Sr Vendor Risk Management Analyst
Virginia, St. Louis County, Minnesota, 55792, USA
Listed on 2026-06-02
-
IT/Tech
Information Security, Cybersecurity, Data Security, IT Business Analyst
Are you ready to join a team that helps Thomson Reuters, a global leader in providing trusted news, information, and software solutions, make informed decisions about the vendors and third-party providers that power our business? We are looking for a Senior Vendor Risk Management Analyst to join our global team in
Richmond, VA,to help continue current vendor risk processes while working to improve the way that we handle incoming and ongoing assessments.
In this role, you will play a critical role in assessing, monitoring, and mitigating the risks associated with our vendors and third-party providers. In this position, you will be responsible for conducting in‑depth risk assessments, analyzing vendor performance, and developing strategic recommendations to ensure that our vendor relationships align with our business goals and risk tolerance. You will work closely with stakeholders across the organization to identify, assess, and mitigate potential risks, and collaborate with vendors to implement risk mitigation plans and monitor their effectiveness.
Aboutthe Role
In this opportunity as
Seniorr Vendor Risk Management Analyst
, you will:
- Vendor Risk Assessment:
Conduct thorough risk assessments of vendors to evaluate their security practices and identify potential vulnerabilities. - Due Diligence:
Perform due diligence on new and existing vendors to ensure they meet security requirements and comply with relevant regulations and standards. - Monitoring and Reporting:
Continuously monitor vendor security performance and report findings to management. Maintain metrics and dashboards for tracking vendor risk. - Policy and Procedure Development:
Develop and maintain policies and procedures related to vendor risk management, ensuring they align with industry best practices and organizational standards. - Collaboration:
Work closely with internal teams, such as procurement, legal, and security, to integrate vendor risk management processes across the organization. - Contract Review:
Assist in the review of vendor contracts to ensure appropriate security clauses and requirements are included. - Incident Response:
Participate in incident response activities related to vendor security breaches, including investigation and remediation efforts. - Continuous Improvement:
Identify opportunities for improving vendor risk management processes and implement changes to enhance overall security posture. - Vendor Compliance:
Ensure that vendor management practices comply with industry standards, such as SOC, ISO, or PCI‑DSS. - Vendor
Risk Management:
Analyze security findings from risk assessments and ensure that they are logged and tracked appropriately in the Enterprise Risk Management tooling.
You’re a fit for the role of
Senior Vendor Risk Management Analyst
if your background includes:
- 5‑7+ years of experience in vendor risk management, third‑party risk, or related fields
- Experience with vendor assessment methodologies and frameworks (e.g., NIST, ISO, SIG)
- Experience with vendor risk assessment tools and databases
- Contract review and negotiation experience
- Strong communication skills for interacting with vendors and internal stakeholders
- Industry certifications such as CTPRP, CRISC, or CISA are considered a plus but are not required for this position
- Hybrid Work Model:
We’ve adopted a flexible hybrid working environment (2‑3 days a week in the office depending on the role) for our office‑based roles while delivering a seamless experience that is digitally and physically connected. - Flexibility & Work‑Life Balance:
Flex My Way is a set of supportive workplace policies designed to help manage personal and professional responsibilities, whether caring for family, giving back to the community, or finding time to refresh and reset. This builds upon our flexible work arrangements, including work from anywhere for up to 8 weeks per year, empowering employees to achieve a better work‑life balance. - Career Development and Growth:
By fostering a culture of continuous learning and skill development, we prepare our talent to tackle tomorrow’s challenges and deliver real‑world solutions. Our Grow My Way programming and skills‑first…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).