Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Detego Health Benefits

Third-Party Risk Management (TPRM) Lead

Career Insights for Risk Consultant

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Nebraska data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Risk Consultant helps clients to evaluate risk and recommends strategies to mitigate or offset risks that could result in financial losses for a company or organization. May analyze risk in investments, business operations or technology systems at a company. May provide risk management consulting for life insurance, health insurance or other types of insurance companies.

$74,550 / year median in Nebraska

-4% projected decline

Explore Career

Job Description

About the Role Detego Health is growing quickly, and the integrity of our third-party risk program has to grow with it. This role owns that program end to end. You are accountable not only for completing vendor assessments, but for the reliability of the record itself. At any moment, leadership, an auditor, or a client should be able to ask which vendors are assessed, what the risk recommendation was, what evidence supports it, and whether any remediation, exception, contract, or reassessment obligation remains open. The answer must hold up. If you are looking for a role where you close tickets and wait for direction, this is not it. If you want to own a program and be measured on whether it can be trusted, this role is built for you. What You Own The vendor risk register as the authoritative source of truth. Every assessment recorded as complete is substantiated by retained evidence, and reported status reconciles to that evidence at all times. The full vendor lifecycle, including intake and onboarding, risk tiering, assessment, remediation tracking, annual reassessment, material change review, contract renewal risk checks, and offboarding. The risk recommendation. You assess, document, and recommend risk acceptance, mitigation, rejection, or escalation, and you bring unresolved risk through the formal risk acceptance process. The evidence trail. Assessment conclusions, risk recommendations, exceptions, remediation, and approvals are documented as the work happens, not reconstructed afterward. Contract and regulatory risk coordination. You coordinate review of business associate agreements, data processing agreements, audit rights, subcontractor provisions, insurance requirements, security obligations, privacy obligations, and regulatory commitments. Reporting leadership can rely on. Monthly and quarterly views of KPIs, high and critical vendor risks, remediation status, exceptions, and reassessment activity reconcile to the register without adjustment. What You Will Do Conduct vendor risk assessments using recognized due diligence methods such as SIG Lite and CAIQ, and tier vendors by inherent and residual risk. Review SOC reports, security questionnaires, insurance certificates, penetration test summaries, privacy documentation, business continuity evidence, subcontractor information, and other due diligence artifacts to assess vendor risk. Communicate directly with vendors to obtain security, privacy, compliance, continuity, and insurance documentation, clarify control responses, and drive remediation to closure. Partner with Procurement, Finance, Legal, Information Systems, Operations, Privacy and Compliance, Security, and business owners so vendor engagements carry required terms, including BAAs and DPAs, before access or data sharing begins. Monitor contract expirations and control triggers, enforce documentation and response SLAs, and initiate reassessments on schedule. Maintain the risk scoring methodology and keep the vendor risk register current, complete, accurate, and audit ready. Track exceptions and bring them through formal risk acceptance with a clear owner, rationale, expiration, review cadence, and retained evidence. Ensure contractual risk requirements are incorporated into assessment activities and tracked through remediation when necessary. Prepare leadership reporting on vendor risk, high and critical findings, overdue assessments, remediation status, exception status, and reassessment performance. What Success Looks Like First 90 Days The current vendor population is validated against the vendor risk register and evidence repository. Gaps between recorded assessment status and supporting documentation are identified, prioritized, and actively remediated. A reconciliation routine is established to keep the register, evidence repository, and reporting aligned going forward. High and critical vendor risks are visible, assigned, and tracked with clear remediation or escalation paths. The reassessment schedule and lifecycle triggers are documented and operating. Within Six Months Any assessment marked complete can be evidenced on demand without reconstruction. Leadership reporting reconciles to the vendor risk register and evidence repository without manual adjustment. High and critical vendor risks have documented owners, remediation plans, due dates, and reporting visibility. Vendor reassessment schedules operate consistently and do not depend on ad hoc reminders. Exceptions and risk acceptances have documented approvals, owners, expiration dates, and review cadence. What We Are Looking For Five or more years in third party risk, vendor risk, IT risk, security risk, procurement risk, or GRC, preferably in healthcare, a TPA, health plan, or another regulated environment. Strong command of SOC 2, HIPAA, vendor due diligence, BAAs, DPAs, subcontractor risk, insurance evidence, and contractual risk obligations. Fluency in vendor due diligence frameworks and artifacts such as SIG Lite, CAIQ, SOC 1, SOC 2, security questionnaires, policies, penetration test summaries, and business continuity documentation. A track record of owning assessments, remediations, vendor obligations, risk registers, and evidence workflows with minimal oversight. Strong documentation discipline and ability to keep a defensible record while moving work forward. Working familiarity with GRC tooling and evidence workflows. Experience with Vanta, BitSight, SharePoint, Microsoft Forms, and Power Automate is a plus. CTPRP, CISA, CISSP, CRISC, or comparable certification strongly preferred. The Kind of Person Who Thrives Here You operate independently and move quickly, but you never trade speed for a record you cannot defend. You are comfortable being the person an auditor, client, vendor, or executive stakeholder speaks with about third-party risk. You treat the vendor risk register as a control, not a spreadsheet. You would rather surface a gap early than explain one later. You are direct with vendors, practical with business owners, and disciplined with evidence. Equal Opportunity Statement Detego Health is an Equal Opportunity Employer. We are committed to an inclusive workplace.
Job Type:
Full-time Pay:
$100,000.00 - $120,000.00 per year
Benefits:
401(k) 401(k) matching Dental insurance Employee assistance program Health insurance Health savings account Life insurance Paid time off Vision insurance
Work Location:
In person