1

Vendor Risk Manager Jobs in Virginia Beach, VA (NOW HIRING)

Senior IT Security Engineer

Chesapeake, VA · On-site

$125 - $150/hr

  • Medical

  • Dental

  • Life

  • Retirement

  • PTO

Lead third-party vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations. * Direct the security ...

New

Senior IT Security Engineer

Chesapeake, VA

$92K - $126K/yr

  • Medical

  • Dental

  • Life

  • Retirement

  • PTO

... vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations. • Direct the security awareness and ...

Senior IT Security Engineer

Chesapeake, VA · On-site

$92K - $126K/yr

  • Medical

  • Dental

  • Life

  • Retirement

  • PTO

... vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations. • Direct the security awareness and ...

The Risk Analyst will hold key responsibilities related to the administrative handling and ... vendors and contractors to ensure compliance with contractual insurance requirements. * Manage ...

Analyst - Risk

Chesapeake, VA · On-site

$68K - $83K/yr

The Risk Analyst will hold key responsibilities related to the administrative handling and ... vendors and contractors to ensure compliance with contractual insurance requirements. * Manage ...

Director of Benefits Operations

Norfolk, VA · On-site

$140K - $180K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead vendor governance by overseeing vendor relationships, including contract management, service level expectations, and ongoing business reviews while managing vendor risk. * Identify opportunities ...

Director of Benefits Operations

Norfolk, VA · On-site

$140K - $180K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead vendor governance by overseeing vendor relationships, including contract management, service level expectations, and ongoing business reviews while managing vendor risk. * Identify opportunities ...

Director of Benefits Operations

Norfolk, VA

$140K - $180K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead vendor governance by overseeing vendor relationships, including contract management, service level expectations, and ongoing business reviews while managing vendor risk. * Identify opportunities ...

Director of Benefits Operations

Norfolk, VA · On-site

$140 - $180/hr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Lead vendor governance by overseeing vendor relationships, including contract management, service level expectations, and ongoing business reviews while managing vendor risk. * Identify opportunities ...

General Liability Specialist

Chesapeake, VA · On-site

$95K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Monitor significant claims and exposures to ensure alignment with organizational objectives and risk management strategies. Third-Party Administrator (TPA) & Vendor Management * Oversee Third-Party ...

General Liability Specialist

Chesapeake, VA · On-site

$95K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Monitor significant claims and exposures to ensure alignment with organizational objectives and risk management strategies. Third-Party Administrator (TPA) & Vendor Management * Oversee Third-Party ...

next page

Showing results 1-20

Vendor Risk Manager information

See Virginia Beach, VA salary details

$48.9K

$105.9K

$161.3K

How much do vendor risk manager jobs pay per year?

As of Aug 19, 2026, the average yearly pay for vendor risk manager in Virginia Beach, VA is $105,869.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,400.00 and $122,400.00 per year, depending on experience, location, and employer.

What is a vendor risk manager?

Vendor Risk Managers are professionals responsible for identifying, assessing, and mitigating risks associated with third-party vendors that provide goods or services to an organization. They evaluate vendors’ security, compliance, and operational practices to ensure they meet the company’s standards and regulatory requirements. These managers implement frameworks to monitor vendor performance, manage contracts, and respond to potential risks or incidents. Their role is crucial in protecting the organization from financial, reputational, and regulatory harm that can arise from third-party relationships.

What are the key skills and qualifications needed to thrive as a vendor risk manager?

To thrive as a Vendor Risk Manager, you need expertise in risk assessment, third-party management, and compliance, often backed by a degree in business, finance, or a related field. Familiarity with risk management platforms, contract management tools, and certifications like Certified Third Party Risk Professional (CTPRP) are highly valuable. Strong analytical thinking, negotiation, and clear communication skills help you collaborate with vendors and internal stakeholders effectively. These skills ensure organizations can identify, mitigate, and manage risks arising from third-party relationships, safeguarding business continuity and compliance.

How does a vendor risk manager typically collaborate with other departments within an organization?

A Vendor Risk Manager works closely with departments like procurement, legal, IT, and compliance to ensure that vendors meet the organization's security and regulatory standards. This collaboration often involves reviewing contracts, assessing potential risks, and implementing mitigation strategies. Regular communication with stakeholders is essential to keep everyone informed about vendor performance and risk status, making cross-functional teamwork a key aspect of the role. Effective collaboration helps streamline risk assessments and supports informed decision-making across the business.

What is the difference between Vendor Risk Manager vs Vendor Compliance Analyst?

AspectVendor Risk ManagerVendor Compliance Analyst
CertificationsCertified Third Party Risk Professional (CTPRP), Certified Information Systems Auditor (CISA)Certified Compliance & Ethics Professional (CCEP), Certified Regulatory Compliance Manager (CRCM)
Work EnvironmentRisk management teams, procurement, legal departmentsCompliance departments, audit teams, legal units
Industry UsageFinance, healthcare, technology, retailFinance, healthcare, manufacturing, technology
Primary FocusIdentifying, assessing, and mitigating vendor risksEnsuring vendor adherence to compliance standards and policies

The Vendor Risk Manager focuses on evaluating and mitigating risks associated with vendors, while the Vendor Compliance Analyst concentrates on ensuring vendors meet regulatory and internal compliance standards. Both roles are essential in managing vendor relationships but differ in their core responsibilities and focus areas.

What cities near Virginia Beach, VA are hiring for Vendor Risk Manager jobs?

Cities near Virginia Beach, VA with the most Vendor Risk Manager job openings:

Infographic showing various Vendor Risk Manager job openings in Virginia Beach, VA as of August 2026, with employment types broken down into 83% Full Time, 15% Part Time, 1% Contract, and 1% Nights. Highlights an 84% Physical, 2% Hybrid, and 14% Remote job distribution, with an average salary of $105,869 per year, or $50.9 per hour.

Program Manager - Third Party Risk Management

Sentara Healthcare Inc

Norfolk, VA • On-site

$106 - $177/hr

Other

Posted 6 days ago


Sentara Health rating

6.7

Company rating: 6.7 out of 10

Based on 412 frontline employees who took The Breakroom Quiz

531st of 888 rated healthcare providers


Job description

Overview

The Third-Party Risk Program Manager is responsible for the end-to-end management of the organization’s third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle — from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding — ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness.

Key Responsibilities

Program Management
  • Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle

  • Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders

  • Identify process gaps and drive continuous improvement of program workflows

  • Be a part of the team and support the execution of the program

Vendor Management
  • Serve as the primary point of contact for third-party vendors throughout the assessment and management process

  • Coordinate with vendors to gather required documentation, evidence, and remediation plans

  • Track vendor responsiveness and elevate delays or non-compliance issues appropriately

Risk Assessments (OneTrust)
  • Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion

  • Analyse assessment results to identify risk levels, gaps, and required remediation actions

  • Maintain accurate, up-to-date vendor and assessment records within OneTrust

  • Generate reports and dashboards from OneTrust to support program reporting and audits

Documentation & Compliance
  • Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current

  • Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)

  • Support internal and external audits by providing timely and accurate documentation

Cross-Functional Collaboration
  • Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage

  • Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike

  • Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward

Education
  • Bachelor Level Degree (Preferred)

  • 5+ years relevant experience may be accepted in lieu of degree

Certification/Licensure
  • Certification in risk, or compliance (e.g., CTPRP, CRISC) preferred

Experience

Required

  • Bachelor’s degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry

  • 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry without a Bachelor's degree preferred.

  • Hands‑on experience with OneTrust or similar GRC/risk management platforms

  • Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements

  • Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously

  • Excellent written and verbal communication skills, with experience working cross functionally

Preferred

  • Certification in risk, or compliance (e.g., CTPRP, CRISC)

  • Experience with vendor contract review or working alongside Legal/Procurement

  • Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)

We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is: $106,080.00-$176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.

#J-18808-Ljbffr

What Sentara Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom