Overview of the Role: Reporting to the Chief Information Security Officer (CISO) the Third-Party Enterprise Risk Manager is responsible for managing and growing a comprehensive third-party risk management program across the organization. This role is responsible for ensuring that Privia Health's information assets are safeguarded against cyber threats originating from third and fourth parties. The position involves leading the Third Party Access Committee (TPAC), driving compliance with federal and state regulations (such as HIPAA, SOX, HITRUST, and state privacy laws), and implementing industry best practices for vendor risk management. The manager will collaborate cross-functionally to identify, evaluate, and mitigate risks associated with all third-party engagements, contributing to the organization's strategic objectives and security posture.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
501-1,000 employees