Jobs and Careers
PL
Senior Specialist, Information Security, Third Party Risk
Planned ParenthoodTelecommuterRemotefull_timeVerifiedPosted 26 Mar 2026
About the role
Planned Parenthood is the nation’s leading provider and advocate of high-quality, affordable sexual and reproductive health care for all people, as well as the nation’s largest provider of sex education. Planned Parenthood organizations serve all people with care and compassion, with respect, and without judgment, striving to create equitable access to health care. Through health centers, programs in schools and communities, and online resources, Planned Parenthood is a trusted source of reliable education and information that allows people to make informed health decisions. We do all this because we care passionately about helping people lead healthier lives.
Planned Parenthood Federation of America (PPFA) is a 501(c)(3) charitable organization that supports the independently incorporated Planned Parenthood affiliates, which operate non-profit health centers across the U.S. PPFA also works to educate the public on and advocate for issues of sexual and reproductive health. Formed as the advocacy and political arm of Planned Parenthood Federation of America, Planned Parenthood Action Fund is a separate non-profit membership organization tax-exempt under section 501(c)(4). The Action Fund engages in educational, advocacy, and limited electoral activity, including grassroots organizing, legislative advocacy, and voter education in furtherance of the Planned Parenthood mission.
Planned Parenthood Federation of America (PPFA) and Planned Parenthood Action Fund seek a knowledgeable and proactive Senior Specialist, Information Security, Third Party Risk. This job reports directly to the Manager, Information Security, Third Party Risk in the Information Security department of PPFA. The Technology Strategy & Services division provides information security policies, procedures, and technical systems in order to maintain the confidentiality, integrity, and availability of all organizational healthcare information systems and their associated data.
Purpose:
- The Senior Specialist for the Information Security Third Party Risk Management (TPRM) team will be responsible for executing comprehensive information security risk assessments of third-party vendors engaged by PPFA, Affiliate, and Ancillary organizations. This includes evaluating vendors across multiple risk tiers to ensure they meet internal information security policies, HIPAA and PCI DSS requirements, and applicable regulatory standards. The Senior Specialist will thoughtfully analyze vendor-provided documentation, proactively identify potential risks, collaborate with key parties to determine appropriate risk management strategies, and produce detailed and accurate assessment reports to inform business, procurement, and contracting decisions. This role plays a critical part in safeguarding sensitive organizational data by ensuring that all third-party engagements align with PPFA’s privacy, compliance, and cybersecurity expectations and requirements.
Delivery:
- The Senior Specialist delivers by managing the end-to-end TPRM process for their assigned vendors. This includes initiating and maintaining communications with internal and external partners; reviewing and analyzing security and compliance documentation; identifying and documenting risks and control gaps; and producing formal assessment reports to inform risk management decisions. This role partners with vendors and internal stakeholders to ensure third-party engagements meet established security, privacy, and compliance requirements, and supports continuous improvement through diligent documentation, analysis, and escalation of identified issues.
- Initiate required communications in a timely manner and engage directly with key parties to gather needed information, clarify responses, and support risk management efforts.
- Review intake/triage responses in collaboration with the TPRM Manager to determine the appropriate evaluation path based on inherent risk indicators.
- Adhere to TPRM-defined SLAs, templates, processes, guidelines, requirements, and expectations throughout the TPRM lifecycle process.
- Conduct detailed information security risk assessments of third-party vendors across various risk levels (e.g., SaaS, consulting, low-risk), in alignment with strategies and expectations as defined by the Manager and within TPRM documentation.
- Evaluate all vendor-provided documentation and responses against internal policies and applicable regulatory and industry standards, including HIPAA, NIST CSF, PCI DSS, and PPFA information security policies.
- Produce clear and actionable risk assessment reports that communicate findings to procurement, legal, security, and business stakeholders to support risk management decision-making.
- Collaborate with internal partners to advise on vendor-related risks during intake, onboarding, and renewal processes.
- Monitor and report on assessment progress, inc
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s