One million success stories. Start yours today.

Manager -Cyber Third Party Risk

Date Posted: Jul 05, 2026
Yearly: USD - USD

Job Detail

  • location_on
    Location New Norfolk, Virginia, United States of America
  • desktop_windows
    Job Type: Permanent
  • schedule
    Shift:
  • analytics
    Career Level:
  • group
    Positions:
  • calendar_view_day
    Experience:
  • male
    Gender: No Preference
  • school
    Degree:
  • calendar_month
    Apply Before: Oct 03, 2026

Job Description

Overview

City/State Norfolk, VAWork Shift First (Days)Overview:OverviewAs a Cyber Third-Party Risk Manager, you will play a critical role developing, enhancing and executing the third-party risk management program including onboarding, maintenance and ongoing monitoring, and offboarding of third-party suppliers. Your primary responsibilities will include identifying and categorizing third party vendors based on risk, understanding and prioritizing the risks, establishing and enforcing key controls to mitigate the risk, perform continuous monitoring that tracks and reassesses third parties, and ensure third party contractual compliance with Sentara policy and standards. You will also be responsible for negotiating and maintaining the information security exhibit with the vendors through the contracting process. Key ResponsibilitiesRegularly interact with all levels of management to present and discuss third-party risk managementConduct comprehensive risk assessments of third-party vendors based on riskManage a team of assessors for performing vendor assessments and vendor contracts negotiationsAnalyze and prioritize risks based on their potential impact on the organization's operations, data, and reputation.Develop and streamline the third-party risk management process.Identify and assess vulnerabilities within vendor systems, networks, and applications.Collaborate with cross-functional teams, including IT, security, and compliance, to develop and implement risk mitigation strategies.Prepare detailed third-party risk assessment reports, including findings, recommendations, and mitigation plans, for presentation to management.Maintain accurate and up-to-date documentation of third-party risk assessment activities, findings, and risk treatment plans.Assist in audits and assessments to demonstrate compliance with cybersecurity standards.Education: Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field (preferred)(OR)Experience in lieu of Bachelor's Degree- 7+ years of experience in cybersecurity, with at least 3 years in risk management Certification/Licensure CISSP (Certified Information Systems Security Professional) (Preferred)CISM (Certified Information Security Manager)(Preferred)CRISC (Certified in Risk and Information Systems Control)(Preferred)CISA (Certified Information Systems Auditor)(Preferred) Experience 5+ years of experience in cybersecurity, with at least 3 years in risk management with a degree (Required)7+ years of experience in cybersecurity, with at least 3 years in risk management without a degree) (Required)Strong understanding of cybersecurity principles, risk assessment methodologies, and threat landscape analysis. 3 years' experience managing a third-party risk management program and team Proficiency in performing third-party risk assessments and negotiating contractual security languageKnowledge of regulatory compliance requirements and industry standards.Excellent analytical and problem-solving skills. Effective communication and interpersonal abilities to collaborate with multidisciplinary teams. Experience in healthcare or other highly regulated industries preferredDeep understanding of cybersecurity frameworks (NIST CSF, NIST 800-53, ISO 27001, HITRUST)Knowledge of healthcare regulations (HIPAA, HITECH) and their technical requirementsFamiliarity with risk assessment methodologies and toolsUnderstanding of security technologies, controls, and best practicesExperience with GRC (Governance, Risk, and Compliance) platforms such as ServiceNOW, OneTrusKeyword, Cybersecurity Risk, TPRM Talroo - ITWe provide market-competitive compensation packages, inclusive of base pay, incentives, and benefits. The base pay rate for Full Time employment is:$116,729.60-$216,777.60. Additional compensation may be available for this role such as shift differentials, standby/on-call, overtime, premiums, extra shift incentives, or bonus opportunities.Benefits: Caring For Your Family and Your Care

Key responsibilities

Not specified in the original listing.

Required skills

  • I.T. & Communications

What the company offers

Not specified in the original listing.

Skills Required

Company Overview

Virginia Beach, Virginia, United States of America

Sentara Health is a healthcare organization focused on operational improvement and quality care. They emphasize innovation and efficiency in their processes to enhance patient experience and resource utilization. Read More

Google Map

Related Jobs