Role Description
Omnicell is building its AI governance program and we are looking for a Manager, AI Vendor Governance to join our Legal Department and own how AI enters the company through third parties.
As a foundational member of Omnicell’s AI Governance Program, you will design and operate a third-party intake process that identifies AI solutions entering the organization, evaluates them against the company’s responsible-AI and risk standards, and determines the level of risk each presents to the business. Working closely with Procurement, Legal, Privacy, Security, Quality, and business owners, you will establish questionnaires, risk-tiering criteria, and review workflows that allow Omnicell to adopt AI tools quickly and responsibly.
Qualifications
-
6+ years of experience in third-party or vendor risk management, IT or security risk, compliance, or a related governance function
-
Demonstrated experience building or substantially maturing a vendor risk or governance program, including intake and risk-tiering processes
-
Strong knowledge of third-party and vendor risk management principles and lifecycle, from intake and due diligence through monitoring and offboarding
-
Familiarity with AI and machine learning concepts and the risks they raise, including bias, transparency, data privacy, security, and model reliability
-
Working knowledge of AI governance frameworks and standards, such as the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act
-
Familiarity with security and privacy frameworks commonly used in vendor assessments, such as SOC 2, ISO 27001, HIPAA, and GDPR
-
A talent for designing clear, repeatable processes and operationalizing them across a cross-functional organization
-
The ability to assess complex risk and make pragmatic, risk-calibrated recommendations that balance innovation with protection of the business
-
A track record of partnering across Procurement, Legal, Privacy, Security, and business owners, with excellent stakeholder management skills
-
The ability to explain technical and risk concepts clearly to both technical and non-technical audiences
-
The ability to operate independently in a fast-moving environment, manage competing priorities, and stay highly organized, with sharp attention to detail and a commitment to thorough documentation
Requirements
-
Bachelor’s degree, or equivalent practical experience
-
Experience assessing AI or machine learning solutions, or building AI-specific risk controls
-
Healthcare, life sciences, or other regulated-industry experience
-
Relevant certifications, such as AIGP, CIPP, CIPM, CTPRP, CRISC, CISA, or CISSP
-
Experience with third-party risk, GRC, or AI governance tooling, such as ServiceNow, OneTrust, or similar platforms
-
Familiarity with AI assurance artifacts, such as model cards, system cards, and impact assessments, and with vendor monitoring tools
-
Relevant advanced education, such as a degree or coursework in law, risk management, information security, data science, or a related field, or equivalent experience
Benefits
-
Flexibility in working hours as needed
-
Some travel, ~10%