Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Vendor Risk Analyst

$100k - $130k

Fortress Information Security

Senior Vendor Risk Analyst

Location: Hybrid – Candidates must be based in one of the following areas Naperville, IL / Birmingham, AL / Atlanta, GA. You will work out of the client site closest to your location three days per week, with an expectation of four days per week later in 2026.

Compensation: $100,000 - $130,000 per year, depending on experience and qualifications. Employment Type: Full-Time Travel: Less than 15%, occasional travel for industry collaboration or professional development

What You Can Expect As The Senior Vendor Risk Analyst At Fortress

The Senior Vendor Risk Analyst plays a pivotal role within the Supply Chain Risk Management (SCRM) team, leading third-party vendor risk assessments and shaping how a major energy organization manages supply chain cyber risk. Working directly with vendor relationship owners and cross-functional stakeholders across Legal, Supply Chain, Cybersecurity, and Technology, this role drives continuous improvement of the Third-Party Risk Management (TPRM) program and directly influences leadership-level business decisions. This position provides meaningful exposure to critical infrastructure protection under NERC CIP standards and offers a mission-driven opportunity to help secure systems that society depends on. This is an ideal role for an experienced risk professional seeking broad organizational influence, visibility, and impact. This role offers the opportunity to work closely with a major energy sector client in a highly integrated capacity. Based on performance, business needs, and client discretion, there may be future opportunities to transition into direct employment with the client organization.

Job Responsibilities

  • In coordination with the customers vendor relationship owners, manage assessments of vendors' security controls to identify shortfalls.
  • Communicate remediation options to the vendors
  • Collaborate with TPRM team members and business partners to complete assessments and determine risk mitigation strategies
  • Become an expert of the TPRM platform to identify and direct necessary customizations, enhancements, and record maintenance to a vendor-supported platform that enable relevant reporting and Program maturation
  • Develop an appreciation and understanding of various business units while employing your knowledge of security fundamentals to effectively communicate customer risk resulting from assessment findings
  • Proactively propose and implement changes to customer Program policy/practice to ensure a risk-informed approach to vendor/supply chain management
  • Collaborate across Supply Chain, Legal, Cybersecurity, and the Technology Organizations to create a shared picture of supplier risk
  • Support cross-functional teams to investigate, analyze, and make recommendations to leadership or process owners regarding technology solutions, security architecture, or security vulnerabilities
  • When appropriate, collaborate across Cyber org to identify compensating controls for significant vendor-specific risks to the company and its customers
  • Review vendor-proposed modifications to Master Service Agreements or Application Service Provider Agreements on behalf of customer to identify any unacceptable security risks associated with new language
  • Understand, relate, and transform regulatory requirements into information security policy, standards, procedures, and guidelines
  • Maintain current knowledge of information security concepts, technologies, and practices
  • Apply deep cybersecurity expertise to assess vendors' security controls, identify cyber risk gaps, and translate technical findings into actionable business recommendations.

Required Qualifications

  • United States citizenship is required
  • 7-10 years experience in security risk assessment, risk management, compliance or auditing
  • Strong knowledge of cybersecurity control frameworks (e.g., NIST SP 800-53, ISO/IEC 27001:2013), with direct cybersecurity experience conducting or overseeing security assessments, control design reviews, or cybersecurity audits
  • Ability to communicate clearly, confidently, and knowledgeably to internal and external stakeholders regarding the Program and assessment results
  • Demonstrated history of critical, independent, and creative thinking to enable continuous improvement or business success within the constraints of security imperatives
  • Ability to holistically assess the risk of a third party engagement, considering control gaps, the nature of the vendor relationship, and the way a vendor's products/services are leveraged
  • Must have demonstrated history of critical, independent, and creative thinking with high attention to detail; this will enable continuous improvement and ensure auditable record trail for all assessment data
  • Prior experience overseeing one or more people in support of a technology solution or program
  • Demonstrated ability to work with and in cross-functional teams
  • One or more of the following certifications: TPCRA, C3PRMP, CTPRA CISSP, CASP, CISA, CISM, GIAC, PMP
  • Must be able to pass NERC CIP and Insider Threat Program background screening due to access to sensitive critical infrastructure and information regarding security capabilities
  • Occasional travel for industry collaboration/influence or professional development is expected
  • This is a hybrid role but three days per week in the office (Naperville, IL, Birmingham, AL or Atlanta, GA) is expected initially but will grow to four days per week in office during 2026. In-office expectations may change over time depending on organizational policy and supervisor's requirements.
  • Education: Bachelor's degree or equivalent experience in a related field required

Preferred Qualifications

  • Experience working in a highly regulated industry
  • Prior experience advocating security policies, practices, controls, and standards to business and IT teams
  • Familiarity with basic requirements for architecting secure information systems
  • Familiarity with NERC's Critical Infrastructure Protection (CIP) standards
  • Experience with non-IT risk such as operational, financial, Compliance and Regulatory, Strategic Risk, Legal Risk, and ESG risk (Environmental, Social, and Governance)

Employee Benefits

  • Remote and Hybrid working environment
  • Competitive pay structure
  • Medical, dental, vision plans with employees covered up to 90% with highly progressive options for dependents and families
  • Company paid life, short- and long-term disability insurance
  • Employee Assistance Program
  • 401(k) match
  • Flexible Paid Time Off
  • Parental Leave

Employment Perks

  • We provide each employee with professional growth opportunities through succession planning, up-skilling, and certifications
  • Tuition and certification reimbursement
  • Employee Referral Programs
  • Company Sponsored Events

Foretress is proud to be an Equal Opportunity Employer. All employees and applicants will receive consideration for employment without regard to age, color, disability, gender, national origin, race, religion, sexual orientation, gender identity, protected veteran status, or any other classification protected by federal, state, or local law. Fortress Information Security takes part in the E-Verify process for all new hires. For positions located in the US, the following conditions apply. If you are made a conditional offer of employment, you will have to undergo a drug test. ADA Disclaimer: In developing this job description care was taken to include all competencies needed to successfully perform in this position. However, for Americans with Disabilities Act (ADA) purposes, the essential functions of the job may or may not have been described for purposes of ADA reasonable accommodation. All reasonable accommodation requests will be reviewed and evaluated on a case-by-case basis.

Vacancy posted 6 hours ago
Similar jobs that could be interesting for youBased on the Senior Vendor Risk Analyst in Birmingham, AL vacancy
  • $62.99k

     ...will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and...  ...Job Description: At Regions, the Business Unit Operational Risk Analyst works within a given line of business to help ensure the line... 
    Suggested
    Full time
    Work at office
    Flexible hours

    Regions Bank

    Birmingham, AL
    6 days ago
  • $65.85k

     ...be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and experience...  ...of the system. Job Description: At Regions, the Risk Credit Reporting Analyst assists in the analysis of the company's risk and prepares... 
    Suggested
    Full time
    Work at office
    Flexible hours

    Regions Bank

    Birmingham, AL
    6 days ago
  • $80.63k

     ...reviewed by associates, consultants, and vendors of Regions in order to evaluate...  ...Description: At Regions, the Risk Quantitative Model Validation Analyst serves as a member of a key strategic...  ...from validation manager and/or senior validation analyst and summarizes test... 
    Suggested
    Full time
    Work experience placement
    Flexible hours

    Regions Bank

    Birmingham, AL
    2 days ago
  •  ...Senior Business Analyst Location: Alabama, United States – Onsite Note – We need someone with hands...  ...closely with business stakeholders, vendors, and PMO teams Review and support project...  ...impacts Track project artifacts, risks, issues, and action items Support... 
    Senior
    For contractors

    RIT Solutions

    Homewood, AL
    3 days ago
  • $91k - $321.5k

     ...Specialty/Competency: IFS - Risk & Quality (R&Q) Industry/Sector: Not Applicable Time Type: Full time Travel Requirements...  ...As a Risk Management - Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise risk management... 
    Senior
    Full time
    Contract work
    H1b

    PwC

    Birmingham, AL
    8 days ago
  •  ...Business Insurance Sr. Risk Control Consultant Our not-so-secret sauce. Award-winning, inclusive, top workplace culture doesn't happen overnight. It's a result of hard work by extraordinary people. More than 11,000 of the industry's brightest talent drive our efforts... 
    Senior
    Work at office
    Local area
    Night shift
    3 days per week

    Marsh & McLennan

    Birmingham, AL
    1 day ago
  •  ...Personal Risk Specialist The Personal Risk Specialist is an outside sales position focused on serving the unique insurance needs...  ...beautification and restoration projects to partnering with eco-conscious vendors and taking steps to reduce our own environmental footprint we're... 
    Temporary work
    Local area
    Flexible hours

    USI Insurance Services

    Birmingham, AL
    4 days ago
  •  ...Operational Risk Consultant Sr. – Business Risk Oversight Officer Job Category: Banking Requisition Number: OPERA016708 Location: On site at location(s) listed in job posting. Summary: As the Business Risk Oversight Officer within our second line of defense (... 
    Senior

    First Horizon

    Birmingham, AL
    3 days ago
  •  ...sensitivity analyses, projecting competitive behaviors, identifying risks, and interpreting solicitation requirements. - Act as a member...  .... - Participate in strategy meetings, status meetings and senior management reviews including the presentation of competitive analyses... 
    Senior
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Local area

    MAXIMUS

    Birmingham, AL
    2 days ago
  •  ...problems. Ensuring that sufficient sketches and details are provided for completion of engineering drawings. Reviewing and checking vendor drawings and other discipline drawings for electrical/instrumentation input. Producing bid packages enabling electrical/... 
    Senior
    Local area

    Hargrove Engineers + Constructors

    Birmingham, AL
    1 day ago
  •  ...Senior Electrical Engineer – Fossil Generation Experience Level: 10+ Years Industry: Power Generation (Fossil-Fired Plants) Location...  ...Communicate effectively with plant operations, maintenance, vendors, and other engineering disciplines Build effective working relationships... 
    Senior
    Contract work
    Local area

    4P Consulting Inc

    Vestavia Hills, AL
    3 days ago
  • $80 per hour

     ...Our client, a leading organization in the industry, is seeking a dedicated and skilled Senior Workday HCM Analyst, Recruiting, to join their dynamic team. As a Senior Workday HCM Analyst, Recruiting, you will be an integral part of the Human Resources and Talent Acquisition... 
    Senior
    Weekly pay
    Temporary work
    Remote work
    Flexible hours

    ManpowerGroup Global, Inc.

    Birmingham, AL
    4 days ago
  • $80k - $95k

     ...Senior Accountant Senior Accountant Birmingham, Alabama $80,000 - $95,000 An established organization is hiring...  ...and entities Maintain ownership of expense areas tied to vendor services, infrastructure support, and production-related inputs... 
    Senior
    Contract work
    Local area

    PangeaTwo

    Birmingham, AL
    2 days ago
  •  ...Advocacy Lead the resolution of complex claims by serving as the primary liaison between clients, carriers, TPAs, and specialized vendors. Advocate for clients throughout the claim lifecycle, ensuring timely communication, accurate reserving, and effective claim... 
    Senior
    Work at office

    Lockton, Inc.

    Birmingham, AL
    3 days ago
  • $175k - $225k

     ...in Microsoft Office, FactSet, and other investment industry standard data sources To land this role you will need: * Senior Sell Side Analyst with 15+ names under coverage * Displays integrity, teamwork and a strong work ethic * Excellent analytical, written and... 
    Senior
    Permanent employment
    Full time
    Work at office

    StoneX Group Inc.

    Birmingham, AL
    4 days ago
  • $83.5k

     ...will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and...  ...Job Description: At Regions, the Business Unit Operational Risk Analyst works within a given line of business to help ensure the line... 
    Full time
    Flexible hours

    Regions Bank

    Vestavia Hills, AL
    1 day ago
  • $50.5k

     ...will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and experience...  ...agency, bank and federal guidelines and procedures to mitigate risk Works under limited direction and/or supervision This position... 
    Full time
    Work at office
    Flexible hours

    Regions Bank

    Vestavia Hills, AL
    3 days ago
  •  ...customers. This position is responsible for leading technical discussions with general and electrical contractors, engineering firms, vendors, end users and internal departments to successfully achieve project milestones and ensure ultimate customer satisfaction. What... 
    Senior
    For contractors
    Flexible hours

    Nixon Power Services

    Gardendale, AL
    5 days ago
  •  ...Senior Technical Delivery Manager – Open Banking & Open Finance Location: Charlotte,...  ...production sign-off Actively remove delivery risks related to: Architecture gaps...  ...throw over the wall.” 7. Stakeholder, Vendor & Executive Management Act as single... 
    Senior

    United IT

    Birmingham, AL
    3 days ago
  •  ...-5 years of industry experience Career Level Senior Salesperson Exemption Exempt Senior Account...  ...estimating. Business Development. Networking with vendors, suppliers and industry contacts. Creation of quotes and scopes... 
    Senior
    Full time
    Contract work

    Next Gen Security, Inc.

    Irondale, AL
    4 days ago
  •  ...multiple projects simultaneously. and the ability to build effective relationships with plant staff, design engineering staff and/or vendors. dditional qualification preferences/requirements : Engineering degree from an ABET accredited institution is... 
    Senior
    Work at office
    Local area

    Varite

    Birmingham, AL
    2 days ago
  •  ...Senior Leader, Information Systems About the Company Top health maintenance organization providing quality, accessible health care...  ...development leadership, ETL/EDI pipelines, project execution, vendor partnerships, data security, privacy oversight, and business continuity... 
    Senior

    Confidential

    Birmingham, AL
    2 days ago
  •  ...Pharmacy DevOps Analyst, Senior The Pharmacy Care Management Platform team delivers all IT Pharmacy solutions to support Pharmacy Operations and Pharmacy Transformation. The DevOps Analyst, Senior will report to the Pharmacy Development Senior Manager. In this role... 
    Senior
    Full time
    Part time
    Work at office
    Local area
    Work from home
    Home office
    2 days per week

    Blue Shield Of California

    Homewood, AL
    4 days ago
  • $84.57k

     ...collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and...  ...Description: At Regions, the Business Unit Compliance Analyst is a first line of defense risk management function that ensures that business unit... 
    Full time
    Work at office
    Flexible hours

    Regions Bank

    Vestavia Hills, AL
    2 days ago
  • $81.29k

     ...will be collected and reviewed by associates, consultants, and vendors of Regions in order to evaluate your qualifications and...  ...Description: At Regions, the Enterprise Compliance and Operational Risk Analyst serves as a member of Regions’ second line of defense risk... 
    Full time
    Work at office
    Flexible hours

    Regions Bank

    Birmingham, AL
    2 days ago
  •  ...candidates. Forvis Mazars, LLP expressly reserves the right not to consider any unsolicited referrals, resumes or CVs from vendors including and without limitation, search firms, staffing agencies, fee-based referral services, and recruiting agencies.... 
    Senior
    Work at office
    Flexible hours
    Night shift

    Forvis Mazars

    Birmingham, AL
    3 days ago
  •  ...Position Summary The Senior Staff Accountant is responsible for preparing, analyzing, and maintaining accurate financial records...  ...audit assistance. Coordinate with accounting software vendors; recommend system enhancements and updates as needed. Manage... 
    Senior
    Work at office

    Alabama Regional Medical Services

    Birmingham, AL
    3 days ago
  •  ...and Responsibilities: - Perform complex risk analyses and risk assessment. -...  ...remediation with internal stakeholders and vendors, and deliver recurring leadership reporting...  ...market and internal value analysis including seniority and merit systems, as well as internal... 
    Senior
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    For subcontractor
    Work at office

    MAXIMUS

    Birmingham, AL
    1 day ago
  • $90k - $185k

     ...principal engineers. Our Electrical Engineer career path has many options. You can bring your experience to our mid-level and senior roles, or step into a principal engineer position where you'll lead and mentor others. We continually invest in our employees and... 
    Senior
    Full time
    Temporary work
    Part time
    Remote work

    Enercon

    Birmingham, AL
    1 day ago
  •  ...POSITION SUMMARY & RESPONSIBILITIES: We are seeking a Senior Accounting Associate - Midstream Accounting to support our midstream...  ...accounting and analysis for a portfolio of customers and vendors across our pipeline systems and plays a critical role in delivering... 
    Senior
    Work at office

    Diversified Gas & Oil Corporation

    Birmingham, AL
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Vendor Risk Analyst. Be the first to apply!