Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Third Party Risk Management Analyst

Burke & Herbert Bank

Third-Party Vendor Risk Analyst

Under the direction of the Program Manager, Third Party Risk Management, the Third-Party Vendor Risk Analyst supports the execution of the Bank's Third-Party Risk Management (TPRM) Program by performing day-to-day operational, analytical, and facilitation activities. In partnership with the Program Manager, the Analyst helps strengthen and sustain effective vendor review cadence by coordinating stakeholder inputs, producing complete and traceable documentation, and preparing exam-ready artifacts. This role ensures vendor risk activities—including due diligence, ongoing monitoring, documentation, and issue tracking—are executed in a timely, consistent, and examination-defensible manner.

Execute day-to-day third-party risk management activities for new and existing vendors in accordance with the Bank's TPRM Program, with heightened focus on critical and GLBA-High risk relationships. Support initial due diligence and ongoing risk assessments by collecting, validating, and documenting required artifacts and supporting materials for higher-risk vendors to facilitate effective review, challenge, and approval by the Program Manager.

  • Maintain and manage the rolling vendor review schedule established by the Program Manager, ensuring critical and high-risk third-party relationships are prioritized and reviewed in accordance with established cadence and monitoring requirements. Coordinate with internal stakeholders, including Information Security, IT, Compliance, Finance, and Accounting, to obtain required risk assessment inputs and documentation necessary to support vendor reviews, providing enhanced facilitation for critical and GLBA-High risk vendors.
  • Track vendors review progress, outstanding action items, and remediation activities, maintaining visibility into reviews, documentation gaps, and issue resolution. Proactively escalate aging, overdue, or at-risk items to the Program Manager to support timely awareness, decision-making, and risk mitigation.
  • Prepare, maintain, and organize comprehensive vendor review documentation, including executive summaries, evidence inventories, and issue tracking materials, with enhanced rigor applied to files associated with critical and GLBA-High risk vendors. Ensure that vendor risk conclusions and assigned risk ratings are clearly, consistently, and defensibly supported by documented evidence prior to Program Manager review and sign-off.
  • Assist in documenting risk acceptance decisions and remediation status under the direction of the Program Manager, ensuring alignment with TPRM program standards, internal governance expectations, and applicable regulatory requirements.
  • Identify procedural gaps, workflow inefficiencies, and documentation issues encountered during third-party risk management execution, particularly those impacting oversight of critical and GLBA-High risk vendors. Escalate observations and improvement opportunities to the Program Manager for program-level evaluation and continuous improvement.
  • Support ad hoc projects, process enhancements, and targeted initiatives led by the Program Manager to strengthen third-party risk governance, operational effectiveness, and overall program maturity.

Support the Program Manager by tracking vendor-related review milestones (including onboarding, renewals, and amendments). Ensure required vendor review documentation is complete, accurate, and available to support informed contractual decisions prior to execution.

Compile and maintain program metrics, status reports, and supporting materials used to measure and monitor Third-Party Risk Management (TPRM) program performance. Assist, as directed by the Program Manager, in preparing materials for internal governance forums, audits, and regulatory examinations.

Support internal and external audits and regulatory examinations by organizing vendor files, maintaining evidence mappings, and assembling response documentation under Program Manager guidance. Maintain vendor records in an exam-ready state to support Program Manager interactions with auditors, regulators, and risk committees.

Working knowledge of third-party risk management practices and regulatory expectations within a regulated financial services environment.

  • Strong analytical skills with the ability to assess risk data, identify trends, and support informed decision-making.
  • Excellent organizational and documentation skills with high attention to detail.
  • Ability to collaborate effectively with cross-functional stakeholders while operating under Program Manager direction.
  • Strong written and verbal communication skills to support clear documentation, issue analysis, and timely escalation.
  • Proficiency with Microsoft Office (Excel, Word, PowerPoint) and risk management or workflow tracking tools.

This position does not have supervisory responsibilities.

This job operates in an office setting, the opportunity to telework is not available. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines. Office environment with job duties conducted via telephone, face to face meetings, and on the computer.

This position requires manual dexterity, the ability to lift files and open cabinets. This position requires bending, stooping, or standing, as necessary.

Limited local travel may be required for this position.

Requires a bachelor's degree in business, Finance, Risk Management, Information Systems, Compliance, or a related field or equivalent professional experience supporting risk management functions in a regulated environment.

  • Requires a minimum of 1 year of experience supporting third-party vendor management, operational risk, compliance, information security, or a related risk discipline within a regulated industry.
  • Requires hands-on experience supporting vendor due diligence, ongoing monitoring, documentation, and issue tracking activities.
  • Experience coordinating with cross-functional stakeholders (e.g., Information Security, IT, Compliance, Finance) to collect and organize risk assessment inputs.
  • Experience producing or maintaining clear, well-organized, and evidence-based documentation to support management review, audit, or regulatory examination.

Equal Employment Opportunity/M/F/disability/protected veteran status.

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

Vacancy posted 5 hours ago
Similar jobs that could be interesting for youBased on the Third Party Risk Management Analyst in Alexandria, VA vacancy
  • $80.83k - $129.32k

     ...Third-Party Risk Management Analyst Location : Location US-MD-Bethesda ID 2025-2096 Location : Address 7500 Old Georgetown Road Position Type Full Time Regular Business Unit Description Risk and Compliance Overview... 
    Suggested
    Full time
    Work at office
    Remote work
    Flexible hours

    EagleBank

    Bethesda, MD
    5 days ago
  • $120.8k - $137.9k

    Capital One is seeking a Principal Associate for the Third Party Risk Management (TPRM) Team in McLean, VA. In this role, you will assess risks before procurement and provide oversight to ensure effective management of operational risks. You should have at least 3 years... 
    Suggested

    Capital One

    Mc Lean, VA
    2 days ago
  • Overview Join to apply for the Enterprise Risk Management Analyst Journeyman role at Spectrum Comm Inc Pentagon, Arlington, VA Spectrum is currently seeking a Management Analyst to support our customer site and support the Department of Navy’s Business Operations Service... 
    Suggested
    Full time

    Spectrum Comm Inc

    Arlington, VA
    2 days ago
  •  ...Cyber Supply Chain Risk Management Analyst We are seeking a technically proficient Cyber Supply Chain Risk Management (C-SCRM) professional...  ...: Evaluate vendor and supplier security postures (third-party/fourth-party) using frameworks such as NIST SP 800-161.... 
    Suggested

    WISC Enterprises, LLC

    Springfield, VA
    5 days ago
  • $62.64k - $89.49k

     ...is currently seeking an Intermediate-level Supply Chain Risk Management (SCRM) Audit Analyst to work out of Fairfax, VA in support of the DoD/DoW...  ...classified environments. Conducts structured analysis of third‑party vendor security documentation, evaluating cybersecurity... 
    Suggested
    Full time
    Contract work
    Work at office
    Local area

    Huntington Ingalls Industries

    Fairfax, VA
    3 days ago
  • $80.83k - $129.32k

    Eagle Bancorp, Inc. is looking for a Third-Party Risk Management Analyst in Bethesda, MD. The role involves ensuring vendor and service provider compliance with regulatory guidelines, managing risks, and collaborating with cross-functional teams. The ideal candidate will... 
    Work at office

    Eagle Bancorp, Inc.

    Bethesda, MD
    2 days ago
  •  ...Job Title: Risk Management Analyst Job ID: 86542 Location: Landover, Maryland Overview: We are seeking aRisk Management Analysts who will play a pivotal role in supporting our federal partner's cybersecurity and compliance efforts. What you will be doing:... 

    TEEMA

    Hyattsville, MD
    1 day ago
  •  ...Enterprise Risk Management Analyst We are seeking an Enterprise Risk Management Analyst to support the Department of State IT Governance Support Services Bureau of Consular Affairs. This position supports the decision-making framework for addressing several enterprise... 
    Work at office

    Ryde Technologies

    Washington DC
    4 days ago
  • $80k - $90k

    A leading technology company in Washington, D.C. is seeking a Risk Management Analyst to join a federal Electronic Health Record Modernization program. This role involves identifying, assessing, and mitigating risks across deployment sites to ensure successful implementation... 

    SteerBridge

    Washington DC
    2 days ago
  •  ...Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst Location: Washington, DC Schedule: Onsite, 5 days/week Position Type: Direct Hire Clearance Required: Active TS clearance required at time of application. Must be willing and able to obtain... 

    JCD Staffing

    Washington DC
    21 hours ago
  •  ...and winning ideas. Military Veterans Encouraged to Apply. Job Description: The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports the Agency's Office of the Chief Information Officer (OCIO) by managing cybersecurity risks associated with... 
    For contractors
    Work at office

    Network Designs

    Washington DC
    4 days ago
  • A modern technology company in Washington is seeking a Risk Management Analyst to support a federal Electronic Health Record Modernization program. The role involves identifying, assessing, and mitigating risks to ensure successful implementation of the Federal EHR system... 

    SteerBridge

    Washington DC
    5 days ago
  •  ...Senior Cybersecurity Supply Chain Risk Management Analyst We are an IT Services company founded to create innovative solutions to enhance the capabilities of our customers. Our employees have successfully satisfied the technology needs of the U.S. Government and we... 

    STEM Solutions

    Washington DC
    2 days ago
  • $110k - $130k

     ...long-lasting results. Job Description: G3 Innovative Solutions is currently seeking a Senior Cybersecurity Supply Chain Risk Management Analyst to supports OCIO's focus on the information, communications, and operational technology (ICT/OT) users who rely on a... 
    Full time

    Resilient Solutions Plus

    Washington DC
    5 days ago
  • $110k - $130k

     ...Overview Senior Cybersecurity Supply Chain Risk Management Analyst G3 Innovative Solutions, LLC is an IT Services company focused on innovative solutions for the U.S. Government. This role supports OCIO's focus on ICT/OT users within a complex, globally distributed... 
    Full time

    Resilient Solutions Plus, LLC

    Washington DC
    3 days ago
  • $80k - $85k

    Walker & Dunlop in Bethesda, MD is seeking a Risk Management professional to support the coordination of risk assessments and monitor Key Risk Indicators for multifamily lending. The role demands strong analytical and organizational skills, along with a bachelor's degree... 
    Remote job

    Walker & Dunlop

    Bethesda, MD
    2 days ago
  •  ...Description Tyto Athene is searching for a forward-thinking and self-motivated Supply Chain Risk Management (SCRM) Analyst to support one of our law enforcement customers in Washington, DC. You will be responsible for helping Federal customers solve one of the most... 
    Full time
    Work experience placement
    Worldwide

    Tyto Athene, LLC

    Washington DC
    3 days ago
  • Job Role: Cybersecurity Supply Chain Risk Management Analyst Location: Washington, DC Duration: Full Time, Onsite Clearance: Active Top Secret Requirements Network+ and Security+ certifications or similar IT certifications are preferred. Provides analytical support... 
    Full time

    Maania Consultancy Services

    Washington DC
    2 days ago
  • $107.32k - $150k

     ...HII designs, develops, integrates and manages the sensors, systems and other assets necessary...  ...? We are seeking talented and motivated Analysts to join our team! Position Summary:...  ...Technologies is seeking a Supply Chain Risk Management (SCRM) Intelligence Analyst for... 
    Full time
    Work at office
    Local area
    Remote work
    Worldwide

    Huntington Ingalls Industries

    Riverdale, MD
    8 days ago
  • Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst Job Description The Senior Cybersecurity Supply Chain Risk Management (SCRM) Analyst supports a Federal Agency by managing cybersecurity risks across the Agency’s complex, Interconnected Information, Communications... 
    Remote work

    Nucorevision, Inc

    Washington DC
    5 days ago
  •  ...Senior Analyst, Cybersecurity Governance, Risk and Compliance, Washington, DC The Senior Analyst, Cybersecurity Governance...  ..., and procedures implemented for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and... 
    Work experience placement

    Next Step Systems LTD

    Washington DC
    4 days ago
  •  ...Private Risk Advisor The USI Insurance Services Personal Risk Practice provides comprehensive risk management and insurance consultation to high net worth individuals and family...  ...Engage, introduce and position value-added third-party subject matter experts in response to... 
    Work at office
    Local area

    USI Insurance Services

    Falls Church, VA
    6 days ago
  •  ...CLASSIFICATION: Non-exempt REPORTS TO: Regulatory Affairs Manager DATE: April 30, 2026 JOB DESCRIPTION Summary/Objective The Enterprise Risk Analyst supports the execution and continued evolution of the Company's Enterprise Risk Management (ERM) program... 
    Work at office
    Local area
    Remote work

    Burke & Herbert Bank

    Alexandria, VA
    4 days ago
  •  ...CeLeen, an operating firm of Command Holdings, is seeking a Management Analyst to support the Cybersecurity and Infrastructure Security Agency...  ...The Management Analyst shall assist and provide research, risk management, and cyber-physical security analytic support services... 
    Full time
    Contract work
    For contractors
    Work at office
    Local area
    Visa sponsorship
    Work visa
    Flexible hours

    Command Holdings

    Arlington, VA
    2 days ago
  • Risk & Controls Analyst ProSidian is a Management and Operations Consulting Services firm that focuses on providing value to clients through tailored solutions based on industry-leading practices. ProSidian provides enterprise services/solutions for Risk Management | Compliance... 
    Full time
    Contract work
    H1b
    Work at office

    ProSidian Consulting

    Alexandria, VA
    3 days ago
  •  ...Description:\n\nCompany Description ProSidian is a Management And Operations Consulting Services firm...  ...enterprise services/solutions for Risk Management | Compliance | Business...  ...Seeks a Records Management & Compliance Analyst | Data Management & Business Intelligence... 
    Full time
    Contract work
    Temporary work
    For contractors
    H1b
    Work at office
    Flexible hours

    ProSidian Consulting, LLC

    Alexandria, VA
    4 days ago
  • $45.48 - $50.48 per hour

    Job Description Day to Day: Insight Global is hiring a Risk Assessment Analyst, sitting hybrid in Alexandria, VA, to support senior DoD leadership in advancing cybersecurity and supply chain risk management across the Defense Industrial Base (DIB). This individual will... 

    Insight Global

    Alexandria, VA
    5 days ago
  • Tecolote Research, Inc. in Arlington, Virginia is seeking a skilled schedule and risk analyst with expertise in schedule analysis and risk management. This senior-level role involves participating in DOE acquisition reviews and requires proficiency in Oracle Primavera... 

    Tecolote Research, Inc.

    Arlington, VA
    2 days ago
  •  ...Role: Technical Risk Analyst Location: Open to hybrid in Vienna, VA, Wichester, VA,...  ...designated to support the Operational Risk Management (ORM) role for Issue Management. The...  ...staff, management, stakeholders, and third parties • Ability to build effective relationships... 
    For contractors
    Remote work

    TechWish

    Fairfax, VA
    1 day ago
  • $131.3k - $237.35k

     ...Modernization sector seeks an experienced SCRM Analyst SME to support the delivery, enhancement,...  ...Conduct comprehensive Cyber Supply Chain Risk Assessments on systems, products, and...  ..., Executive Orders, and Office of Management and Budget (OMB) memorandums. Ensure continuous... 
    Work at office

    Leidos LLC

    Alexandria, VA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Third Party Risk Management Analyst. Be the first to apply!