Logo for Sentara Healthcare

Program Manager – Third Party Risk Management

Role overview

Qualifications

  • Bachelor’s degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry
  • 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry without a Bachelor's degree preferred
  • Hands-on experience with OneTrust or similar GRC/risk management platforms
  • Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements

Responsibilities

  • Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle
  • Serve as the primary point of contact for third-party vendors throughout the assessment and management process
  • Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion
  • Ensure all program documentation is accurate, complete, and current

About the company

Sentara Healthcare logo

Sentara Healthcare

Hospitals & Health Care

Sentara Health celebrates a 130-year history of innovation, compassion, and community benefit. Based in Norfolk, VA, Sentara is a diverse not-for-profit family of 12 hospitals, an array of integrated services, and a team of nearly 30,000 strong on a mission to improve health every day. This is pursued through a disciplined strategy to achieve Top 10% performance in key measures through shared best practices, transformation of primary care through clinical integration and strategic growth that adds value to the communities we serve in Virginia and North Carolina. Like us on Facebook at www.facebook.com/sentarahealth Follow us on Instagram at @SentaraHealth

Company details

Company typeXLarge
IndustryHospitals & Health Care
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

City/State

Norfolk, VA

Work Shift

First (Days)

Overview:

Overview

The Third-Party Risk Program Manager is responsible for the end-to-end management of the organization’s third-party risk management program within a healthcare environment. This individual contributor role owns the program lifecycle — from vendor onboarding and risk assessment through ongoing monitoring, documentation, and offboarding — ensuring third party relationships comply with applicable healthcare regulations (e.g., HIPAA, HITECH) and internal policy. The role requires close collaboration with vendors and cross-functional partners including Legal, Information Security, Privacy, Procurement, and Compliance to ensure full program coverage and audit readiness

Key Responsibilities  

Program Management  

  • Own and drive the third-party risk program end-to-end, ensuring consistent execution across the vendor lifecycle  

  • Establish and maintain program timelines, milestones, and status reporting for leadership and stakeholders  

  • Identify process gaps and drive continuous improvement of program workflows 

  • Be a part of the team and support the execution of the program  

Vendor Management  

  • Serve as the primary point of contact for third-party vendors throughout the assessment and management process  

  • Coordinate with vendors to gather required documentation, evidence, and remediation plans  

  • Track vendor responsiveness and escalate delays or non-compliance issues appropriately  

Risk Assessments (OneTrust 

  • Manage and execute third-party risk assessments using OneTrust, including assessment creation, distribution, tracking, and completion  

  • Analyze assessment results to identify risk levels, gaps, and required remediation actions  

  • Maintain accurate, up-to-date vendor and assessment records within OneTrust  

  • Generate reports and dashboards from OneTrust to support program reporting and audits  

Documentation & Compliance  

  • Ensure all program documentation (policies, procedures, assessment records, contracts, remediation plans) is accurate, complete, and current  

  • Maintain audit-ready documentation in alignment with healthcare regulatory requirements (HIPAA, HITECH, and other applicable frameworks)  

  • Support internal and external audits by providing timely and accurate documentation 

Cross-Functional Collaboration  

  • Partner with Legal, Information Security, Privacy, Procurement, and business owners to ensure comprehensive risk coverage  

  • Communicate program requirements, risk findings, and remediation needs clearly to non-technical and technical stakeholders alike  

  • Act as a liaison between vendors and internal teams to resolve issues and keep the program moving forward  

Education

  • Bachelor Level Degree (Preferred)

  • 5+ years relevant experience may be accepted in lieu of degree

Certification/Licensure

  • Certification in risk, or compliance (e.g., CTPRP, CRISC)   preferred

Experience

Required  

  • Bachelor’s degree with 3+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry  

  • 5+ years of experience in third-party/vendor risk management, program management, or compliance, ideally within healthcare or a regulated industry  without a Bachelor's degree preferred.

  • Hands-on experience with OneTrust or similar GRC/risk management platforms  

  • Working knowledge of HIPAA, HITECH, and healthcare data privacy/security requirements  

  • Strong organizational skills with the ability to manage multiple vendors and assessments simultaneously  

  • Excellent written and verbal communication skills, with experience working cross functionally  

Preferred  

  • Certification in risk, or compliance (e.g., CTPRP, CRISC)  

  • Experience with vendor contract review or working alongside Legal/Procurement  

  • Familiarity with information security risk assessment frameworks (e.g., NIST, HITRUST)  

We provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:$106,080.00-$176,820.80. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.


Benefits: Caring For Your Family and Your Career

Medical, Dental, Vision plans

• Adoption, Fertility and Surrogacy Reimbursement up to $10,000

• Paid Time Off and Sick Leave

• Paid Parental & Family Caregiver Leave

• Emergency Backup Care

• Long-Term, Short-Term Disability, and Critical Illness plans

• Life Insurance

• 401k/403B with Employer Match

• Tuition Assistance – $5,250/year and discounted educational opportunities through Guild Education

• Student Debt Pay Down – $10,000

•Pet Insurance 
•Legal Resources Plan
•Colleagues have the opportunity to earn an annual discretionary bonus if established system and employee eligibility criteria is met.

Sentara Health is an equal opportunity employer and prides itself on the diversity and inclusiveness of its close to an almost 30,000-member workforce. Diversity, inclusion, and belonging is a guiding principle of the organization to ensure its workforce reflects the communities it serves.


In support of our mission “to improve health every day,” this is a tobacco-free environment.

For positions that are available as remote work, Sentara Health employs associates in the following states:

Alabama, Delaware, Florida, Georgia, Idaho, Indiana, Kansas, Louisiana, Maine, Maryland, Minnesota, Nebraska, Nevada, New Hampshire, North Carolina, North Dakota, Ohio, Oklahoma, Pennsylvania, South Carolina, South Dakota, Tennessee, Texas, Utah, Virginia, Washington, West Virginia, Wisconsin, and Wyoming.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Program Manager Related jobs

Other jobs at Sentara Healthcare

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.