VA
Third-Party Risk Analyst
Vanta · San Francisco, CA
Compensation
$60k–$78kper year
HybridFull-timeGovernance Risk & Compliance
📋Plain English
What is GRC?
You review policies, check systems, and write reports. The least technical path into cybersecurity.
This role is for you if you're organized, love checklists, and communicate clearly.
📋About the Role
Evaluate the security posture of third-party vendors. Conduct risk assessments using SIG questionnaires, review security documentation, and track remediation of identified gaps.
Vendor RiskQuestionnairesSIGTiering
Your roadmap to get this job
Most people finish in 10–18 weeks from zero.
▸CompTIA Security+
▸Read NIST Framework
▸Learn risk assessment
▸Study SOC 2 / ISO 27001
▸Write practice assessments
▸Create sample deliverables
▸Highlight transferable skills
▸Apply to GRC roles
▸Use writing strengths
Want the full GRC career guide?
Salary data, day-in-life, personality match, full roadmap.
Read guide →