GRC CareersAGJ, the AI governance job boardPost a Job

Jobs › Director, 3rd Party Security Risk

Director, 3rd Party Security Risk

HealthEquity

Job at a glance

Category
GRC
Work arrangement
Remote
Location
Remote
Salary range
$151,500
Posted
Aug 31, 2026
Apply for this jobApplications go directly to HealthEquity
Applying today? Most GRC roles fill fast. Get the next ones the day they post, in Remote.

Free. One click to unsubscribe. We never share your address.

ShareEmailLinkedInXFacebookPrint / Save PDF

HealthEquity is hiring a Director, 3rd Party Security Risk in Remote. This is a GRC job in the governance, risk, and compliance field, with a posted range of $151,500. Review the full details below and apply directly with HealthEquity.

Our Mission Our mission is to SAVE AND IMPROVE LIVES BY EMPOWERING HEALTHCARE CONSUMERS. Come be part of remarkable. Overview How you can make a difference HealthEquity relies on a broad ecosystem of third party partners, vendors, platforms, and service providers to support member, client, and teammate experiences while protecting trust, resilience, and compliance. The Director of 3rd Party Risk is a strategic leadership role responsible for overseeing and evolving the 3rd party (third-party) risk management program into an enterprise-wide, AI-aware risk governance capability. In this role, you will drive a pragmatic, measurable program that defines “what good looks like” across vendor tiers, incorporates AI and agentic system risks into due diligence and lifecycle oversight, and aligns third party risk practices with enterprise strategy, regulatory expectations, resiliency objectives, and business priorities. The Director will lead a growing team and collaborate cross-functionally with Security, Procurement, Legal, Privacy, Enterprise Risk, IT, Engineering, Finance, and business owners to identify, assess, quantify, and manage third party risks across cybersecurity, resiliency, financial, operational, contractual, reputational, and AI domains. This role is critical in establishing clear operating procedures, risk-tiered requirements, meaningful KRIs/KPIs, and board-ready reporting, ensuring third party relationships and AI-enabled vendor services align with the company’s risk appetite, strategic objectives, and obligation to protect member, client, and company data while fostering a culture of accountability and resilience. What you’ll be doing Develop and execute a transformatiomal third-party risk strategy that integrates cybersecurity, privacy, resiliency, financial, operational, contractual, reputational, and AI risks into enterprise goals. Design policies, standards, playbooks, and scalable processes to streamline third party intake, risk assessments, issues mananagement, offboarding and continuous monitoring and automated assurance of controls while reducing duplicative or low-value work. Incorporate AI and agentic systems and solutions into the TPRM lifecycle, including AI-use disclosure, AI-specific due diligence, data-use restrictions, model or system documentation review, human oversight expectations, output integrity, monitoring, incident response, and residual risk acceptance. Partner with the AI Governance Council, Legal, Privacy, Enterprise

Full responsibilities and requirements are on HealthEquity's application page.

Apply for this job →
About HealthEquity
Hiring for governance, risk, and compliance jobs on GRC Careers.
Search all HealthEquity jobs →

Location and market context

This is a remote third-party risk job, so it draws from a national talent pool rather than a single metro. Remote governance and compliance jobs reward candidates who can show they work effectively across time zones and distributed legal, security, and product teams. Confirm any residency, travel, or occasional-onsite expectations directly with HealthEquity.

About third-party risk jobs

Third-party and vendor risk teams assess and monitor the security, privacy, and compliance posture of suppliers, an area under sharp regulatory and operational focus as AI vendors proliferate. Jobs like this one are typically evaluated against frameworks such as third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices.

How to position yourself for this third-party risk job

Strong candidates emphasize vendor due diligence and assessment, ongoing monitoring, contract and control requirements, and coordinating across security, privacy, and procurement. In your resume and outreach, tie your experience to how HealthEquity would apply third-party risk frameworks, SOC 2, ISO/IEC 27001, and vendor due-diligence and monitoring practices, and lead with concrete outcomes rather than duties.

Similar GRC jobs

Counsel - Third Party Risk Management
Everest Re Group
London, UK
Central Outsourcing Control Office (COCO)
Morgan Stanley
Frankfurt, Germany
Cybersecurity and Third-Party Risk Manager
Lord Abbett
Jersey City, NJ$95k to $110k
Risk Business Partner - Third Party Risk Management
FNZ
Edinburgh, UK
Assistant Chief Supply Chain Officer - ACSCO
Veterans Health Administration
Indianapolis, Indiana$107k to $140k
Third Party Oversight Coordinator
U.S. Coast Guard
Staten Island, New York$125k to $163k
Get more jobs like this by email
We will email you new GRC jobs in Remote as they post. Free and confidential, one click to unsubscribe.

Know your GRC? Take the 2-minute AI Governance Challenge. No signup needed.
Play now →

More GRC jobs: All GRC jobs · Search by category & location · All CISO & security-leadership jobs · CISO career guide