Program Manager – Third Party Risk Management
About the role
The Third-Party Risk Program Manager is responsible for the end-to-end management of the organization’s third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle — from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding — ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy.
Responsibilities
- Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle
- Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders
- Identify process gaps and drive continuous improvement of program workflows
- Serve as the primary point of contact for third-party vendors throughout the assessment and management process
- Coordinate with vendors to gather required documentation, evidence, and remediation plans
- Track vendor responsiveness and escalate delays or non-compliance issues appropriately
- Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion
- Analyze assessment results to identify risk levels, gaps, and required remediation actions
- Maintain accurate, up-to-date vendor and assessment records within OneTrust
- Generate reports and dashboards from OneTrust to support program reporting and audits
- Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current
- Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)
- Support internal and external audits by providing timely and accurate documentation
- Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage
- Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike
- Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward
Qualifications
A Bachelor's degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry. Alternatively, 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry, may be accepted in lieu of a degree.
Skills
- Hands-on experience with OneTrust or similar GRC/risk management platforms
- Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements
- Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously
- Excellent written and verbal communication skills, with experience working cross functionally
- Certification in risk, or compliance (e.g., CTPRP, CRISC) preferred
- Experience with vendor contract review or working alongside Legal/Procurement
- Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)
Benefits
- Medical, Dental, Vision plans
- Adoption, Fertility and Surrogacy Reimbursement up to $10,000
- Paid Time Off and Sick Leave
- Paid Parental & Family Caregiver Leave
- Emergency Backup Care
- Long-Term, Short-Term Disability, and Critical Illness plans
- Life Insurance
- 401k/403B with Employer Match
- Tuition Assistance – $5,250/year and discounted educational opportunities through Guild Education
- Student Debt Pay Down – $10,000
- Pet Insurance
- Legal Resources Plan
Pay
The base pay rate for Full Time employment is: $106,080.00-$176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.
Schedule
Work Shift: First (Days)