Manager, Risk (IT)
DaVitaAbout the role
Posting Date
03/31/20262000 16th Street, Denver, Colorado, 80202, United States of AmericaManager, Risk (IT)
At DaVita, we find that our best leaders are those who create an inspiring vision for the future and empowers their team to achieve success. They have always enjoyed tackling difficult problems and believe that the best way to solve them is through collaborative, team efforts. They take ownership of results and instill accountability in those they lead. They are driven, strong communicators, relationship builders, and find real fulfillment in challenging work.
Here's what you can expect as a IT Risk Manager at DaVita:
Role Overview
The Manager, IT Risk reports to the Director of IT Risk & Audit and helps protect DaVita’s patients, teammates, and the Village by identifying, managing, and driving remediation of technology risk. This role leads a team of analysts responsible for third‑party/vendor risk assessments, formal exception management, HIPAA‑focused enterprise risk assessments, and continuous monitoring of vendor partners.
This role balances strong risk governance with practical business enablement, ensuring risks are clearly understood, ownership is defined, and remediation is achievable and timely.
Key Responsibilities
Team Leadership & Development
Lead, coach, and develop a team of IT Risk Analysts; set clear expectations and manage workload, prioritization, and quality.
Foster a collaborative, accountable team culture focused on outcomes and continuous improvement.
Establish and maintain standard playbooks, templates, and quality practices.
Third‑Party Risk Management
Oversee the end‑to‑end third‑party risk assessment lifecycle for technology vendors.
Ensure assessments appropriately address cloud services, AI‑enabled solutions, and emerging technology risks.
Partner with Procurement, Legal, Privacy, and Information Security to align risk expectations with onboarding, renewals, and contracting.
Communicate risk findings clearly to support informed business decisions.
Exception Management
Own the formal exception process for security policy and standards violations.
Evaluate risk, document compensating controls, manage approvals, track expirations, and drive remediation.
Maintain transparency and escalation for aged or high‑risk exceptions.
Enterprise Risk Assessments (HIPAA)
Conduct and oversee enterprise risk assessments related to HIPAA control gaps or failures.
Document clear risk statements, assess likelihood and impact, and map findings to appropriate frameworks
Partner with Privacy, Compliance, and IT Audit teams to ensure patient data protection remains central to risk decisions.
Continuous Monitoring
Run a continuous monitoring program to identify changes in vendor risk posture, including incidents and control changes.
Define monitoring tiers and response triggers aligned to vendor criticality.
Translate monitoring signals into actionable risk decisions and follow‑up.
Risk Tracking, Reporting & Governance
Maintain risk registers, remediation trackers, and exception metrics.
Drive clear ownership and accountability for remediation across IT and business partners.
Prepare concise, executive‑ready reporting on key risks, trends, and decisions.
Apply HIPAA, ISO, and NIST principles in practical, business‑aligned ways.
Support internal and external audits and help reduce repeat findings.
Process Improvement & Tooling
Continuously improve intake, assessment, exception, and monitoring processes.
Leverage cloud and AI tools thoughtfully to improve efficiency and insight.
Identify opportunities to simplify, automate, and scale risk processes.
Required Qualifications
5+ years of experience in IT security, IT risk management, compliance, audit, or a related field.
Experience leading people or complex risk workstreams.
Hands‑on experience with third‑party/vendor risk assessments and exception management.
Working knowledge of HIPAA, ISO, and NIST frameworks.
Strong ability to translate technical risk into clear, business‑relevant recommendations.
Demonstrated ability to drive risk remediation through partnership and accountability.
Preferred Qualifications
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s