1

Vendor Risk Assessment Jobs in Kentucky (NOW HIRING)

Senior Manager, Privacy

Boston, KY · On-site

$160 - $180K/hr

Oversee privacy risk assessments for vendors and other third parties. * Develop training and workflows for privacy assessments and RoPAs. * Maintain the Privacy Intranet and related guidance ...

Senior Manager, Privacy

Boston, KY · Hybrid

$160 - $180K/hr

Oversee privacy risk assessments for vendors and other third parties. * Develop training and workflows for privacy assessments and RoPAs. * Maintain the Privacy Intranet and related guidance ...

Assess AI-specific risks including data handling, model provenance, supply chain integrity, API ... Collaborate with Legal, Privacy, Procurement, and Vendor Risk Management teams to define security ...

Assess AI-specific risks including data handling, model provenance, supply chain integrity, API ... Collaborate with Legal, Privacy, Procurement, and Vendor Risk Management teams to define security ...

next page

Showing results 1-20

Vendor Risk Assessment information

What is the difference between Vendor Risk Assessment vs Vendor Compliance Analyst?

AspectVendor Risk AssessmentVendor Compliance Analyst
Primary FocusEvaluating risks associated with vendors and third-party providersEnsuring vendors comply with policies, regulations, and contractual obligations
CertificationsCertifications like CISSP, CISA, or vendor risk management coursesCertifications such as CCEP, CISA, or compliance-specific credentials
Work EnvironmentRisk management teams, procurement, cybersecurity departmentsCompliance teams, legal, procurement, and audit departments
Industry UsageCommon in finance, healthcare, and IT sectorsPrevalent in regulated industries like finance, healthcare, and manufacturing

Vendor Risk Assessment focuses on identifying and mitigating risks posed by vendors, while Vendor Compliance Analysts ensure vendors adhere to policies and regulations. Both roles are essential for managing third-party relationships but differ in their primary objectives and activities.

What are the key skills and qualifications needed to thrive as a vendor risk assessment professional?

To thrive in Vendor Risk Assessment, you need a solid understanding of risk management principles, third-party due diligence, and regulatory compliance, often supported by a degree in business, IT, or a related field. Familiarity with risk assessment tools, governance frameworks (like ISO 27001), and platforms such as GRC (Governance, Risk, and Compliance) systems is typically required. Strong analytical thinking, attention to detail, and effective communication skills help professionals assess vendor risks and collaborate across departments. These skills are crucial for identifying, mitigating, and communicating risks that could impact an organization’s operations, security, or reputation.

What are some common challenges faced in a vendor risk assessment role, and how can I prepare to address them?

Professionals in Vendor Risk Assessment often encounter challenges such as managing large volumes of vendor data, ensuring compliance with evolving regulations, and effectively communicating risks to both internal stakeholders and vendors. To prepare for these challenges, it's important to develop strong organizational and analytical skills, stay informed about regulatory changes, and build effective communication strategies. Collaborating closely with procurement, legal, and IT teams is also essential for gathering accurate information and implementing risk mitigation measures.

What is a vendor risk assessment?

A Vendor Risk Assessment is a process used by organizations to evaluate and manage the potential risks associated with outsourcing services or products to third-party vendors. The assessment typically examines areas such as data security, regulatory compliance, financial stability, and operational practices of the vendor. Its purpose is to identify potential vulnerabilities or threats that could impact the organization if the vendor fails to meet expectations or is compromised. Regular vendor risk assessments help ensure that third-party relationships do not expose the company to undue risk and that appropriate controls are in place.
What are popular job titles related to Vendor Risk Assessment jobs in Kentucky? For Vendor Risk Assessment jobs in Kentucky, the most frequently searched job titles are:
What job categories do people searching Vendor Risk Assessment jobs in Kentucky look for? The top searched job categories for Vendor Risk Assessment jobs in Kentucky are:
What cities in Kentucky are hiring for Vendor Risk Assessment jobs? Cities in Kentucky with the most Vendor Risk Assessment job openings:

Senior Manager, Privacy

Servier

Boston, KY • On-site

$160 - $180K/hr

Full-time

Medical, Dental, Vision, Life, Retirement

Re-posted 4 days ago


Job description

About Servier
Servier in the U.S. is a Boston-based, commercial-stage biopharmaceutical company launched by Servier Group in 2018. As a privately held organization, Servier is uniquely positioned to advance cutting-edge science, tackle underserved therapeutic areas and make patients the focus of every strategic decision.
Role Summary
The Privacy professional will play a pivotal role in ensuring Servier's compliance with privacy laws and regulations across the US. Reporting to the Sr. Director, US Head of Data Privacy, this Senior Manager level professional will be responsible for advancing Servier US data privacy programs through strategic oversight, operational execution and cross functional collaboration. This ensures responsible data is used to support business objectives and plays a critical role in risk identification and mitigation. Key cross functional partners may include Patient Services, Patient Advocacy, Data Management, IT, HR, Legal, Clinical, R&D, Market Research, Commercial Marketing, and Commercial Operations This position requires a strategic problem solver who can lead initiatives, provide expert guidance, and collaborate with team members to manage privacy risks effectively.
Primary Responsibilities
  • Support day-to-day operations of the privacy program, including policy implementation, training, and awareness initiatives.
  • Serve as the subject matter expert on privacy impact assessments (PIAs), records of processing activities and vendor risk assessments.
  • Ensure timely completion of PIAs, including providing business guidance on when and how to complete them.
  • Review completed PIAs to identify risks, recommend mitigations, and support privacy by design.
  • Support maintenance of records of processing activities (RoPAs) and data maps.
  • Oversee privacy risk assessments for vendors and other third parties.
  • Develop training and workflows for privacy assessments and RoPAs.
  • Maintain the Privacy Intranet and related guidance documents for business teams.
  • Manage privacy technology platforms (e.g., OneTrust) and lead issue resolution, integration, and optimization.
  • Develop and track privacy program metrics to identify trends, measure effectiveness, and drive improvement.
  • Support the implementation and ongoing enhancement of processes and procedures to mitigate identified and potential privacy risks.
  • Support the development and maintenance of the internal U.S. Privacy Network.
  • Other duties as assigned by manager or department leader.

Job Description
Candidate Profile
Education and Required Skills
  • BA Degree required. JD Degree from an accredited law school is preferred.
  • BA degree with 7+ years or JD with 6+ years of privacy experience including supporting business functions on data privacy PIAs, ROPAs and vendor risk assessments.
  • In-depth knowledge of U.S. privacy laws and requirements. Knowledge of GDPR and Canadian privacy laws and regulations is a plus.
  • AI literacy and experience using technology to enhance privacy operations
  • Must have expert proficiency with the common privacy compliance tools - e.g. One Trust, etc.
  • Ability to work independently and respond to shifting priorities.
  • Strong communication, project management, and presentation skills.
  • Proven ability to collaborate effectively with cross-functional partners.
  • Proven track record of assessing risk and developing privacy legal and compliance strategies to minimize and manage risk.
  • Experience supporting clients within the life sciences or a similar industry focused on data privacy and security is required.
  • CIPP/US privacy certification is a plus.

Travel and Location
  • Boston-based; hybrid role with expectation to be in office 2-3 days per week
  • Minimal travel as required

Servier's Commitment
Servier is committed to modeling diversity, equity, and inclusion within the industry. We are dedicated to fostering an environment that maintains equitable treatment for all and we welcome applicants who are passionate, committed, and innovative individuals. We encourage candidates to apply to our open roles as we are always willing to consider experiences and skills beyond what is listed in the job description.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Salary Range
The salary range for this role is $160-$180k. An employee's pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, geographic location, performance, and business or organizational needs. We may ultimately pay more or less than the posted range, and the range may be modified in the future. Employees in this position are also eligible for Short-Term and Long-Term incentive programs. Servier also offers a competitive and comprehensive benefits package that includes benefits such as medical, dental, vision, flexible time off (Servier provides unlimited sick time and flex time, and does not accrue time off), 401(k), life and disability insurance, recognition programs among other great benefits (all benefits are subject to eligibility requirements). For more information on our benefits, please visit this link.