Director, 3rd Party Security Risk @HealthEquity
All Others
Salary $151500.00 - $2..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1wk ago

[Hiring] Director, 3rd Party Security Risk @HealthEquity

1wk ago - HealthEquity is hiring a remote Director, 3rd Party Security Risk. 💸 Salary: $151500.00 - $200500 📍Location: USA

Role Description

HealthEquity relies on a broad ecosystem of third-party partners, vendors, platforms, and service providers to support member, client, and teammate experiences while protecting trust, resilience, and compliance. The Director of 3rd Party Risk is a strategic leadership role responsible for overseeing and evolving the 3rd party risk management program into an enterprise-wide, AI-aware risk governance capability.

In this role, you will:

  • Drive a pragmatic, measurable program that defines “what good looks like” across vendor tiers.
  • Incorporate AI and agentic system risks into due diligence and lifecycle oversight.
  • Align third-party risk practices with enterprise strategy, regulatory expectations, resiliency objectives, and business priorities.
  • Lead a growing team and collaborate cross-functionally with Security, Procurement, Legal, Privacy, Enterprise Risk, IT, Engineering, Finance, and business owners.
  • Identify, assess, quantify, and manage third-party risks across various domains.
  • Establish clear operating procedures, risk-tiered requirements, meaningful KRIs/KPIs, and board-ready reporting.

This role is critical in ensuring third-party relationships and AI-enabled vendor services align with the company’s risk appetite, strategic objectives, and obligation to protect member, client, and company data while fostering a culture of accountability and resilience.

What you’ll be doing:

  • Develop and execute a transformational third-party risk strategy that integrates various risks into enterprise goals.
  • Design policies, standards, playbooks, and scalable processes for third-party intake, risk assessments, issues management, offboarding, and continuous monitoring.
  • Incorporate AI and agentic systems into the TPRM lifecycle.
  • Partner with various councils and teams to ensure third-party-sourced AI capabilities are reviewed, approved, monitored, and governed.
  • Establish meaningful KRIs, KPIs, dashboards, and management routines.
  • Design and maintain tier-based operating procedures for third-party risk management.
  • Lead third-party tiering and re-tiering efforts using objective criteria.
  • Identify and address risks proactively, engaging stakeholders for effective remediation.
  • Prepare strategic updates for executive leadership, auditors, regulators, and the board of directors.
  • Support Legal and Procurement as an infosec SME for negotiating and approving third-party contracts.
  • Collaborate across teams to ensure alignment of third-party risk management practices.
  • Lead creation, execution, and automation of security, privacy, resiliency, and AI-specific assessments.
  • Validate third-party security controls and AI controls for compliance.
  • Track and report remediation progress and unresolved risks.
  • Facilitate risk acceptance processes and escalate critical issues as needed.
  • Reassess critical third-party security and AI risks periodically.
  • Support audit inquiries, regulatory exams, client due diligence, and executive requests.
  • Set team goals aligned with organizational priorities and foster continuous improvement.
  • Other third-party leadership duties as assigned.

Qualifications

  • Bachelor’s Degree in Computer Science or Engineering, or a related technical field.
  • 12+ years of combined experience in information security.
  • Prior supervisory experience.

Requirements

  • Ability to integrate with the existing team and deliver on key objectives.
  • Build constructive relationships with diverse groups of people.
  • Demonstrates excellent communication and listening skills.
  • Drives results and champions change.
  • Knowledge of AI technologies, governance concepts, and third-party AI risks.
  • Experience in reviewing technical policies and developing standard operating procedures.
  • High level of credibility and a technical background in security.
  • Strong passion and motivation for security.

Benefits

  • Medical, dental, and vision.
  • HSA contribution and match.
  • Dependent care FSA match.
  • Uncapped paid time off.
  • Paid parental leave.
  • 401(k) match.
  • Personal and healthcare financial literacy programs.
  • Ongoing education & tuition assistance.
  • Gym and fitness reimbursement.
  • Wellness program incentives.
Before You Apply
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Director, 3rd Party Security Risk @HealthEquity
All Others
Salary $151500.00 - $2..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1wk ago
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 125,000+ Remote Jobs
🇺🇸 Be aware of the location restriction for this remote position: USA Only
Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply
Applied
Sent Follow-Up
Interview Scheduled
Interview Completed
Offer Accepted
Offer Declined
Application Denied
Unlock 125,000+ Remote Jobs
×

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews
Unlock All Jobs Now

Maybe later