×
Register Here to Apply for Jobs or Post Jobs. X

Director, 3rd Party Security Risk

Job in Jacksonville, Duval County, Florida, 32290, USA
Listing for: HealthEquity, Inc.
Full Time position
Listed on 2026-07-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 151500 - 200500 USD Yearly USD 151500.00 200500.00 YEAR
Job Description & How to Apply Below

Overview

Health Equity relies on a broad ecosystem of third party partners, vendors, platforms, and service providers to support member, client, and teammate experiences while protecting trust, resilience, and compliance. The Director of 3rd Party Risk is a strategic leadership role responsible for overseeing and evolving the 3rd party risk management program into an enterprise-wide, AI-aware risk governance capability.

In this role, you will drive a pragmatic, measurable program that defines “what good looks like” across vendor tiers, incorporates AI and agentic system risks into due diligence and lifecycle oversight, and aligns third party risk practices with enterprise strategy, regulatory expectations, resiliency objectives, and business priorities. The Director will lead a growing team and collaborate cross-functionally with Security, Procurement, Legal, Privacy, Enterprise Risk, IT, Engineering, Finance, and business owners to identify, assess, quantify, and manage third party risks across cybersecurity, resiliency, financial, operational, contractual, reputational, and AI domains.

This role is critical in establishing clear operating procedures, risk-tiered requirements, meaningful KRIs/KPIs, and board-ready reporting, ensuring third party relationships and AI-enabled vendor services align with the company’s risk appetite, strategic objectives, and obligation to protect member, client, and company data while fostering a culture of accountability and resilience.

What you’ll be doing

  • Develop and execute a transformatiomal third-party risk strategy that integrates cybersecurity, privacy, resiliency, financial, operational, contractual, reputational, and AI risks into enterprise goals.
  • Design policies, standards, playbooks, and scalable processes to streamline third party intake, risk assessments, issues mananagement, offboarding and continuous monitoring and automated assurance of controls while reducing duplicative or low-value work.
  • Incorporate AI and agentic systems and solutions into the TPRM lifecycle, including AI-use disclosure, AI-specific due diligence, data-use restrictions, model or system documentation review, human oversight expectations, output integrity, monitoring, incident response, and residual risk acceptance.
  • Partner with the AI Governance Council, Legal, Privacy, Enterprise Risk, Data Governance, Procurement, and business owners to ensure third party-sourced AI capabilities are reviewed, approved, monitored, and governed consistently with enterprise AI policies and standards.
  • Establish meaningful KRIs, KPIs, dashboards, and management routines that demonstrate whether the program is buying down third-party risk, including coverage, assessment quality, remediation aging, contract control gaps, external risk posture, AI-enabled vendor coverage, and unresolved risk acceptances.
  • Design and maintain tier-based operating procedures that clearly articulate what is required for tiered third party, including required risk assessments, contract safeguards, monitoring cadence, remediation expectations, and escalation triggers.
  • Lead third party tiering and re-tiering efforts using objective criteria such as criticality, data sensitivity, regulatory exposure, operational dependency, resiliency impact, replaceability, AI usage, and business materiality.
  • Identify and address risks proactively, engaging stakeholders to drive effective remediation efforts.
  • Identify and address risks proactively, engaging stakeholders to drive effective remediation efforts and ensuring ownership is assigned across Security, Procurement, Legal, IT, Engineering, Finance, Enterprise Risk, and business teams.
  • Prepare strategic updates of third-party and AI-enabled risk updates for executive leadership, auditors, regulators, and the board of directors.
  • Support Legal and Procurement as an infosec SME in collaboration with security relevant teams for negotiating and approving third-party contracts.
  • Collaborate across teams to ensure third-party risk management practices are integrated and aligned into procurement, contracting, technology governance, SaaS security, identity governance, business continuity, incident…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary