Baylor Genetics Logo

Baylor Genetics

Sr Mgr Third Party Risk

Posted 25 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Leads and matures the enterprise third-party risk management program, including vendor intake, risk tiering, security assessments, monitoring, remediation, audits, and offboarding. Manages quarterly user access reviews and least-privilege controls while supporting HIPAA, GDPR, HITRUST, ISO 27001, ISO 27701, and ISO 42001 audit readiness. Partners with Security, Privacy, Compliance, Legal, Procurement, and application teams to report risk metrics and ensure vendor documentation and controls are maintained.
The summary above was generated by AI

JOB SUMMARY

Baylor Genetics is seeking a Manager, Third Party Risk to build, lead, and mature our enterprise Third-Party Risk Management (TPRM) program. As one of the nation’s leading clinical genetic testing laboratories, we entrust vendors and partners with highly sensitive data including Protected Health Information (PHI) and Sensitive Personal Information, this role ensures every third party that creates, receives, maintains, transmits, or accesses that data does so in compliance with HIPAA, GDPR, CLIA, CAPA, and other applicable regulatory requirements.

Reporting to the Director of Information Security, the Third Party Risk Manager owns the full vendor lifecycle intake, risk tiering, security and privacy assessment, onboarding, ongoing monitoring, and offboarding for both upstream and downstream vendors. This role also leads Baylor Genetics’ recurring User Access Review (UAR) program and drives audit readiness across ISO 27001, ISO 27701, ISO 42001, and HITRUST. Scope may evolve as organizational needs change.

KEY RESPONSIBILITIES

Third-Party / Vendor Risk Management

• Lead and continuously mature the enterprise Third-Party Risk Management program using a risk-based, lifecycle approach covering both upstream and downstream vendors.

• Own vendor intake and reassessment, inherent-risk scoring, risk-tier assignment, and lead security and cybersecurity reviews SOC 2, HITRUST, ISO 27001) for medium- and high-risk vendors.

• Establish a standardized vendor onboarding, continuous monitoring, and reassessment process leveraging the SIG questionnaire, and draft the SOPs, policies, and documentation that govern intake, assessment, and monitoring.

• Conduct internal and external vendor audits including “high-risk” upstream vendors with access to PHI, PII, and AI categorize vendors by criticality, and maintain a vendor risk heat map and single source of truth.

• Operate ongoing monitoring (annual reassessment for high-risk, biennial for medium-risk vendors), track remediation, and collaborate with cross departmental stakeholders to ensure BAAs/DPAs, DPIAs/TIAs, and sub-processor requirements are in place.

User Access Reviews & Governance

• Develop and manage the recurring (quarterly) User Access Review program across in-scope applications, including employees, contractors, temporary staff, and vendors, and extend coverage to administrator and privileged accounts.

• Enforce least-privilege access, collect attestations of completion, and produce evidence to support HIPAA, GDPR, IGTC, and other applicable audit requirements.

• Drive audit readiness and evidence collection across ISO 27001, ISO 27701, ISO 42001, and HITRUST, partnering with Privacy, Compliance, and Legal.

Reporting & Collaboration

• Produce regular reports, KPIs, and risk metrics for leadership on vendor risk posture, remediation status, and audit progress.

• Partner cross-functionally with Security, Privacy, Compliance, Procurement, and application teams; where vendors deliver software, review application-security evidence including static code analysis (e.g., SonarQube/SAST) results.

Other Duties:

• Contribute to a culture of integrity and service by putting the customer first, treating colleagues with respect, and conducting business with the highest standards of professionalism.

• Perform other job-related duties as assigned to support the team and business needs.

QUALIFICATIONS

Required

• Bachelor’s degree in Cybersecurity, Information Technology, Risk Management, or a related field or an equivalent combination of education and experience.

• Minimum of 6–8 years of experience in information security, risk, or compliance, including demonstrated experience creating and running upstream and downstream vendor management programs.

• Hands-on audit experience with ISO 27001, ISO 27701, and ISO 42001.

• Demonstrated HITRUST experience (assessment, readiness, and/or certification support).

• Experience developing and managing recurring User Access Review (UAR) programs and least-privilege access controls.

• Working knowledge of vendor risk assessment methodologies (e.g., SIG) and risk scoring/tiering.

• Strong understanding of HIPAA, GDPR, and security requirements for PHI and sensitive PII.

Preferred

• Relevant certifications such as CTPRP, CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor/Implementer.

• Experience with GRC platforms (e.g., TrustArc,) and vendor risk tooling.

• Prior experience in a healthcare, clinical laboratory, or other regulated (HIPAA/PHI) environment.

• People- or program-management experience leading assessments and coordinating cross-functional stakeholders.

COMPETENCIES

• Strong analytical and risk-based judgment with meticulous attention to detail.

• Excellent written and verbal communication; able to convey complex risk to technical and executive audiences.

• Program- and project-management skills, managing multiple concurrent assessments and deadlines.

• Collaborative influence across Security, Privacy, Compliance, Procurement, and business units.


PHYSICAL DEMANDS AND WORK ENVIRONMENT

• Remote with occasional travel to headquarters in Houston, Texas.

• Frequently required to sit and use hand and finger dexterity for prolonged periods.

• Occasional travel for meetings, vendor audits, or conferences.

EEO STATEMENT

Baylor Genetics is proud to be an equal opportunity employer committed to fostering an inclusive and diverse workplace. We welcome and encourage applicants from all backgrounds to apply. We do not discriminate on the basis of race, color, religion, national origin, sex, sexual orientation, gender identity, age, veteran status, disability, genetic information, pregnancy, childbirth, or any other status protected by applicable federal, state, or local law. If you need an accommodation during the application process, please contact our Human Resources team. 

Note to Recruiters:

We value building direct relationships with our candidates and prefer to manage our hiring process internally. While we occasionally partner with select recruitment agencies for specialized roles, we do not accept unsolicited resumes from recruiters or agencies without a written agreement executed by the authorized signatory for Baylor Genetics ("Agreement"). Any resumes submitted to Baylor Genetics in the absence of an Agreement executed by Baylor Genetics' authorized signatory will be considered the property of Baylor Genetics, and Baylor Genetics will not be obligated to pay any associated recruitment fees.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.

Similar Jobs

5 Hours Ago
Remote or Hybrid
45K-85K Annually
Junior
45K-85K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handle inbound calls and warm leads, assess customers’ insurance needs, recommend appropriate Property and Casualty coverages, and convert prospects into policyholders. Representatives receive paid training and licensing support, use provided computer equipment, and work remotely on a fixed schedule that includes one weekend day. The role requires strong communication, persuasion, organization, PC skills, and customer focus, with residence restricted to specified states.
Top Skills: PcWired High-Speed Internet
6 Hours Ago
Remote or Hybrid
130K-180K Annually
Senior level
130K-180K Annually
Senior level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
Leads corporate communications technology products and platforms, including intranet, CMS, email marketing, event management, and employee engagement solutions. Defines product strategy, roadmaps, backlogs, requirements, and success measures; partners with stakeholders, engineering teams, architects, and vendors to deliver scalable solutions. Oversees projects, budgets, risks, testing, deployment, governance, and operational readiness while providing technical guidance, resolving complex issues, and mentoring junior team members.
Top Skills: AgileCampaign Management ToolsCmsDigital Asset Management TechnologiesEmail Marketing PlatformsEmployee Engagement TechnologiesEvent Management PlatformsExcelInternet PlatformsIntranet PlatformsJIRAPowerPoint
7 Hours Ago
Remote or Hybrid
Pennsylvania, USA
19-34 Hourly
Senior level
19-34 Hourly
Senior level
Digital Media • Information Technology • News + Entertainment
Manages and grows Comcast Business’s existing mid-market and SMB customer accounts through telephone and digital sales, retention efforts, account reviews, solution-based selling, and problem resolution. The role focuses on meeting sales quotas, increasing revenue through advanced product upgrades and multi-product solutions, processing orders, preparing sales documentation, and coordinating with Sales Engineering and Customer Project Management. Requires flexible scheduling, including nights, weekends, and overtime.
Top Skills: Billing SystemsMicrosoft DynamicsMicrosoft Office SuiteMicrosoft OutlookMicrosoft TeamsSalesforceSd-Wan

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account