
City/State
Norfolk, VA
Work Shift
First (Days)
The Third-Party Risk Program Manageris responsible forthe end-to-end management of the organization’s third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle — from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding — ensuring third party relationshipscomply withapplicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness
Key Responsibilities
Program Management
Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle
Establish andmaintainprogram timelines, milestones, and status reporting for leadership and stakeholders
Identifyprocess gaps and drive continuous improvement of program workflows
Be a part of the teamandsupporttheexecution ofthe program
Vendor Management
Serve as the primary point of contact for third-party vendors throughout the assessment and management process
Coordinate with vendors to gather required documentation, evidence, and remediation plans
Track vendor responsiveness and escalate delays or non-compliance issues appropriately
Risk Assessments (OneTrust)
Manage and execute third-party risk assessments usingOneTrust, including assessment creation, distribution, tracking, and completion
Analyze assessment results toidentifyrisk levels, gaps, andrequiredremediation actions
Maintainaccurate, up-to-date vendor and assessment records withinOneTrust
Generate reports and dashboards fromOneTrustto support program reporting and audits
Documentation & Compliance
Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) isaccurate, complete, and current
Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)
Support internal and external audits by providingtimelyandaccuratedocumentation
Cross-Functional Collaboration
Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage
Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike
Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward
Bachelor Level Degree (Preferred)
5+ years relevant experience may be accepted in lieu of degree
Certification in risk, or compliance (e.g., CTPRP, CRISC) preferred
Required
Bachelor’s degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry
5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry without a Bachelor's degree preferred.
Hands-on experience withOneTrustor similar GRC/risk management platforms
Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements
Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously
Excellent written and verbal communication skills, with experience working cross functionally
Preferred
Certification in risk, or compliance (e.g., CTPRP, CRISC)
Experience with vendor contract review or working alongside Legal/Procurement
Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)
We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:$106,080.00-$176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.
Benefits: Caring For Your Family and Your Career
• Medical, Dental, Vision plans
• Adoption, Fertility and Surrogacy Reimbursement up to $10,000
• Paid Time Off and Sick Leave
• Paid Parental & Family Caregiver Leave
• Emergency Backup Care
• Long-Term, Short-Term Disability, and Critical Illness plans
• Life Insurance
• 401k/403B with Employer Match
• Tuition Assistance – $5,250/year and discounted educational opportunities through Guild Education
• Student Debt Pay Down – $10,000
•Pet Insurance
•Legal Resources Plan
•Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.
Sentara Health is an equal opportunity employer and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.
In support of our mission “to improve health every day,” this is a tobacco-free environment.
For positions that are available as remote work,Sentara Health employs associates in the following states:
Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.

Sentara Health, an integrated, not-for-profit health care delivery system, celebrates more than 135 years in pursuit of its mission - "we improve health every day." Sentara is one of the largest health systems in the U.S. Mid-Atlantic and Southeast, and among the top 20 largest not-for-profit integrated health systems in the country, with 34,000 employees, 12 hospitals in Virginia and Northeastern North Carolina, including 10 hospitals with the prestigious Magnet®️ recognition, and the Sentara Health Plans division which serves more than 1 million members in Virginia and Florida. Sentara is recognized nationally for clinical quality and safety and is strategically focused on innovation and creating an extraordinary health care experience for our patients and members. Sentara was named a Health Quality Innovator of the Year (2024), was recognized by Forbes as "America’s Best-In-State Employer” (2024), "Best Employer for Veterans" (2022, 2023), and "Best Employer for Women" (2020), and named to IBM Watson Health's "Top 15 Health Systems" (2021, 2018).
Like us on Facebook at www.facebook.com/sentarahealth
Follow us on Instagram at @SentaraHealth