Program Manager – Third Party Risk Management
Sentara HealthAbout the role
City/State
Norfolk, VAWork Shift
First (Days)Overview:
Overview
The Third-Party Risk Program Manager is responsible for the end-to-end management of the organization’s third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle — from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding — ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness
Key Responsibilities
Program Management
Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle
Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders
Identify process gaps and drive continuous improvement of program workflows
Be a part of the team and support the execution of the program
Vendor Management
Serve as the primary point of contact for third-party vendors throughout the assessment and management process
Coordinate with vendors to gather required documentation, evidence, and remediation plans
Track vendor responsiveness and escalate delays or non-compliance issues appropriately
Risk Assessments (OneTrust)
Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion
Analyze assessment results to identify risk levels, gaps, and required remediation actions
Maintain accurate, up-to-date vendor and assessment records within OneTrust
Generate reports and dashboards from OneTrust to support program reporting and audits
Documentation & Compliance
Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current
Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)
Support internal and external audits by providing timely and accurate documentation
Cross-Functional Collaboration
Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage
Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stak
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s