace for the fourth year. We provide excellent benefits and a friendly, team-focused work environment to drive employee engagement.
Vendor Risk & Compliance Specialist
The Vendor Risk & Compliance Specialist role is responsible for advancing the organization’s vendor governance program into a strategic, risk-driven function focused on AI, data exposure, and technology portfolio optimization.
This role evolves beyond operational vendor tracking to provide analytical oversight of third-party risk, AI model exposure, SaaS rationalization strategy, and contractual data governance. The Vendor Risk & Compliance Specialist partners cross-functionally with Security, Legal, Procurement, IT, Application Development, and Compliance to evaluate vendor AI posture, assess model risk exposure, and ensure responsible technology adoption across the enterprise.
This position plays a critical role in strengthening the organization’s Third-Party Risk Management (TPRM) and AI governance frameworks, driving informed decision-making through risk analytics, vendor scoring, and portfolio optimization.
What You’ll Do:
Vendor Governance & Lifecycle Management
- Maintain contract repository and track renewal dates
- Coordinate renewals with Legal and Procurement
- Maintain vendor tier classifications and risk profiles
- Track remediation items and follow up with vendors.
- Review and distribute security questionnaires.
- Collect and analyze SOC reports, cyber insurance documentation, and compliance artifacts.
- Identify and execute Continuous improvement opportunities for the customer experience
- Proactively do research on the vendors spaces to track trends, risks and current events. Raise risks as needed.
AI & Third-Party Risk Analysis
- Conduct AI-focused vendor risk assessments, including model usage, training data sources, and data retention practices.
- Evaluate vendor AI posture and develop AI risk scoring methodology.
- Assess AI model risk exposure, including bias, explainability, and regulatory considerations.
- Partner with Security to detect and mitigate Shadow AI usage across the organization.
- Track vendor data exposure risk and data-sharing pathways.
- Coordinate OneTrust integrations and AI governance workflows.
Contract & Data Governance Oversight
- Review and evaluate AI/data-related clauses in contracts, including:
- Data ownership
- Data residency
- Model training rights
- Sub processor disclosures
- AI indemnification and liability language
- Partner with Legal to strengthen AI and data protection contractual standards.
- Support AI/data usage contractual reviews during vendor onboarding and renewals.
Technology Portfolio & SaaS Rationalization
- Maintain enterprise SaaS inventory and technology portfolio map.
- Analyze license utilization and identify consolidation opportunities.
- Develop SaaS rationalization strategy to reduce redundant platforms.
- Assess overlapping AI tool capabilities and risk duplication.
- Provide cost-risk optimization recommendations to leadership.
Analytics & Strategic Reporting
- Develop vendor risk dashboards and AI posture reporting.
- Create executive-level reporting on:
- AI vendor exposure
- Data risk trends
- Model risk concentration
- SaaS redundancy and cost optimization
What We’re Looking For:
Required
- 3–5+ years of experience in vendor management, third-party risk, IT governance, compliance, or risk analysis.
- Proficiency in LLM technology and utilization of such tools to manage the complexities of the research and analysis are critical to the success of the role.
- Effective hands-on usage of LLM technology-based tools to help achieve department Ends
- Experience reviewing vendor contracts and tracking renewals.
- Exposure to third-party risk assessments and security questionnaire processes.
- Strong analytical and documentation skills.
- Highly curious, and a desire for continuous improvement of the customer experience and risk management processes.
- Experience managing SaaS inventories or technology portfolios.
- Proficiency in Excel and vendor management platforms.
Preferred
- Experience supporting SOC 2, ISO 27001, or similar audits.
- Familiarity with OneTrust or TPRM platforms.
- Exposure to AI governance, data risk management, or emerging technology risk.
- Understanding of AI model risk principles (bias, explainability, regulatory impact).
Ability to be on-site 5 days a week is a must. The need for extended hours may be required to support meetings/events.
Required Competencies
- Analytical and risk-based decision-making
- Strategic thinking
- Strong organization skills
- AI and data governance awareness
- Strong cross-functional collaboration
- Process optimization mindset
- Executive-ready reporting skills
- Strive to reflect our five cultural values in all efforts: Put the Customer First, Do What You Say, Work Together, Be Innovative and Do the Right Thing.
The Best Part? The Benefits!
To enforce the importance of work-life balance, employees enjoy excellent benefits, including:
- 401(k) plan with company contribution up to 16%
- Generous time off package that includes paid vacation, personal, sick, and holidays
- Paid maternity and parental leave
- Tuition reimbursement
- Medical, dental, vision, and prescription coverage
- On our Malvern campus: Free lunch every day when working on campus, onsite fitness center, and a beautiful 1.25-mile walking path!
- ...investment in GRC modernization. You will lead risk assessments, design and scale forward-looking governance, risk, and compliance programs, and serve as a trusted advisor... ...The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard's Global...SuggestedWork experience placement
- ...Business Risk & Governance, Specialist Apply ( locations Malvern, PA time type Full time... ...and governance activities within the Vendor Management Office of the Investment Management... .... Move beyond checklist‑based compliance byshaping how third‑party risk...SuggestedFull timeWork at officeRemote workMonday to Friday
- ...Senior AI Risk Analyst Malvern, Pennsylvania, United States Senior AI Risk Analyst Full-time/Regular/Direct Hire role No VISA... ...and manage risks proactively. Partner with IT, business, and vendor teams to guide secure technology implementations. Define and...SuggestedFull timeVisa sponsorship
- ...The Senior Risk Advisor, Debit Card & Digital Payments, provides risk advisory support... ...product, operations, technology, legal, compliance, and third-party providers (e.g., card processors... ..., legal, compliance) and third-party vendors to support the design, launch, and...SuggestedWork experience placement
- ...A leading financial institution in Berwyn, PA seeks a Senior Specialist in Information Risk to ensure effective internal controls and support risk management initiatives. The ideal candidate will have a Bachelor’s Degree, 2-3 years of experience in risk and audit, and...Suggested
$60k - $70k
...the general direction of the Director of Risk and Governance Services, the Third Party... ...related to the protection and regulatory compliance of patient health information. Essential... ...Functions Ensure timely delivery of TPRM vendor assessment reports, and other TPRM service...Work at officeFlexible hours- ...organization operates within its regulatory, legal, and compliance obligations while managing risk effectively. The Global GRC Senior Analyst will report... ...documented, prioritized, and mitigated. • Perform third-party/vendor risk assessments to evaluate potential risks associated...For contractors
$60k - $70k
Silversmith Capital Partners in Exton, PA is looking for a Third Party Risk Analyst to manage vendor risk assessments in a healthcare environment. You'll ensure timely delivery of assessments, maintain compliance with relevant regulations, and handle client communications....- ...This role will take ownership of actuarial risk analysis and reporting for defined areas of the risk management function, with a primary... ...with auditors, actuarial outsourcing partners, and other vendors. Qualifications Bachelor’s degree in Mathematics, Actuarial Science...
$70k - $118.75k
...Risk, Performance & Attribution Consultant - PMAR Specialist Overview PMAR Specialists lead or directly contribute to CRIMS implementations... ...Risk ~ Regime and Trend Analysis ~ Risk Compliance Monitoring. ~ Design Operational controls....Temporary workFlexible hours- ...Senior Technology Risk Consultant Apply ( locations Malvern, PA North Carolina time type Full time posted on... ...experience. Similar Jobs (5) Technology Risk Advisor, Senior Specialist locations 2 Locations time type Full time posted...Full timeFlexible hours
- ...Our client is currently seeking a Data Risk Analyst Core Responsibilities Vulnerability Reporting - Develop clear, data-... ...vulnerability scanning programs (on-prem and/or cloud), including SLA compliance. False Positive Investigation - Ability to conduct...
- ...~1. Prepare detailed reporting on vulnerabilities and related risks, integrating risk concepts such as impact and likelihood to ensure... ...enterprise assets (on prem and/or cloud workloads), including compliance to remediation SLAs. Ability to perform a structured...
- ...Vulnerability Analyst Prepare detailed reporting on vulnerabilities and related risks, integrating risk concepts such as impact and likelihood to ensure proper prioritization. Reporting will outline security posture, vulnerability trends, and mitigation results....
- ...Vulnerability Management Specialist Prepare detailed reporting on vulnerabilities and related risks, integrating risk concepts such as impact and likelihood to ensure... ...(on prem and/or cloud workloads), including compliance to remediation SLAs. Ability to perform a...
- ...Risk Insurance Analyst Join a dynamic organization driven by our passion for healthcare... ...to coordinate, monitor, review for compliance, negotiate, analyze, facilitate procedures... ...with the hospital facilities, possibly the vendors, and their insurance agents when there are...Contract workLocal area
$40 - $45 per hour
Alphanumeric is hiring a Compliance Specialist - Level 2 to support our long-standing client committed to improving lives through medical and... ...traceability. Support compliance with internal policies related to risk and issue management, including tracking and following up on...$118.7k - $207.8k
...underwriting actions to enhance profitability, proactively optimising risk management. Large Account Pricing: Utilize actuarial pricing... ...CUO, Underwriting, Reserving, Claims, Models & Analytics, IT, Compliance, etc.) to drive pricing accuracy, profitability, and...Flexible hours- ...Venerable in Glenloch, Pennsylvania, is seeking an Associate Actuary to manage actuarial risk analysis and reporting. This role involves financial risk assessment, stress testing analysis, and report preparation for management and external parties. The ideal candidate...
$73.9k - $122.7k
...metrics monitoring, including data quality, outlier analysis, and compliance audits. Assist in analyzing portfolio results to evaluate... ...improvement. Who we are AXA XL, the P&C and specialty risk division of AXA, is known for solving complex risks. For mid-sized...Flexible hours- Universal Health Services, Inc. is seeking a Risk Insurance Analyst in King of Prussia, Pennsylvania. You will coordinate... ...analyze insurance requirements for contracts, ensuring compliance while communicating with vendors and hospital facilities. Ideal candidates have a...
- ...Senior Risk Director, Financial Advisor Services (FAS) Apply ( locations Malvern, PA time type Full time posted on... ...appetite. Partner with other GR&S risk teams and Legal and Compliance teams to develop a comprehensive view of risk to the business....Full timeWork experience placementWork at office
- Venerable in Glenloch, Pennsylvania is seeking a talented analyst for Variable Annuity model validation and project reviews. This role involves deep collaboration across Finance and external actuarial services while ensuring audit and approval processes are meticulously...
$118.7k - $207.8k
AXA Group is seeking a motivated and experienced actuary for their North America Excess Casualty team in Hartford, CT. The role involves developing pricing models, conducting analyses, and collaborating with various stakeholders to drive pricing accuracy. Required skills...$55k - $70k
...Risk Analyst Job Category: Commercial Lines Location: Media, PA 19063, USA Description Join the Porter & Curtis Division of Heffernan Insurance Brokers! We have a consultative commercial insurance model that provides superior client service day in and day...$73.9k - $122.7k
...selections to underwriters. Support rate change and profitability metrics monitoring, including data quality, outlier analysis, and compliance audits. Assist in analyzing portfolio results to evaluate the impact of pricing decisions on future business profitability....Flexible hours- AXA XL is seeking a motivated and experienced actuary for their team in Exton, PA. In this role, you will develop pricing models, conduct analyses, and provide insights to support actuaries and underwriters. You will also mentor junior colleagues and analyze data for strategic...
- ...to validate implementation of changes. Document modeling changes and testing for audit trails and approval processes under the model risk framework. Summarize and present findings in a digestible format for senior audience. Review work by junior model validation team...
- ...dental, and life insurance for employees. This role involves overseeing daily operations, maintaining data integrity, and managing vendor relationships across all US locations. The ideal candidate will have a Bachelor's degree in Human Resource Management or related field...
- ...motivated individual to join the newly established Operational Risk Management - Methodology & Governance team as a Risk Analyst. The... ...& Testing Risk Ranking Methodology Governance, Risk, Compliance “GRC” tooling Partner with one or more business area(s) to: Identify...Work experience placementFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Vendor Risk & Compliance Specialist. Be the first to apply!

