Director, 3rd-Party Risk & AI Governance

HealthEquity

Draper (UT)

On-site

USD 151,500 - 200,500

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision
HSA contribution and match
Dependent care FSA match
Uncapped paid time off
Paid parental leave
401(k) match

Job summary

HealthEquity seeks a Director of 3rd Party Security Risk to lead our enterprise TPRM program in a remote US role. You will drive AI-aware risk governance, define tiered vendor procedures, and partner with Legal, Procurement, Security, Privacy, IT, and Engineering to reduce third-party risk while enabling business growth.

You will build metrics, KRIs/KPIs, and executive reporting for the board, regulators, and auditors, ensuring controls across cybersecurity, resiliency, and data protection are

Qualifications

  • Bachelor's Degree in Computer Science or Engineering, or a related technical field; substitution of technical work experience allowed.
  • 12+ years of combined experience in information security.
  • Prior supervisory experience.

Responsibilities

  • Develop and execute a transformational third-party risk strategy that integrates cybersecurity, privacy, resiliency, financial, operational, contractual, reputational, and AI risks into enterprise goals.
  • Design policies, standards, playbooks, and scalable processes to streamline third party intake, risk assessments, issues management, offboarding, and continuous monitoring and automated assurance of controls while reducing duplicative or low-value work.
  • Incorporate AI and agentic systems and solutions into the TPRM lifecycle, including AI-use disclosure, AI-specific due diligence, data-use restrictions, model or system documentation review, human oversight expectations, output integrity, monitoring, incident response, and residual risk acceptance.
  • Partner with the AI Governance Council, Legal, Privacy, Enterprise Risk, Data Governance, Procurement, and business owners to ensure third party‑sourced AI capabilities are reviewed, approved, monitored, and governed consistently with enterprise AI policies and standards.
  • Establish meaningful KRIs, KPIs, dashboards, and management routines that demonstrate whether the program is buying down third‑party risk, including coverage, assessment quality, remediation aging, contract control gaps, external risk posture, AI‑enabled vendor coverage, and unresolved risk acceptances.
  • Design and maintain tier‑based operating procedures that clearly articulate what is required for tiered third party, including required risk assessments, contract safeguards, monitoring cadence, remediation expectations, and escalation triggers.
  • Lead third party tiering and re‑tiering efforts using objective criteria such as criticality, data sensitivity, regulatory exposure, operational dependency, resiliency impact, replaceability, AI usage, and business materiality.
  • Identify and address risks proactively, engaging stakeholders to drive effective remediation efforts and ensuring ownership is assigned across Security, Procurement, Legal, IT, Engineering, Finance, Enterprise Risk, and business teams.
  • Prepare strategic updates of third‑party and AI‑enabled risk updates for executive leadership, auditors, regulators, and the board of directors.
  • Support Legal and Procurement as an infosec SME in collaboration with security relevant teams for negotiating and approving third‑party contracts.
  • Collaborate across teams to ensure third‑party risk management practices are integrated and aligned into procurement, contracting, technology governance, SaaS security, identity governance, business continuity, incident response, audit, and enterprise risk processes.
  • Lead creation, execution, and automation of security, privacy, resiliency, and AI‑specific assessments for third‑party partners.
  • Validate third‑party security controls and AI controls to ensure compliance with organizational policies, standards, regulatory requirements, contractual commitments, and recognized frameworks.
  • Track and report remediation progress overdue findings, exception trends, and unresolved residual risks, providing insights and clear accountability to stakeholders.
  • Facilitate risk acceptance processes and elevate critical issues, material vendor events, AI‑related risks, and control deficiencies to senior leaders as needed.
  • Reassess critical third‑party security and AI risks periodically, applying lessons learned, external risk signals, material changes, incidents, regulatory updates, and evolving practices.
  • Support audit inquiries, regulatory exams, client due diligence, and executive requests by maintaining defensible evidence of program design, control execution, decision records, metrics, and risk treatment.
  • Set team goals aligned with organizational priorities, coach team members toward strategic thought leadership, and foster continuous improvement, automation, accountability, and business‑oriented risk management.
  • Other third‑party leadership duties as assigned.

Skills

Strategic leadership
Cross-functional collaboration
Communication skills
Risk assessment
AI governance

Education

Bachelor's Degree in Computer Science or Engineering
12+ years information security
Supervisory experience

Job description

HealthEquity seeks a Director of 3rd Party Security Risk to lead our enterprise TPRM program in a remote US role. You will drive AI-aware risk governance, define tiered vendor procedures, and partner with Legal, Procurement, Security, Privacy, IT, and Engineering to reduce third-party risk while enabling business growth.

You will build metrics, KRIs/KPIs, and executive reporting for the board, regulators, and auditors, ensuring controls across cybersecurity, resiliency, and data protection are

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director of 3rd-Party Risk & AI Security
Director of 3rd-Party Risk & AI Security

HealthEquity • United States

On-site
USD 180,000 - 260,000
Remote Director of 3rd-Party Risk & AI Governance
Remote Director of 3rd-Party Risk & AI Governance

HealthEquity, Inc. • United States

Remote
USD 151,500 - 200,500
Medical benefits
Dental & vision
HSA match
+7
Director, 3rd Party Security Risk
Director, 3rd Party Security Risk

HealthEquity • United States

On-site
USD 180,000 - 260,000
Director, 3rd Party Security Risk
Director, 3rd Party Security Risk

HealthEquity, Inc. • United States

Remote
USD 151,500 - 200,500
Medical benefits
Dental & vision
HSA match
+7
Executive Director, Information Risk & Governance (Remote)
Executive Director, Information Risk & Governance (Remote)

Modernhealth • United States

On-site
USD 231,000 - 272,000
Medical/Dental/Vision Insurance
Generous Time Off
401k with match
+1
Remote Senior Director, Information Risk & Governance
Remote Senior Director, Information Risk & Governance

Modern Health • Northern (KY)

Hybrid
USD 208,000 - 272,000
Remote Head of Third-Party Risk & Procurement Orchestration
Remote Head of Third-Party Risk & Procurement Orchestration

Envestnet • Berwyn (PA)

Hybrid
USD 115,000 - 143,000
TPRM Lead: Cybersecurity Vendor Risk & AI Governance
TPRM Lead: Cybersecurity Vendor Risk & AI Governance

Relha LLC • Reston (VA)

Hybrid
USD 171,000 - 256,000
Remote Data Privacy & Responsible AI Leader
Remote Data Privacy & Responsible AI Leader

Accuray • Mountain View (CA)

Hybrid
USD 150,000 - 190,000
Senior TPRM Analyst: AI Security & Governance
Senior TPRM Analyst: AI Security & Governance

DoorDash • Austin (TX)

On-site
USD 132,000 - 195,000
401(k) match
Paid parental leave
Wellness benefits
+3