Jobedly Post a Job

Director, 3rd Party Security Risk

HealthEquity · Remote
RemoteFull-timeHealthcareLead$151,500–$200,500/yr
Apply on Jobedly ⚡ One-click AI Apply

About the Director RD Party Security Risk role

Director RD Party Security Risk positions focus on delivering results in their domain. This page aggregates open Director RD Party Security Risk roles and what employers typically expect.

## Our Mission Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable. ## Overview How you can make a difference HealthEquity relies on a broad ecosystem of third party partners, vendors, platforms, and service providers to support member, client, and teammate experiences while protecting trust, resilience, and compliance. The Director of 3rd Party Risk is a strategic leadership role responsible for overseeing and evolving the 3rd party (third-party) risk management program into an enterprise-wide, AI-aware risk governance capability. In this role, you will drive a pragmatic, measurable program that defines “what good looks like” across vendor tiers, incorporates AI and agentic system risks into due diligence and lifecycle oversight, and aligns third party risk practices with enterprise strategy, regulatory expectations, resiliency objectives, and business priorities. The Director will lead a growing team and collaborate cross-functionally with Security, Procurement, Legal, Privacy, Enterprise Risk, IT, Engineering, Finance, and business owners to identify, assess, quantify, and manage third party risks across cybersecurity, resiliency, financial, operational, contractual, reputational, and AI domains. This role is critical in establishing clear operating procedures, risk-tiered requirements, meaningful KRIs/KPIs, and board-ready reporting, ensuring third party relationships and AI-enabled vendor services align with the company’s risk appetite, strategic objectives, and obligation to protect member, client, and company data while fostering a culture of accountability and resilience. What you’ll be doing - Develop and execute a transformatiomal third-party risk strategy that integrates cybersecurity, privacy, resiliency, financial, operational, contractual, reputational, and AI risks into enterprise goals. - Design policies, standards, playbooks, and scalable processes to streamline third party intake, risk assessments, issues mananagement, offboarding and continuous monitoring and automated assurance of controls while reducing duplicative or low-value work. - Incorporate AI and agentic systems and solutions into the TPRM lifecycle, including AI-use disclosure, AI-specific due diligence, data-use restrictions, model or system documentation review, human oversight expectations, output integrity, monitoring, incident response, and residual risk acceptance. - Partner with the AI Governance Council, Legal, Privacy, Enterprise Risk, Data Governance, Procurement, and business owners to ensure third party-sourced AI capabilities are reviewed, approved, monitored, and governed consistently with enterprise AI policies and standards. - Establish meaningful KRIs, KPIs, dashboards, and management routines that demonstrate whether the program is buying down third-party risk, including coverage, assessment quality, remediation aging, contract control gaps, external risk posture, AI-enabled vendor coverage, and unresolved risk acceptances. - Design and maintain tier-based operating procedures that clearly articulate what is required for tiered third party, including required risk assessments, contract safeguards, monitoring cadence, remediation expectations, and escalation triggers. - Lead third party tiering and re-tiering efforts using objective criteria such as criticality, data sensitivity, regulatory exposure, operational dependency, resiliency impact, replaceability, AI usage, and business materiality. - Identify and address risks proactively, engaging stakeholders to drive effective remediation efforts. - Identify and address risks proactively, engaging stakeholders to drive effective remediation efforts and ensuring ownership is assigned across Security, Procurement, Legal, IT, Engineering, Finance, Enterprise Risk, and business teams. - Prepare strategic updates of third-party and AI-enabled risk updates for executive leadership, auditors, regulators, and the board of directors. - Sup…

Salary estimate

$151,500 – $200,500/yr
Provided by the employer.

Skills for this role

LeadershipSecurity

Resume tips for Director RD Party Security Risk applicants

Interview preparation

Prepare concrete STAR-format stories that show Director RD Party Security Risk outcomes you drove.

Research the employer's product and recent news before the interview.

Be ready to explain how you'd approach a typical Director RD Party Security Risk problem end to end.

Have thoughtful questions ready about the team, tools and success metrics.

About HealthEquity

HealthEquity is actively hiring on Jobedly. Explore their open roles and what it's like to work there.

Apply on Jobedly ⚡ One-click AI Apply

Similar jobs

Companies hiring for similar roles