City/StateNorfolk, VA
Work ShiftFirst (Days)
Overview:OverviewThe Third-Party Risk Program Manager is responsible for the end-to-end management of the organization's third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle - from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding - ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness
Key ResponsibilitiesProgram Management - Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle
- Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders
- Identify process gaps and drive continuous improvement of program workflows
- Be a part of the team and support the execution of the program
Vendor Management - Serve as the primary point of contact for third-party vendors throughout the assessment and management process
- Coordinate with vendors to gather required documentation, evidence, and remediation plans
- Track vendor responsiveness and escalate delays or non-compliance issues appropriately
Risk Assessments (OneTrust) - Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion
- Analyze assessment results to identify risk levels, gaps, and required remediation actions
- Maintain accurate, up-to-date vendor and assessment records within OneTrust
- Generate reports and dashboards from OneTrust to support program reporting and audits
Documentation & Compliance - Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current
- Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)
- Support internal and external audits by providing timely and accurate documentation
Cross-Functional Collaboration - Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage
- Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike
- Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward
Education- Bachelor Level Degree (Preferred)
- 5+ years relevant experience may be accepted in lieu of degree
Certification/Licensure- Certification in risk, or compliance (e.g., CTPRP, CRISC) preferred
ExperienceRequired - Bachelor's degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry
- 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry without a Bachelor's degree preferred.
- Hands-on experience with OneTrust or similar GRC/risk management platforms
- Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements
- Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously
- Excellent written and verbal communication skills, with experience working cross functionally
Preferred - Certification in risk, or compliance (e.g., CTPRP, CRISC)
- Experience with vendor contract review or working alongside Legal/Procurement
- Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)
We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:$106,080.00-$176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.
Benefits: Caring For Your Family and Your Career• Medical, Dental, Vision plans
• Adoption, Fertility and Surrogacy Reimbursement up to $10,000
• Paid Time Off and Sick Leave
• Paid Parental & Family Caregiver Leave
• Emergency Backup Care
• Long-Term, Short-Term Disability, and Critical Illness plans
• Life Insurance
• 401k/403B with Employer Match
• Tuition Assistance - $5,250/year and discounted educational opportunities through Guild Education
• Student Debt Pay Down - $10,000
• Pet Insurance
• Legal Resources Plan
• Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.