HomeSearch › Job

Sr Mgr Third Party Risk

recruiting2.ultipro.com:BAY1006BML:0669eed3-5441-4f8e-a7b1-c5df596a4dfe

USA · manager

JOB SUMMARY Baylor Genetics is seeking a Manager, Third Party Risk to build, lead, and mature our enterprise Third-Party Risk Management (TPRM) program. As one of the nation’s leading clinical genetic testing laboratories, we entrust vendors and partners with highly sensitive data including Protected Health Information (PHI) and Sensitive Personal Information, this role ensures every third party that creates, receives, maintains, transmits, or accesses that data does so in compliance with HIPAA, GDPR, CLIA, CAPA, and other applicable regulatory requirements.

Reporting to the Director of Information Security, the Third Party Risk Manager owns the full vendor lifecycle intake, risk tiering, security and privacy assessment, onboarding, ongoing monitoring, and offboarding for both upstream and downstream vendors. This role also leads Baylor Genetics’ recurring User Access Review (UAR) program and drives audit readiness across ISO 27001, ISO 27701, ISO 42001, and HITRUST.

Scope may evolve as organizational needs change. KEY RESPONSIBILITIES Third-Party / Vendor Risk Management • Lead and continuously mature the enterprise Third-Party Risk Management program using a risk-based, lifecycle approach covering both upstream and downstream vendors. • Own vendor intake and reassessment, inherent-risk scoring, risk-tier assignment, and lead security and cybersecurity reviews SOC 2, HITRUST, ISO 27001) for medium- and high-risk vendors.

• Establish a standardized vendor onboarding, continuous monitoring, and reassessment process leveraging the SIG questionnaire, and draft the SOPs, policies, and documentation that govern intake, assessment, and monitoring. • Conduct internal and external vendor audits including “high-risk” upstream vendors with access to PHI, PII, and AI categorize vendors by criticality, and maintain a vendor risk heat map and single source of truth.

• Operate ongoing monitoring (annual reassessment for high-risk, biennial for medium-risk vendors), track remediation, and collaborate with cross departmental stakeholders to ensure BAAs/DPAs, DPIAs/TIAs, and sub-processor requirements are in place. User Access Reviews & Governance • Develop and manage the recurring (quarterly) User Access Review program across in-scope applications, including employees, contractors, temporary staff, and vendors, and extend coverage to administrator and privileged accounts.

• Enforce least-privilege access, collect attestations of completion, and produce evidence to support HIPAA, GDPR, IGTC, and other applicable audit requirements. • Drive audit readiness and evidence collection across ISO 27001, ISO 27701, ISO 42001, and HITRUST, partnering with Privacy, Compliance, and Legal. Reporting & Collaboration • Produce regular reports, KPIs, and risk metrics for leadership on vendor risk posture, remediation status, and audit progress.

• Partner cross-functionally with Security, Privacy, Compliance, Procurement, and application teams; where vendors deliver software, review application-security evidence including static code analysis (e.g., SonarQube/SAST) results. Other Duties: • Contribute to a culture of integrity and service by putting the customer first, treating colleagues with respect, and conducting business with the highest standards of professionalism.

• Perform other job-related duties as assigned to support the team and business needs. QUALIFICATIONS Required • Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field or an equivalent combination of education and experience. • Minimum of 6–8 years of experience in information security, risk, or compliance, including demonstrated experience creating and running upstream and downstream vendor management programs.

• Hands-on audit experience with ISO 27001, ISO 27701, and ISO 42001. • Demonstrated HITRUST experience (assessment, re

Search all live jobs — free, no account →