Lead Director - Third Party Security, Assessment Operations
$144.2k - $288.4kHispanic Alliance for Career Enhancement
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time. Position Summary The Lead Director of Third-Party Security Assessment & Risk Operations plays a critical role in protecting the organization by ensuring that third parties (vendors, suppliers, and partners) meet the security standards required to operate in a highly regulated environment. This role leads the end-to-end lifecycle of third-party security assessments, ensuring that risks are identified early, understood clearly, and addressed effectively. By building and advancing a scalable, risk-based assessment program, this position helps safeguard the enterprise while enabling the business to move forward with confidence in its external partnerships. This leader partners closely with Procurement, Legal, Compliance, and business units to embed security into the full vendor lifecycle and translate complex cyber risks into clear, actionable guidance. The role also shapes enterprise-wide risk and control assurance efforts by bringing visibility, consistency, and accountability to third-party risk management. Through strong program leadership, executive engagement, and continuous improvement, the Lead Director ensures the organization can manage third-party risk at scale while supporting growth, regulatory compliance, and operational resilience. Key Responsibilities Third Party Security Leadership Own and continuously mature the enterprise Third Party Security program, including processes, and tooling. Direct staff in the identification, development, implementation, and maintenance of security assessment practices for all third parties - including vendors, suppliers, and business partners. Establish demand-driven resource models and align team capacity to portfolio volume and organizational priorities. Build, coach, and lead a high-performing team of security professionals spanning Individual Contributors, Managers, and Senior Managers. Risk Assessment & Control Assurance Lead the evaluation and assessment of emerging cyber threats, vulnerabilities, and attack vectors relevant to third party ecosystems. Direct detailed control testing, regulatory audit scenarios, and compliance validation activities for third party relationships. Develop and enforce risk-based remediation strategies derived from assessment findings and lessons learned. Implement and enforce security controls within third parties supporting large, complex, and diverse enterprise environments. Regulatory Compliance & Policy Alignment Ensure organizational adherence to applicable local, national, and international regulatory requirements (e.g., HIPAA, PCI-DSS, NIST, ISO 27001/27036, SOC 2) within the scope of third party security. Provide authoritative security guidance to project teams, portfolio personnel, and business leaders to ensure alignment with CVS Health control standards. Monitor evolving regulatory and industry landscapes and proactively adjust program requirements to maintain compliance. Executive Stakeholder Engagement Serve as a trusted advisor to senior business and technology executives on third party cyber security matters. Communicate risk posture, program performance metrics, and remediation status to executive leadership through compelling, data-driven presentations. Act as the primary point of enablement for Third Party Security Assessment Operations across the organization. Develop and sustain strategic relationships across functional business, IT, and vendor leadership teams. Operational Excellence & Continuous Improvement Establish organizational capabilities to track program progress, surface issues, and remove obstacles in alignment with the CVS Health mission. Define and monitor KPIs and KRIs to measure program effectiveness and drive continuous improvement. Identify and implement technology solutions and automation opportunities to scale assessment operations. Required Qualifications 10+ years of progressive Information Security experience, with a strong foundation across risk management, architecture, and engineering domains. 7+ years of direct leadership experience managing security professionals in both direct and matrixed reporting structures. 5+ years of experience building and leading Third Party Security Risk or Vendor Risk Management programs at enterprise scale. 5+ years of experience leading detailed control testing, regulatory audits, and compliance assessments. 3+ years of experience implementing security controls within third party environments supporting large, complex enterprises. Preferred Qualifications Exceptional communication and executive presentation skills; ability to translate technical risk into business language for non-technical audiences. Strong command of risk analysis frameworks and the ability to derive well-defined mitigation strategies from assessment findings. Demonstrated ability to lead and influence without direct authority across cross-functional, matrixed organizations. Superior organizational and process management skills; experience building and scaling high-performing teams. Proficiency with Third Party Risk platforms (e.g., Archer, SecurityScorecard, ServiceNow, BlackKite) and GRC tooling. Integration and adoption of AI-based tooling to facilitate time to market and defensible results Education Bachelor's degree or equivalent experience (High School Diploma and 4 years relevant experience) Pay Range The typical pay range for this role is: $144,200.00 - $288,400.00. This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program. Benefits We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families. This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility. Additional details about available benefits are provided during the application process and on Benefits Moments. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws. We anticipate the application window for this opening will close on: 07/06/2026. #J-18808-Ljbffr Hispanic Alliance for Career Enhancement
$144.2k - $288.4k
...helping to simplify health care one person, one family and one community at a time. Position Summary The Lead Director of Third-Party Security Assessment & Risk Operations plays a critical role in protecting the organization by ensuring that third parties (vendors,...OperationsHourly payFull timeTemporary workLocal area- Hispanic Alliance for Career Enhancement is seeking a Lead Director of Third-Party Security Assessment & Risk Operations to oversee and ensure third parties meet security standards. This critical role involves collaboration with various departments to privilege clear risk...Operations
$144.2k - $288.4k
CVS Health is looking for a Lead Director of Third-Party Security Assessment & Risk Operations located in New Jersey. This role is vital for safeguarding the company by ensuring third parties adhere to security standards. The ideal candidate will lead and mature the Third...Operations$144.2k - $288.4k
Hispanic Alliance for Career Enhancement is looking for a Lead Director of Third-Party Security Assessment & Risk Operations. This key role focuses on ensuring that third-party partners meet required security standards. You'll lead assessments, manage risks, and collaborate...Operations- The Hispanic Alliance for Career Enhancement is seeking a Lead Director of Third-Party Security Assessment & Risk Operations. This role is crucial in ensuring that third parties meet the security standards necessary in a regulated environment. You will lead the lifecycle...OperationsFull time
- Stryker Corporation is seeking a Lead Director of Third-Party Security Assessment & Risk Operations. This role involves overseeing the security standards for vendors and partners, ensuring adherence to compliance regulations, and leading a team of security professionals...OperationsFull time
$114.1k - $268.18k
...class training facility, and leading market tools, we help our... ...seeking a Lead Specialist, Third Party Risk Management to join our... ...performing vendor or third-party security assessments, and perform remote... ...Security; Communications and Operations Management; Access Control;...OperationsFull timeLocal areaRemote work- CVS Health is seeking a Lead Director of Third-Party Security Assessment & Risk Operations. This role is crucial for ensuring that all third parties meet the required security standards. Responsibilities include leading the third-party security program and collaborating...Operations
$240k - $300k
A leading real estate services firm is seeking a Senior Director to oversee portfolio transitions and operations. This full-time position in New York offers a salary range of $240,000... ...commercial acumen and experience in a third-party environment, along with the ability...OperationsFull time- Radar Labs, Inc. is seeking a Senior GRC Analyst to enhance their security and compliance programs with a focus on third-party risk. This role involves collaborating with multiple teams, evaluating modern SaaS and AI tools, and improving risk management workflows. The...Flexible hours
- ...bring greater capital and operational efficiency to digital... ...'s offering is Multi-Party Computation (MPC)... ...the gold standard in secure custody. Copper’s multi... ...addition to industry‑leading security certifications... ...and inclusion. Talent Assessment: Conduct thorough screening...OperationsWork at officeLocal areaFlexible hours
- ...Cybersecurity Assessor to join our Third-Party Assurance team within our... ...offers the opportunity to assess the security of JPMC’s Third-Party... ...resilience, recoverability, and operational/data risks associated with... ...& Controls and Risk Pillar leads to raise awareness and...OperationsWorldwide
- ...portfolio and those of third parties, with a focus on... ...Legal Compliance Team Lead to oversee regulatory... ...related to corporate operations, contract governance,... ...thorough compliance risk assessments and spearhead effective... ...U.S. real estate law, secured transactions, and issues...OperationsContract workTemporary workWork at officeLocal areaRemote workWork from homeMonday to Friday
- ...alignment across Engineering, Security, Legal, Privacy, and... .... TPM establishes and operates the governance... ...manage dependencies, assess risks, and coordinate... ...transit paths. Coordinate third-party vendor security assessments... ...validation. Leading Clean Rooms program execution...Operations
- ..., and Change Management Team Lead is responsible for overseeing security incident/threat operations and enterprise change management... ...08). Coordinate breach risk assessments and documentation to support... ...management to coordinate third‑party incident handling and ensure...OperationsLocal areaRemote work
$75k - $90k
...management, executive protection, security operations, or business resiliency,... ...advisory services, risk assessments, physical protection,... ...contact for plan vendors and third-party administrators. Coordinate... ...related to benefits programs. Lead or support cross-functional...OperationsContract workTemporary workCurrently hiringWork at officeImmediate startRemote workVisa sponsorshipFlexible hoursShift work- ...cancer. What you’ll be doing The Director, Medical Capabilities Lead will be responsible for leading the... ...in building processes, systems, and operational efficiencies in support the Medical... ...medical affairs team; conduct ongoing assessments to identify gaps and opportunities...OperationsFull timeLocal area
$214.9k - $358.1k
...Pfizer Patient Services (PPS) Affordability Lead is responsible for leading a team... ...patients (e.g., accumulators/maximizers). Assess and develop patient affordability programs... ...vendor relationships to execute copay program operations and auxiliary tactics to ensure program...OperationsPermanent employmentH1bVisa sponsorshipWork visaRelocation package2 days per week3 days per week$214.9k - $358.1k
...Pfizer Patient Services (PPS) Affordability Lead is responsible for leading a team... ...as, enterprise-wide oversight of program operational compliance. This leader will:Lead the continued... ...patients (e.g., accumulators/ maximizers)Assess and develop patient affordability...OperationsPermanent employmentH1bLocal areaRelocationVisa sponsorshipWork visaRelocation package2 days per week3 days per week- ...Lead Technical Program Manager Leverage your deep technical... ...contribute to the development of operational plans and risk management... ...payments platforms. Identify, assess, and mitigate project risks... ...across banking, markets, securities services and payments. Corporations...Operations
- ...Transfers Key Technology: Source to Contract, Third Party Risk Management, Data Science and... .../supervision on their landscape/needs assessments while actively discouraging the growth... ...not fit into the wider T&D landscape. Operate & reduce 45 apps to 19 Skills and Experience...OperationsContract work
$150k - $200k
Augustus is seeking an experienced Third-Party Risk Manager to own TPRM at the company, from assessing and building the program to ongoing risk management and escalation. This role requires strong independent decision-making skills and a proactive approach to vendor relationships...$123.6k - $185.4k
Stripe is seeking a Program Manager for Third Party Risk in New York City. This role involves maintaining and enhancing the third party... ...framework to protect the company while collaborating on risk assessments and compliance activities. Candidates should have a minimum...$150k - $175k
A leading global alternative investment firm in New York is seeking a seasoned candidate for the Third-Party Risk Management Team. The role involves managing the TPRM platform and conducting vendor risk assessments. Candidates should hold a Bachelor's degree and have over...$172k - $236.5k
...autoimmune diseases. The Associate Director Ethics & Compliance (E&C), Risk Assessment and Monitoring is a key member of our E&C team who supports our operations and is based in Boston (US) or... ...Quality, Finance and those of third-party partners. Ensure timely, high-quality...OperationsTemporary work$138k - $190.3k
...it FanDuel is seeking a Lead Product Manager to drive the... ...capabilities across marketing operations. In this role, you'll own... ...performance management, and third-party integration oversight ~ Experience... ...with operating model assessments, RACI matrix design, or organization...OperationsContract workTemporary workLocal areaWorldwide$144k - $198k
...consists of a portfolio of leading brands across mobile... ..., FanDuel Group operates FanDuel TV, its broadly... ...on it The New Ventures Director position is a highly strategic... ...Ventures to identify, assess, and prioritize... ...Flutter and external 3rd parties, across the...OperationsTemporary workLocal areaWorldwide- ...corporate and government security teams identify threats, assess risk, and respond faster... ...Platform unifies security operations and data into a centralized... ...highly respected Senior Director, GSOC Practice Leader to... ...management. Direct experience leading or transforming a GSOC...OperationsTemporary workRemote workHome officeFlexible hoursShift work
$135k - $175k
...adeptly close top talent and help us scale our operations. This role is for someone who thrives in... ...Achieve: Executive & Critical Searches: Lead the end-to-end recruitment lifecycle for... ...the ability to effectively source and assess candidates for a variety of roles....OperationsWork at office$110k - $130k
...The Associate Media Director, Programmatic has a core responsibility... ...opportunities and pitches Lead media collaboration with... ...to directing trading and ad operations teams as needed Media Planning... ...the Integrated Media Team and third-party media agencies to: # Ensure...OperationsFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Lead Director - Third Party Security, Assessment Operations. Be the first to apply!
- physical security manager Brooklyn, NY
- surveillance manager Brooklyn, NY
- corporate security manager Brooklyn, NY
- program manager with security clearance Brooklyn, NY
- director information security Brooklyn, NY
- security operations manager Brooklyn, NY
- security systems manager Brooklyn, NY
- security manager Brooklyn, NY
- senior vice president of operations Brooklyn, NY
- deposit operations Brooklyn, NY


