About this role
Enterprise Supplier Risk Analyst
Hybrid – 3 days onsite, Richmond, VA
5 month contract
Position Overview
We are seeking an experienced Enterprise Supplier Risk Analyst to establish and execute a formal Supplier Management and Third-Party Risk Management program. This role will serve as the subject matter expert for supplier oversight, managing the vendor lifecycle from sourcing and due diligence through onboarding, ongoing performance monitoring, renewal, and offboarding.
The successful candidate will design supplier governance frameworks, implement risk-tiering methodologies, and ensure suppliers meet contractual, operational, cybersecurity, financial, and regulatory requirements. This individual will partner closely with Legal, Information Security, Enterprise Risk, Procurement, and business stakeholders to mitigate third-party risk while maximizing supplier value.
Key Responsibilities
- Lead the development, implementation, and ongoing management of a Supplier Management and Third-Party Risk Management program.
- Manage the complete supplier lifecycle, including sourcing support, due diligence, risk assessment, onboarding, monitoring, renewal, and offboarding.
- Develop and maintain supplier governance frameworks, policies, procedures, standards, and reporting.
- Establish and administer a risk-tiering methodology to evaluate suppliers based on criticality, data access, cybersecurity exposure, operational dependency, financial risk, and regulatory impact.
- Conduct and coordinate supplier due diligence assessments, including cybersecurity, privacy, financial, operational, compliance, and reputational reviews.
- Review and assess supplier documentation, including contracts, statements of work, service-level agreements, insurance documentation, security questionnaires, audit reports, and compliance certifications.
- Evaluate supplier compliance with relevant industry standards and controls, including SOC 1, SOC 2, PCI DSS, ISO 27001, and related frameworks.
- Identify supplier risks, document findings, develop mitigation plans, and track remediation activities through resolution.
- Monitor vendor performance, contractual obligations, service levels, risk indicators, and ongoing compliance requirements.
- Partner with Legal, Procurement, Information Security, Risk, Finance, and business owners to ensure appropriate contract terms and risk controls are in place.
- Support contract lifecycle management activities, including supplier renewals, amendments, termination planning, and offboarding.
- Perform cost, value, and performance analyses to support supplier decisions and optimization opportunities.
- Prepare risk reports, dashboards, and executive-level summaries on supplier risk, compliance status, key findings, and remediation progress.
- Build strong working relationships with internal stakeholders and external suppliers to promote accountability and effective risk management.
Required Qualifications
- Demonstrated experience in supplier management, vendor management, third-party risk management, procurement, contract lifecycle management, or a related discipline.
- Strong understanding of supplier due diligence, vendor onboarding, ongoing monitoring, performance management, and offboarding processes.
- Experience developing or enhancing supplier governance frameworks, risk-assessment methodologies, policies, and procedures.
- Knowledge of cybersecurity, operational, financial, regulatory, and compliance risks associated with third parties.
- Familiarity with industry assurance reports and standards, including SOC 1, SOC 2, PCI DSS, ISO 27001, or similar frameworks.
- Ability to read, interpret, and assess contracts, statements of work, service-level agreements, and regulatory requirements.
- Strong analytical and critical-thinking skills, with the ability to evaluate complex information and make sound, risk-based recommendations.
- Excellent verbal and written communication skills, including the ability to influence stakeholders at all organizational levels.
- Strong project management and organizational skills, with the ability to manage multiple vendors, assessments, deliverables, and deadlines simultaneously.
- Highly self-directed and proactive, with the ability to serve as the primary subject matter expert for supplier oversight.
- Collaborative and relationship-focused approach, with the ability to build trust across Legal, Security, Risk, Procurement, Finance, and business teams.
Preferred Qualifications
- Experience establishing a third-party risk management program within a regulated, financial services, government, healthcare, or similarly compliance-driven environment.
- Experience with governance, risk, and compliance (GRC), vendor management, contract lifecycle management, or procurement platforms.
- Certifications such as Certified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Risk Management Professional (CRMP), or similar credentials.
- Familiarity with privacy and data protection requirements, business continuity planning, and supplier incident-management processes.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status.