1

Third Party Risk Jobs in Oregon (NOW HIRING)

$125K - $168K/yr

Vendor/third-party risk coordination: Collaborate on third-party due diligence and contracting controls impacting compliance, privacy, and security obligations. * Litigation management support: In ...

Oversee third-party risk management activities, including anti-bribery/anti-corruption due diligence, background checks, and trade sactions screening, to ensure compliance with compliance standards ...

... third-party risk management. --- Primary Location: Remote Primary Location Salary Range: $75/hr - $150/hr --- Responsibilities * Assimilate and manage complex data into actionable reports and ...

Director of Security

OR · Remote

$190K - $240K/yr

The scope includes third party risk, vendor assessment and qualification, security architecture oversight, AI related security assessments and guidance, incident response leadership, and budget ...

Collaborate with third-party vendors and internal stakeholders to support rollout, troubleshooting, and updates of SaaS tools * Assist with Third Party Risk Management (TPRM) reviews, including ...

Establishes and formalizes AI Governance, Privacy & Third-Party Risk requirements by defining security expectations for AI use cases, third-party models, vendor integrations, and sensitive data usage ...

Decisioning, including integration of alternative data sources and third-party risk intelligence tools. * Collaborate with Technology and Data teams to modernize underwriting systems and reduce ...

next page

Showing results 1-20

Third Party Risk information

What are some common challenges faced in a Third Party Risk role and how can they be managed?

Professionals in Third Party Risk often encounter challenges such as managing a large and diverse vendor portfolio, staying updated on regulatory requirements, and ensuring timely risk assessments. Navigating communication gaps between internal stakeholders and external vendors can also be demanding. These challenges are typically managed by implementing robust risk assessment frameworks, fostering cross-functional collaboration, and leveraging technology to streamline due diligence and monitoring processes. Continuous training and clear communication protocols further help in addressing these complexities and maintaining effective third-party risk management.

What is the difference between Third Party Risk vs Vendor Risk Management?

AspectThird Party RiskVendor Risk Management
FocusAssessing risks from all external entities, including vendors, partners, and contractorsEvaluating risks specifically associated with third-party vendors
CredentialsRisk management certifications, compliance knowledgeVendor management certifications, procurement experience
Work EnvironmentCorporate risk teams, compliance departmentsProcurement, vendor management teams
Industry UsageFinancial, healthcare, technology sectorsPrimarily in supply chain and procurement functions

Third Party Risk encompasses a broader scope, including all external entities, while Vendor Risk Management specifically focuses on vendors. Both roles require risk assessment skills and industry knowledge, but Third Party Risk roles often involve broader compliance and strategic oversight.

What are the key skills and qualifications needed to thrive as a Third Party Risk professional, and why are they important?

To thrive as a Third Party Risk professional, you need a solid understanding of risk management principles, vendor assessment processes, and relevant regulatory frameworks, often supported by a degree in business, finance, or a related field. Familiarity with risk assessment tools, GRC (governance, risk, and compliance) software, and certifications such as Certified Third Party Risk Professional (CTPRP) are common requirements. Strong analytical thinking, attention to detail, and effective communication skills help you evaluate vendors and influence stakeholders. These skills are vital for identifying, mitigating, and managing risks associated with third-party relationships to protect organizational integrity and compliance.

What is Third Party Risk?

Third Party Risk refers to the potential risks and vulnerabilities an organization faces when working with external vendors, suppliers, or service providers. These risks can include data breaches, compliance violations, operational disruptions, and reputational damage resulting from the actions or failures of third parties. Managing third party risk involves identifying, assessing, monitoring, and mitigating these risks to protect the organization’s interests and ensure regulatory compliance.
What are the most commonly searched types of Third Party Risk jobs in Oregon? The most popular types of Third Party Risk jobs in Oregon are:
What are popular job titles related to Third Party Risk jobs in Oregon? For Third Party Risk jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Third Party Risk jobs in Oregon look for? The top searched job categories for Third Party Risk jobs in Oregon are:
What cities in Oregon are hiring for Third Party Risk jobs? Cities in Oregon with the most Third Party Risk job openings:
Infographic showing various Third Party Risk job openings in Oregon as of May 2026, with employment types broken down into 2% As Needed, 78% Full Time, 16% Part Time, 2% Temporary, and 2% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution.
Vice President, Compliance & Risk Management

Vice President, Compliance & Risk Management

Emerus

$125K - $168K/yr

Full-time

Posted 19 days ago


Emerus rating

5.7

Company rating: 5.7 out of 10

Based on 22 frontline employees who took The Breakroom Quiz


Job description

About Us

We are Emerus, the leader in small-format hospitals. We partner with respected and like-minded health systems who share our mission: To provide the care patients need, in the neighborhoods they live, by teams they trust. Our growing number of amazing partners includes Allegheny Health Network, Ascension, Baptist Health System, Baylor Scott & White Health, ChristianaCare, Dignity Health St. Rose Dominican, The Hospitals of Providence, INTEGRIS Health, MultiCare and WellSpan. Our innovative hospitals are fully accredited and provide highly individualized care. Emerus' commitment to patient care extends far beyond the confines of societal norms. We believe that every individual who walks through our doors deserves compassionate, comprehensive care, regardless of their background, identity, or circumstances. We are committed to fostering a work environment focused on teamwork that celebrates diversity, promotes equity and ensures equal access to information, development and opportunity for all of our Healthcare Pros.

Position Overview

The VP, Compliance & Risk Management provides enterprise leadership for the organization's compliance program and risk management strategy. This role designs and oversees a comprehensive framework to prevent, detect, and respond to regulatory, legal, accreditation, privacy, and operational risks; partners with clinical and business leaders to strengthen controls; and supports a culture of ethics, patient safety, and accountability. The VP serves as a trusted advisor to executive leadership and leads program reporting, investigations, and continuous improvement across the Company.

Essential Job Functions
  • Enterprise compliance program leadership: Develop, implement, and continuously improve the compliance program, policies, and procedures; align to OIG/CMS expectations and industry best practices.
  • Risk management strategy: Establish and maintain an enterprise risk management approach that identifies, assesses, mitigates, and monitors key risks (clinical, operational, financial, regulatory, and reputational).
  • Regulatory readiness and oversight: Assist with federal/state surveys, audits, and oversight activities.
  • Investigations and case management: Oversee intake, triage, and investigation of hotline reports, complaints, and potential violations; ensure consistent documentation, confidentiality, root cause analysis, and corrective action.
  • Privacy and security partnership: Partner with Privacy and Information Security leaders on HIPAA/privacy incident management, breach risk assessments, mitigation plans, and required notifications.
  • Audit, monitoring, and controls: Build and manage a risk-based annual work plan; oversee auditing and monitoring activities (e.g., EMTALA, billing/claims, documentation, patient rights, conflicts of interest) and track trends and outcomes.
  • Corrective and preventive actions: Drive development, implementation, and verification of corrective action plans; define owners, milestones, and effectiveness measures.
  • Education and culture: Design and oversee compliance and risk training; promote speak-up culture, non-retaliation, and operational integration of compliance requirements.
  • Governance and reporting: Prepare and present compliance/risk metrics, significant matters, and program updates to executive leadership, committees, and Boards; advise on risk tolerance and escalation decisions.
  • Policy management: Oversee development, review, and maintenance of compliance and risk-related policies, standards, and guidance; ensure policies are operationalized and accessible.
  • Vendor/third-party risk coordination: Collaborate on third-party due diligence and contracting controls impacting compliance, privacy, and security obligations.
  • Litigation management support: In partnership with Legal and Risk, coordinate intake and tracking of litigation matters impacting the organization; support document retention and legal holds, discovery readiness, and collection of records; monitor trends, reserves/exposure (as appropriate), and remediation actions to reduce future risk.
  • Claims and litigation partnership: Partner with Legal, Quality/Patient Safety, and insurance partners on claim trends, event investigations, and risk mitigation strategies (as applicable to the organization).
  • Leadership: Recruit, develop, and lead a high-performing team; establish goals, performance expectations, and a continuous improvement mindset.

Key Competencies

  • Ethical leadership and sound judgment
  • Risk-based prioritization and program management
  • Investigation skills, interviewing, and documentation discipline
  • Data-driven reporting (metrics, trending, dashboards)
  • Change management and stakeholder influence
  • Strong collaboration with clinical, operational, legal, HR, finance, and IT partners
  • Ability to translate regulations into workable processes
Other Job Functions
  • Attend staff meetings or other company sponsored or mandated meetings as required
  • Travel as necessary to support investigations, regulatory deadlines, or critical events
  • Perform additional duties as assigned
  • Ability to work off-hours and on call when required to support investigations, regulatory deadlines, or critical events
Basic Qualifications
  • Bachelor's degree in healthcare administration, public health, risk management, law, or a related field (or equivalent experience).
  • 10+ years of progressive experience in healthcare compliance and risk management (hospital, health system, or comparable regulated healthcare environment).
  • Demonstrated knowledge of healthcare regulatory requirements and enforcement expectations (e.g., HIPAA/privacy, EMTALA, fraud/waste/abuse, billing/claims compliance, patient rights, accreditation/survey readiness, incident reporting).
  • Experience leading investigations, audits/monitoring, and corrective action plans with measurable outcomes.
  • Proven executive presence and ability to influence senior leaders and clinicians through clear, practical guidance.
  • Strong written and verbal communication skills, including Board-level reporting.
  • Ability to handle sensitive matters with discretion and maintain confidentiality.
Preferred
  • Master's degree (e.g., MHA, MPH, MBA, MSN, JD).
  • Professional certification(s) such as CHC, CHPC, CHRC, CCEP, CPHRM, or equivalent.
  • Experience supporting multi-state operations and joint venture or partnership models.
  • Experience implementing or maturing an enterprise risk management (ERM) framework and related governance.
  • Experience partnering with Information Security on security incidents and vendor risk practices.
Employment Type: FULL_TIME

What Emerus employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom