
Senior Manager, Third Party Risk
Posted Sep 9

Posted Sep 9
This is a fully remote position, open to applicants in Texas.
• Develop, lead, and enhance Baylor Genetics’ enterprise Third-Party Risk Management program.
• Oversee the complete vendor lifecycle, which includes intake, risk categorization, security and privacy evaluations, onboarding, continuous monitoring, and offboarding.
• Conduct security and cybersecurity evaluations for medium- and high-risk vendors.
• Implement vendor onboarding, ongoing monitoring, and reassessment procedures utilizing the SIG questionnaire.
• Create standard operating procedures (SOPs), policies, and documentation that govern vendor intake, assessment, and monitoring.
• Perform internal and external vendor audits, particularly focusing on high-risk upstream vendors that handle PHI, PII, and AI.
• Classify vendors by their criticality and maintain a vendor risk heat map along with a single source of truth.
• Manage continuous vendor monitoring, oversee remediation efforts, and coordinate BAAs/DPAs, DPIAs/TIAs, and sub-processor obligations.
• Develop and oversee the quarterly User Access Review program for applications in scope, including accounts for employees, contractors, temporary staff, vendors, administrators, and privileged users.
• Enforce least-privilege access principles, gather attestations, and generate audit evidence.
• Facilitate audit preparedness and evidence gathering for compliance with ISO 27001, ISO 27701, ISO 42001, and HITRUST standards.
• Generate leadership reports, KPIs, and risk metrics regarding vendor risk posture, remediation efforts, and audit progression.
• Collaborate with teams in Security, Privacy, Compliance, Procurement, Legal, and application domains.
• Evaluate application-security evidence, including results from static code analysis tools like SonarQube/SAST.
• Foster a culture of integrity and service while fulfilling other assigned responsibilities.
• Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related discipline, or a comparable combination of education and experience.
• At least 6–8 years of experience in information security, risk management, or compliance, including developing and managing upstream and downstream vendor management programs.
• Practical audit experience with ISO 27001, ISO 27701, and ISO 42001.
• Proven experience with HITRUST, encompassing assessment, readiness, and/or certification support.
• Background in creating and managing recurring User Access Review programs and implementing least-privilege access controls.
• Familiarity with vendor risk assessment methodologies, such as SIG, along with risk scoring and tiering.
• Strong knowledge of HIPAA, GDPR, and security standards for PHI and sensitive PII.
• Preferred certifications include CTPRP, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer.
• Experience with GRC platforms, such as TrustArc, and vendor risk management tools is preferred.
• Previous experience in a healthcare, clinical laboratory, or other regulated HIPAA/PHI environments is preferred.
• Experience in people or program management, leading assessments and coordinating cross-functional teams is preferred.
• Strong analytical skills and risk-based judgment with a keen eye for detail.
• Exceptional written and verbal communication abilities, capable of conveying complex risks to both technical and executive audiences.
• Proficient in program and project management, handling multiple assessments and deadlines concurrently.
• Ability to influence collaboratively across Security, Privacy, Compliance, Procurement, and business units.
• Capability to work remotely and travel occasionally to headquarters, meetings, vendor audits, or conferences.
• Remote work arrangement.
• Occasional travel to the headquarters in Houston, Texas.
• Occasional travel for meetings, vendor audits, or conferences.
Horizon Connect @ Wall BCBSNJ
Experian
Ignition
Experian
Get handpicked remote jobs straight to your inbox weekly.