Description
The Vendor Security Analyst evaluates third-party and vendor engagements, assesses vendor risk, reviews security questionnaires, recommends risk mitigations, maintains a vendor risk repository, and conducts onsite security audits of high-risk vendors. The role reports to the Head of Information Risk and requires information security risk assessment, technical security knowledge, risk management, vulnerability management, and third-party risk expertise. It is based in Washington, D.C., with a standard 37.5-hour workweek and a base salary of $120,500 to $146,200 per year.
