1

Vendor Risk Assessment Jobs in Kentucky (NOW HIRING)

$106 - $177/hr

This individual contributor role owns the program lifecycle -- from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding -- ensuring third party ...

New

Senior Manager, Privacy

Boston, KY · On-site

$160 - $180K/hr

Oversee privacy risk assessments for vendors and other third parties. * Develop training and workflows for privacy assessments and RoPAs. * Maintain the Privacy Intranet and related guidance ...

$123 - $185/hr

Develop AI risk assessment criteria and governance standards * Align controls to NIST AI Risk Management Framework and institutional policies * Evaluate AI/ML tools and vendors for data protection ...

New

$180 - $260/hr

Assess market risk measurement frameworks, including VaR, stress testing, scenario analysis, and ... party/vendor data sources. * Identify business process improvement opportunities and propose ...

New

$151 - $276/hr

Participates in the review and assessment of the project team or contractor monthly progress ... contacting vendors to obtain quotes for materials and services, and leading change order ...

New

$160 - $180/hr

Familiarity with AI governance and compliance frameworks (privacy impact assessments, vendor risk review, EU AI Act) strongly preferred.* Bachelor's or Master's degree in Computer Science, Business ...

New

$218 - $260/hr

Conduct systematic risk assessments to identify Critical Material Attributes (CMAs) and Critical ... Manage external CDMO partnerships, including vendor qualification, technical oversight, and ...

New

$140 - $190/hr

Conduct and maintain enterprise risk assessments, third-party/vendor security risk reviews, and business associate agreement (BAA) security requirements. * Develop, maintain, and test incident ...

New

next page

Showing results 1-20

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.

What cities in Kentucky are hiring for Vendor Risk Assessment jobs?

Cities in Kentucky with the most Vendor Risk Assessment job openings:

Program Manager - Third Party Risk Management

Sentara Health Plans

On-site

$106 - $177/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday

New


Job description

Program Manager – Third Party Risk ManagementSkip to main content#Program Manager – Third Party Risk Management page is loaded## Program Manager – Third Party Risk ManagementApplyremote type: Remotelocations: Norfolk, VA: Remote - NV: Remote - FL: Remote - WV: Remote - DEtime type: Full timeposted on: Posted Todayjob requisition id: JR-104441**City/State**Norfolk, VA**Work Shift**First (Days)**Overview:**# **Overview**The Third-Party Risk Program Manager is responsible for the end-to-end management of the organization’s third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle — from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding — ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness**Key Responsibilities****Program Management*** Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle* Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders* Identify process gaps and drive continuous improvement of program workflows* Be a part of the team and support the execution of the program**Vendor Management*** Serve as the primary point of contact for third-party vendors throughout the assessment and management process* Coordinate with vendors to gather required documentation, evidence, and remediation plans* Track vendor responsiveness and escalate delays or non-compliance issues appropriately**Risk Assessments (OneTrust)*** Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion* Analyze assessment results to identify risk levels, gaps, and required remediation actions* Maintain accurate, up-to-date vendor and assessment records within OneTrust* Generate reports and dashboards from OneTrust to support program reporting and audits**Documentation & Compliance*** Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current* Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)* Support internal and external audits by providing timely and accurate documentation**Cross-Functional Collaboration*** Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage* Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike* Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward# **Education*** Bachelor Level Degree (Preferred)* *5+ years relevant experience may be accepted in lieu of degree*# # **Certification/Licensure*** Certification in risk, or compliance (e.g., CTPRP, CRISC) preferred# **Experience****Required*** Bachelor’s degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry* 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry without a Bachelor's degree preferred.* Hands-on experience with OneTrust or similar GRC/risk management platforms* Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements* Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously* Excellent written and verbal communication skills, with experience working cross functionally**Preferred*** Certification in risk, or compliance (e.g., CTPRP, CRISC)* Experience with vendor contract review or working alongside Legal/Procurement* Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:$106,080.00-$176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities. **Benefits: Caring For Your Family and Your Career****•** Medical, Dental, Vision plans• Adoption, Fertility and Surrogacy Reimbursement up to $10,000• Paid Time Off and Sick Leave• Paid Parental & Family Caregiver Leave• Emergency Backup Care• Long-Term, Short-Term Disability, and Critical Illness plans• Life Insurance• 401k/403B with Employer Match• Tuition Assistance – $5,250/year and discounted educational opportunities through Guild Education• Student Debt Pay Down – $10,000•Pet Insurance •Legal Resources Plan •Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.**Sentara Health is an equal opportunity employer** and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.In support of our mission “to improve health every day,” this is a tobacco-free environment.**For positions that are available as remote work,** **Sentara Health employs associates in the following states:**Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming. #J-18808-Ljbffr