1

Third Party Risk Management Manager Jobs in Pennsylvania

... includes Third-Party Risk Management as well as senior risk professionals. Trust Risk at Autodesk is an established team and program. We are looking for a leader with the lived experience of ...

... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...

... Management, and Third-Party Risk Management workstreams in partnership with architects and product owners * Managing stakeholder engagement and executive communications; facilitating decisions ...

... Third-Party Risk Management, and ServiceNow AI Control Tower use cases * Contributing to functional design and configuration of ServiceNow solutions, including forms, workflows, notifications ...

Cybersecurity Program Manager

State College, PA · On-site

$108K - $146K/yr

Contribute to the full lifecycle of the ISO 27001-certified program, including policy development, risk management, compliance oversight, audit coordination, third-party risk management, incident ...

Cybersecurity Program Manager

State College, PA · On-site

$108K - $146K/yr

Contribute to the full lifecycle of the ISO 27001-certified program, including policy development, risk management, compliance oversight, audit coordination, third-party risk management, incident ...

Showing results 21-40

Third Party Risk Management Manager information

What does a Third Party Risk Management Manager do?

A Third Party Risk Management Manager is responsible for identifying, assessing, and mitigating risks associated with an organization's external vendors, suppliers, and partners. They develop and implement processes to evaluate the security, compliance, and operational risks posed by third parties. Their role also includes ongoing monitoring, conducting due diligence, and ensuring that third-party relationships align with the company’s risk tolerance and regulatory requirements.

What are the key skills and qualifications needed to thrive as a Third Party Risk Management Manager?

To excel as a Third Party Risk Management Manager, you need a strong understanding of risk assessment, vendor management, and compliance, typically backed by a degree in business, finance, or a related field. Familiarity with risk management frameworks, tools like RSA Archer or ServiceNow, and certifications such as CTPRP or CISM are often required. Strong analytical thinking, communication, and negotiation skills help manage complex stakeholder relationships and convey risk effectively. These competencies are crucial to identifying, mitigating, and communicating third-party risks, ensuring organizational resilience and regulatory compliance.

How does a Third Party Risk Management Manager typically collaborate with other departments to ensure effective risk mitigation?

A Third Party Risk Management Manager works closely with departments such as Procurement, Legal, IT Security, and Compliance to assess and mitigate risks associated with vendors and external partners. This collaboration often involves facilitating risk assessments, sharing due diligence findings, and coordinating incident response plans. Regular cross-departmental meetings and clear communication channels are essential to ensure that third-party risks are properly understood and managed throughout the organization.

What is the difference between Third Party Risk Management Manager vs Vendor Risk Manager?

AspectThird Party Risk Management ManagerVendor Risk Manager
CertificationsCRMP, CTPRP, or similarCRMP, CTPRP, or similar
Work EnvironmentFinancial institutions, corporations, regulated industriesFinancial services, healthcare, technology companies
Industry UsageCommon in industries with complex third-party relationshipsFocused on vendor-specific risk assessments

The Third Party Risk Management Manager and Vendor Risk Manager roles share similar certifications and often operate in regulated industries. The main difference lies in scope: the Third Party Risk Management Manager oversees all third-party relationships, including vendors, partners, and contractors, while the Vendor Risk Manager primarily focuses on assessing and mitigating risks associated with vendors specifically. Both roles are essential for organizations aiming to ensure compliance and manage third-party risks effectively.

What are the most commonly searched types of Third Party Risk Management jobs in Pennsylvania?

The most popular types of Third Party Risk Management jobs in Pennsylvania are:

What are popular job titles related to Third Party Risk Management Manager jobs in Pennsylvania?

For Third Party Risk Management Manager jobs in Pennsylvania, the most frequently searched job titles are:

What job categories do people searching Third Party Risk Management Manager jobs in Pennsylvania look for?

The top searched job categories for Third Party Risk Management Manager jobs in Pennsylvania are:

What cities in Pennsylvania are hiring for Third Party Risk Management Manager jobs?

Cities in Pennsylvania with the most Third Party Risk Management Manager job openings:

Infographic showing various Third Party Risk Management Manager job openings in Pennsylvania as of July 2026, with employment types broken down into 100% Full Time. Highlights an 90% In-person, and 10% Remote job distribution.

IT Security Program Manager

Recovery Centers of America

Devon, PA • On-site

Full-time

Re-posted 24 days ago


Recovery Centers of America rating

5.3

Company rating: 5.3 out of 10

Based on 22 frontline employees who took The Breakroom Quiz


Job description

Position Overview:

The IT Security Program Manager is responsible for executing and managing the day-to-day operations of Recovery Centers of America's cybersecurity program. Reporting to the manager of infrastructure under the IT OPS director and ensures that RCA's security posture remains compliant with HIPAA, HITECH, and NIST 800-53 standards while continuously improving the effectiveness of the organization's security controls and risk management framework.

This role will coordinate and perform audits, oversee third-party risk management, manage RCA's security awareness and phishing programs, drive policy governance, and ensure the timely resolution of open risk items and vulnerabilities. The ideal candidate is an organized, hands-on leader with a strong understanding of healthcare security and compliance who can align security initiatives with RCA's mission of saving one million lives.

Essential Duties and Responsibilities

Program Management & Governance

  • Manage the daily operations of RCA's cybersecurity program under the guidance of the CISO.
  • Coordinate and track the completion of internal and external security audits, including HIPAA, SOC 2, and NIST-based assessments.
  • Maintain and monitor the Information Security Risk Register, ensuring timely resolution of identified issues and mitigation of critical findings.
  • Lead tabletop exercises and incident response simulations to test and improve RCA's preparedness and business continuity planning.
  • Collaborate with RCA leadership and department heads to ensure that security policies and controls are understood and effectively implemented across all business units.

Third-Party Risk & Vendor Management

  • Manage the third-party risk assessment program, ensuring that all vendors with access to PHI or critical systems undergo security evaluation and periodic reassessment.
  • Review BAAs, security questionnaires, and compliance attestations; ensure corrective action for identified gaps.
  • Partner with Procurement and Legal to integrate security requirements into new and existing vendor contracts.

Policy, Compliance, and Reporting

  • Work with the CISO to review, update, and publish information security policies, standards, and procedures in accordance with HIPAA, HITECH, and NIST frameworks.
  • Develop dashboards and recurring reports to track security metrics, compliance posture, and program maturity for presentation to the CISO and executive leadership.
  • Monitor and interpret changes to regulatory requirements, ensuring timely updates to RCA's compliance program.

Security Awareness & Training

  • Administer and optimize RCA's KnowBe4 Security Awareness and Phishing Training Program.
  • Track user engagement and training completion rates, and provide metrics and recommendations to leadership.
  • Develop creative awareness campaigns to strengthen RCA's security culture.

Vulnerability & Infrastructure Management

  • Identify and track critical infrastructure vulnerabilities, working with IT and Infrastructure teams to ensure remediation and continuous monitoring.
  • Oversee MDM security, ensuring appropriate device controls, encryption, and enforcement of mobile security policies.
  • Support the CISO in analyzing threat intelligence, vulnerability trends, and endpoint security performance (e.g., CrowdStrike, firewall alerts).

Risk and Compliance Leadership

  • Ensure continuous compliance with HIPAA, HITECH, and NIST 800-53 / 800-171 requirements.
  • Coordinate with Compliance, Legal, and Clinical leadership to ensure consistent risk management practices.
  • Participate in post-incident reviews, documenting lessons learned and recommending process improvements.

Education

  • Bachelor's degree in Information Security, Computer Science, Information Technology, or related field required.

Experience

  • Minimum of 5-7 years of progressive experience in cybersecurity, IT risk management, or audit within a regulated environment (preferably healthcare).
  • At least 2 years in a program management or leadership role overseeing information security functions.
  • Strong working knowledge of HIPAA, NIST 800-53, HITRUST, and security risk management frameworks.

Certifications (preferred but not required)

  • Security +, CISSP, CISM, CRISC, HCISPP, or equivalent security certification.
  • PMP or similar project management certification is a plus.

Technical Skills

  • Understanding of endpoint protection, SIEM tools, MDM platforms (e.g., Intune), and vulnerability management solutions.
  • Experience with vendor risk tools, audit tracking systems, and compliance reporting.
  • Familiarity with Microsoft 365 Security Suite, KnowBe4, and GRC platforms.

Core Competencies

  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills, with the ability to translate technical risks for non-technical stakeholders.
  • Highly organized and detail-oriented, with the ability to manage multiple priorities simultaneously.
  • Demonstrated ability to build cross-functional relationships and drive accountability.
  • Passionate about RCA's mission and maintaining the privacy and security of patient information

Travel

  • Limited travel is required for this position
  • This position is primarily a remote position

This job description is not designed to cover or contain a comprehensive listing of all activities, duties, or responsibilities required of the employee. Duties, responsibilities, and activities may change at any time, with or without notice, to meet the evolving needs of the organization. Nothing in this job description alters the at-will nature of employment, and either RCA or the employee may terminate the employment relationship at any time, with or without cause or notice.

RCA is committed to providing reasonable accommodations to qualified individuals with disabilities to enable them to perform the essential functions of their role. Employees or applicants requiring accommodation should contact Human Resources to initiate the interactive accommodation process.


This position primarily involves sedentary work, including extended periods of sitting and computer use. The employee must be able to communicate effectively via phone, video conferencing, and written correspondence.

#EXEC


What Recovery Centers of America employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Recovery Centers of America logo

About Recovery Centers of America

Sourced by ZipRecruiter

Recovery Centers of America (RCA) is a ground-breaking addiction and mental health treatment provider, setting the standard when it comes to accessible, affordable, and effective care. RCA understands the heartache, damage, and pain substance use disorder causes a person as well as their family and friends. Not only do we believe that addiction treatment should be affordable, accessible, and evidence-based, but our driven, compassionate, and dedicated employees make those beliefs a reality.

Industry

Health care and social assistance

Company size

1,001 - 5,000 Employees

Headquarters location

King of Prussia, PA, US

Year founded

2015