Cyber Security Third Party Risk Program Manager at Insight Global in Richmond, Virginia

Posted in Other about 2 hours ago.

Type: full-time





Job Description:

MUST be located in one of the following states: Alabama, Delaware, Florida, Georgia, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington (State), West Virginia, Wisconsin, Wyoming.

Insight Global is seeking a Cyber Security Third Party Risk Manager to join the GRC team at one of our largest health insurance clients. This is a fully remote role (see approved state list) and will be a 6-month contract-to-hire format. As a Cyber Security Third-Party Risk Manager, this individual will play a critical role developing, enhancing and executing the third-party risk management program including onboarding, maintenance and ongoing monitoring, and offboarding of third-party suppliers. Primary responsibilities will include identifying and categorizing third-party vendors based on risk, understanding and prioritizing the risks, establishing and enforcing key controls to mitigate the risk, performing continuous monitoring that tracks and reassesses third parties, and ensuring third party contractual compliance with Sentara policy and standards.

Key Responsibilities:
  • Regularly interact with all levels of management to present and discuss third-party risk management
  • Conduct comprehensive risk assessments of third-party vendors based on risk
  • Manage a team of assessors for performing vendor assessments and vendor contracts negotiations
  • Analyze and prioritize risks based on their potential impact on the organization's operations, data, and reputation.
  • Develop and streamline the third-party risk management process.
  • Identify and assess vulnerabilities within vendor systems, networks, and applications.
  • Collaborate with cross-functional teams, including IT, security, and compliance, to develop and implement risk mitigation strategies.
  • Prepare detailed third-party risk assessment reports, including findings, recommendations, and mitigation plans, for presentation to management.
  • Maintain accurate and up-to-date documentation of third-party risk assessment activities, findings, and risk treatment plans.
  • Assist in audits and assessments to demonstrate compliance with cybersecurity standards.

Desired Characteristics:
  • Organized and detail-oriented, able to work well under deadlines in a changing environment and complete multiple projects effectively and concurrently.
  • Demonstrated customer focus -
  • Strong analytical skills - strong problem-solving skills, communicates in a clear and succinct manner and effectively evaluates information/data to make decisions; anticipates obstacles and develops plans to resolve.
  • Change oriented - actively generates process improvements; supports and drives change and confronts difficult circumstances in creative ways. Self-motivated, self-directed, flexible, and able to work under pressure and in fast paced team environment.
  • Demonstrated ability to lead and motivate staff and to apply skills and techniques to solve dynamic problems.

Must Haves:
  • 10 years of experience in Governance, Risk, and Compliance (GRC) related roles.
  • 2-3 years of experience successfully managing a third-party risk, or vendor due diligence team/program in cyber security.
  • Proficiency in performing third-party risk assessments and negotiating contractual security language with vendors' legal and information security teams.
  • Strong background in risk and controls, security controls, auditing, and system security.
  • Relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA).
  • Experience with industry regulations and frameworks such as HIPAA, NIST, and ISO 27001.

Plusses:
  • Bachelor's degree in computer science, Information Security, or experience in related field
  • Healthcare industry experience / working in a highly regulated environment.
  • Experience with GRC tools such as Service Now, One Trust, Archer, etc.

More jobs in Richmond, Virginia

Other
21 minutes ago

Bobcat of South Richmond
Other
35 minutes ago

Insight Global
Other
36 minutes ago

CarMax
More jobs in Other

Other
less than a minute ago

HMG Careers
Other
less than a minute ago

HMG Careers
Other
less than a minute ago

HMG Careers