About the Role
Detego Health is growing quickly, and the integrity of our third-party risk program has to grow with it. This role owns that program end to end. You are accountable not only for completing vendor assessments, but for the reliability of the record itself.
At any moment, leadership, an auditor, or a client should be able to ask which vendors are assessed, what the risk recommendation was, what evidence supports it, and whether any remediation, exception, contract, or reassessment obligation remains open. The answer must hold up.
If you are looking for a role where you close tickets and wait for direction, this is not it. If you want to own a program and be measured on whether it can be trusted, this role is built for you.
What You Own
- The vendor risk register as the authoritative source of truth. Every assessment recorded as complete is substantiated by retained evidence, and reported status reconciles to that evidence at all times.
- The full vendor lifecycle, including intake and onboarding, risk tiering, assessment, remediation tracking, annual reassessment, material change review, contract renewal risk checks, and offboarding.
- The risk recommendation. You assess, document, and recommend risk acceptance, mitigation, rejection, or escalation, and you bring unresolved risk through the formal risk acceptance process.
- The evidence trail. Assessment conclusions, risk recommendations, exceptions, remediation, and approvals are documented as the work happens, not reconstructed afterward.
- Contract and regulatory risk coordination. You coordinate review of business associate agreements, data processing agreements, audit rights, subcontractor provisions, insurance requirements, security obligations, privacy obligations, and regulatory commitments.
- Reporting leadership can rely on. Monthly and quarterly views of KPIs, high and critical vendor risks, remediation status, exceptions, and reassessment activity reconcile to the register without adjustment.
What You Will Do
- Conduct vendor risk assessments using recognized due diligence methods such as SIG Lite and CAIQ, and tier vendors by inherent and residual risk.
- Review SOC reports, security questionnaires, insurance certificates, penetration test summaries, privacy documentation, business continuity evidence, subcontractor information, and other due diligence artifacts to assess vendor risk.
- Communicate directly with vendors to obtain security, privacy, compliance, continuity, and insurance documentation, clarify control responses, and drive remediation to closure.
- Partner with Procurement, Finance, Legal, Information Systems, Operations, Privacy and Compliance, Security, and business owners so vendor engagements carry required terms, including BAAs and DPAs, before access or data sharing begins.
- Monitor contract expirations and control triggers, enforce documentation and response SLAs, and initiate reassessments on schedule.
- Maintain the risk scoring methodology and keep the vendor risk register current, complete, accurate, and audit ready.
- Track exceptions and bring them through formal risk acceptance with a clear owner, rationale, expiration, review cadence, and retained evidence.
- Ensure contractual risk requirements are incorporated into assessment activities and tracked through remediation when necessary.
- Prepare leadership reporting on vendor risk, high and critical findings, overdue assessments, remediation status, exception status, and reassessment performance.
What Success Looks Like
First 90 Days
- The current vendor population is validated against the vendor risk register and evidence repository.
- Gaps between recorded assessment status and supporting documentation are identified, prioritized, and actively remediated.
- A reconciliation routine is established to keep the register, evidence repository, and reporting aligned going forward.
- High and critical vendor risks are visible, assigned, and tracked with clear remediation or escalation paths.
- The reassessment schedule and lifecycle triggers are documented and operating.
Within Six Months
- Any assessment marked complete can be evidenced on demand without reconstruction.
- Leadership reporting reconciles to the vendor risk register and evidence repository without manual adjustment.
- High and critical vendor risks have documented owners, remediation plans, due dates, and reporting visibility.
- Vendor reassessment schedules operate consistently and do not depend on ad hoc reminders.
- Exceptions and risk acceptances have documented approvals, owners, expiration dates, and review cadence.
What We Are Looking For
- Five or more years in third party risk, vendor risk, IT risk, security risk, procurement risk, or GRC, preferably in healthcare, a TPA, health plan, or another regulated environment.
- Strong command of SOC 2, HIPAA, vendor due diligence, BAAs, DPAs, subcontractor risk, insurance evidence, and contractual risk obligations.
- Fluency in vendor due diligence frameworks and artifacts such as SIG Lite, CAIQ, SOC 1, SOC 2, security questionnaires, policies, penetration test summaries, and business continuity documentation.
- A track record of owning assessments, remediations, vendor obligations, risk registers, and evidence workflows with minimal oversight.
- Strong documentation discipline and ability to keep a defensible record while moving work forward.
- Working familiarity with GRC tooling and evidence workflows. Experience with Vanta, BitSight, SharePoint, Microsoft Forms, and Power Automate is a plus.
- CTPRP, CISA, CISSP, CRISC, or comparable certification strongly preferred.
The Kind of Person Who Thrives Here
You operate independently and move quickly, but you never trade speed for a record you cannot defend. You are comfortable being the person an auditor, client, vendor, or executive stakeholder speaks with about third-party risk.
You treat the vendor risk register as a control, not a spreadsheet. You would rather surface a gap early than explain one later. You are direct with vendors, practical with business owners, and disciplined with evidence.
Equal Opportunity Statement
Detego Health is an Equal Opportunity Employer. We are committed to an inclusive workplace.
Job Type: Full-time
Pay: $100,000.00 - $120,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Dental insurance
- Employee assistance program
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Vision insurance
Work Location: In person