Jobs · Finance · Georgia

Vendor VMS Risk Management Analyst

Onin Technology · Alpharetta, GA · Yesterday
FinanceFull-time
The Vendor Management Analyst is responsible for supporting the full lifecycle of third-party vendor oversight, including onboarding, due diligence, ongoing risk assessments, and offboarding. Working closely with Information Security, Procurement, Legal, and Business Owners, this role ensures vendors meet contractual, operational, and security requirements while aligning with organizational standards and regulatory expectations. Key Responsibilities Vendor Lifecycle Management Facilitate the end-to-end vendor onboarding process, including intake, documentation collection, due diligence, and initial risk assessments. Maintain accurate, up-to-date vendor records within the Vendor Management System (VMS). Coordinate and execute periodic vendor reviews and ongoing risk assessments. Lead vendor offboarding activities to ensure secure, compliant, and complete disengagement. Risk & Compliance Conduct third-party risk assessments focusing on information security, data privacy, financial stability, and regulatory compliance. Review vendor assurance artifacts, including SOC 1/SOC 2 reports, penetration test results, and cybersecurity questionnaires. Identify control gaps, recommend mitigation steps, and track remediation actions with vendors and internal stakeholders. Support alignment with applicable industry frameworks and regulations (e.g., ISO 27001, NIST, SOC, HIPAA, GLBA, PCI DSS). Contract & SLA Oversight Partner with Legal and Procurement teams to review contracts for vendor risk language, security requirements, Service Level Agreements (SLAs), and data protection clauses. Track and monitor contract expirations, renewals, key milestones, and vendor SLA performance. Stakeholder Collaboration Act as a key liaison between internal teams and external vendors to ensure alignment on requirements and expectations. Provide guidance to business owners on vendor selection, ongoing oversight responsibilities, and risk mitigation strategies. Participate in internal/external audits and regulatory examinations related to third-party risk management. Qualifications Required 2-4+ years of experience in vendor management, third-party risk management (TPRM), procurement, or a related field. Strong familiarity with third-party risk frameworks, security standards, and regulatory expectations. Excellent analytical, organizational, and communication skills. Proven ability to prioritize and manage multiple projects simultaneously in a fast-paced environment. Preferred Direct experience working within an Information Security, Risk, or Compliance environment. Hands-on experience with VMS or TPRM tools (e.g., ServiceNow VRM, OneTrust, Venminder, Archer, etc.). Professional certifications such as CTPRP, CTPRA, CRVPM, Security+, or CISA. Proven ability to interpret SOC reports, penetration tests, and technical vendor documentation. Core Competencies Risk Awareness & Critical Thinking: Ability to evaluate vendor risks pragmatically and pay close attention to critical details. Relationship Management: Strong interpersonal skills to build trust with internal business partners and vendor representatives. Data Analysis & Reporting: Ability to turn complex risk data into clear metrics and actionable insights for management. Process Orientation: Dedication to structured workflows with a continuous improvement mindset.

Similar jobs

Vendor Risk Analyst

Hilltop HoldingsDallas, TX· 3 wk ago
Financeapply on ejlu.fa.us2.oraclecloud.com

Vendor Management Analyst

Willmar Lakes Area Chamber of CommerceClara City, MN· 2 wk ago
Managementapply on public.willmarareachamber.com