Third-Party Risk Management Program Officer
Heritage-Bank
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process. Third-Party Risk Management Program Officer Regular Full-Time Compliance Hillsboro, OR, US 1 Attachments 6 days ago Requisition ID: 4447 Heritage Bank has an exciting opportunity to join our organization! We are seeking Third-Party Risk Management Program Officer to join our Risk and Compliance team. The third‑party risk management program officer is responsible for the design, execution, and continuous improvement of the bank's third‑party risk management program across the full vendor lifecycle, from onboarding through offboarding. Operating within the Second Line of Defense (2LoD), this role provides governance and oversight to ensure operational alignment of the bank's TPRM processes across Information Security, Legal, Procurement, Business Units, and Internal Audit. This position is accountable for ensuring third‑party risks, including cybersecurity, operational, compliance, reputational, and concentration risks, are appropriately identified, assessed, and monitored in alignment with regulatory expectations. The geographical location for this position is Tacoma, WA, Seattle, WA, Spokane, WA, or Portland, OR. Base Salary Range: $100,884.00 - $126,105.00 - $151,326.00 annual The Role at a Glance: Leads and manages the Third-Party Risk Management (TPRM) Program, including development and continuous refinement of TPRM policies and procedures, risk tiering and segmentation models, risk rating methodologies, and vendor lifecycle control checkpoints. Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks. Oversees execution of inherent risk assessments, due diligence reviews, and control assessments across all third-party risk domains (cybersecurity, privacy, operational resilience, etc.). Ensures appropriate engagement of cross-functional subject matter experts (e.g., Information Security, Legal, Compliance) and that roles and responsibilities are clearly defined within established processes. Defines and maintains program tools, templates, escalation protocols, and residual risk acceptance processes. Integrates and aligns TPRM program with related programs (e.g., Vendor Management, procurement, Business Continuity Planning, Information Security Risk Assessments, Cloud Governance, AI/Model Risk). Establishes and tracks key risk indicators (KRIs). Provides executive-level reporting on third-party risk posture, program maturity, and systemic exposures (e.g., concentration risk, critical service dependency). Monitors and escalates open risk issues, overdue assessments, and policy exceptions. Serves as the primary contact for regulatory exams and internal/external audits related to third-party risk. Performs continuous monitoring of Critical and High risk third parties. Maintains audit-ready documentation, evidence of program execution, and continuous improvement roadmap. Monitors regulatory changes (e.g., OCC Bulletins, FFIEC updates, DORA, NYDFS, etc.) and updates program controls to align with evolving requirements. Core Skills and Qualifications: Bachelor’s degree in Business, Risk Management, Information Security or related field preferred. 5+ years of recent experience in a vendor risk management, third-party oversight, or enterprise risk program role within a financial services environment required. Proven experience leading the development, implementation, and ongoing management of an enterprise-scale third-party risk management program required. Professional certifications as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or equivalent preferred. Equivalent combination of education, training, certifications, and/or relevant work experience may be considered. Provide an exceptional level of service for internal and external customers, with the ability to build and maintain positive, professional relationships, to successfully interact with and influence all levels of management and functional and cross-functional areas across the organization. Highly effective listening, verbal, written, and telephone etiquette business communication skills, including effective questioning strategies, negotiation and presentation skills to communicate security-related concepts in a variety of settings, to a broad range of technical and non-technical staff. Ability to read, write, speak, and understand English well. Strategic in approach to program design, problem solving, and decision-making, with demonstrated ability to quickly focus on key issues and make decisions under pressure of time constraints. Risk based mindset and strong analytical and critical thinking skills, with the ability to independently assess risk decisions and constructively challenge assumptions and conclusions. Thorough knowledge and understanding of regulatory frameworks (e.g. FFIEC, GLBA, PCI‑DSS, SOX, FFIEC, HIPAA etc.) and of NIST CSF, ISO 27001, COBIT, COSO and vendor risk management frameworks. Strong knowledge of information security assessment and auditing practices, including the ability to evaluate technical and business controls using established frameworks and methodologies, and to effectively interpret results from security tools and subject matter expert assessments. Thorough knowledge and understanding of related statutory banking compliance regulations issued by the FDIC, FinCEN, and Federal Reserve Board, with strong knowledge of privacy laws, such as GLBA and SOX. Strong project management, planning, organizational, time management, and follow-up skills, demonstrating a strong sense of urgency and ability to execute quickly, timely and efficiently; independently ensuring that priorities are set and commitments and deadlines are met with minimal direction and oversight. Unquestionable integrity in handling sensitive and confidential information required. Proficient and advanced use and understanding of MS Office products (Word, Excel, Outlook), with the ability to adapt to and learn new technologies quickly. Proficient use and understanding of third-party risk management software (ex. UpGuard, Tandem, Gartner, etc.). Work Environment/Conditions: Climate controlled office environment. Work involves being able to concentrate on the matter at hand, under sometimes distracting work conditions, and frequent employee and customer contacts and interruptions during the day. Physical Demands/Effort: Work may involve the constant use of computer screens, reading of reports, and sitting throughout the day. Ability to operate a computer keyboard, multi-line telephone, photocopier, scanner and facsimile which often requires dexterity of hands and fingers with repetitive wrist and hand motion. Typically sitting at a desk or table; intermittently standing, stooping, bending at the waist, walking, climbing, kneeling or crouching to file materials. Occasional lifting up to 20 lbs. (files, boxes, etc.). At Heritage Bank, we work hard, but we also know how important it is to take time off to stay healthy, relax, and spend time doing what makes your heart happy! As part of our team, you’ll enjoy a total rewards package, which includes base salary based on the role, experience, and skill set, along with an exceptional benefits package (medical, dental, vision, life insurance, 401(k), community volunteer time), and generous time off policy. Full-time team members receive a minimum of 10 paid vacation days annually and eight hours of paid sick leave per month, while also enjoying 11 paid holidays each calendar year, and an annual float day. The above statements are intended to describe the general nature and level of work being performed and are not an exclusive list of all qualifications for this position. The base salary range represents Heritage Bank’s current salary range for the position. Actual salaries will vary depending on factors including, but not limited to, qualifications, experience, and job performance. The range listed is just one component of Heritage Bank’s total compensation package for full time and part time employees. Depending on position, other total compensation rewards may include, monthly, quarterly or annual incentive, and/or bonuses. Heritage Bank is an Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other basis protected by applicable law. Job applicants have certain legal rights. Please click here for information regarding these rights. #J-18808-Ljbffr Heritage-Bank
- ...Procurement Analyst HMA is the premier third‑party health plan administrator... ...the end‑to‑end vendor management lifecycle, including RFP support... ...appropriate contracting, risk evaluation, and financial stewardship... .... Vendor Risk & Compliance Program Support Perform vendor risk...SuggestedContract workFlexible hours
$90k - $100.8k
...OVERVIEW Philanthropy Northwest is seeking a limited-term Program Officer to join our team and contribute to the successful execution... ...community-based organizations to facilitate their access to and management of federal grant funds. As a Program Officer, you will...SuggestedFull timeLong distanceFlexible hours- ...Chief Program Officer About the Company Charitable organization focused on bringing resources to developing countries Industry International... ...of shaping the future of AI in the developing world. Hiring Manager Title CEO Travel Percent Less than 10% Functions Non-Profit...SuggestedLocal area
- ...time OVERVIEW The Roots & Wings Foundation is looking for a Program Officer to help shape and grow our new foundation. This is a chance to... ...with the Executive Director to set funding strategy and manage our grants program. Other main duties include helping support...SuggestedFull timePart timeWork experience placementWork at office
- The Bill & Melinda Gates Foundation in Seattle is looking for a Senior Program Officer, Gynecology to lead initiatives that address heavy menstrual bleeding for women and girls in low middle-income countries. The role involves collaborating with private sector partners,...Suggested
$190.1k - $294.7k
...supporting other teams within U.S. Program in using data and AI to drive... ...Role As the Senior Program Officer, Portable Memory & Context ,... ...What You’ll Do Develop and manage a portfolio advancing the end‑... ...fragmentation poses systemic risk. Proven ability to translate...H1bLocal areaRelocation$100k - $120k
Wellspring Advisors, a private philanthropic organization, seeks a Program Officer to join its Civil Society Program (CS). CS seeks to help... ...Undertake initial screening of potential grantees; manage grantee relationships; analyze and assess background information...Local area$238.4k - $369.4k
...to and learn from these experts. We take risks in new areas, prove concepts, and bring... ...health R&D ecosystem. Your Role The Senior Program Officer, Gynecology (SPO) will lead a portfolio... ...align with WHI GYN strategy Closely manage a diverse portfolio of investments Work...$238.4k - $369.4k
Gates Foundation is seeking a Senior Program Officer for Gynecology based in Seattle. This role involves leading investments and partnerships aimed at developing solutions for women's health issues, particularly heavy menstrual bleeding. The ideal candidate will possess...$190.1k - $294.7k
The Bill & Melinda Gates Foundation is seeking a Senior Program Officer to lead investments in portable memory systems for AI in education and workforce. The role involves developing a comprehensive approach to a memory stack that connects learners and workers through data...- ...Unit Manager The Unit Manager performs a major role in the planning, development, administration and evaluation of a unit program for incarcerated federal offenders. Must have broad understanding of the field of criminology and corrections, must display management skills...
$110.66k
...communities. Responsibilities The Unit Manager performs a major role in the planning, development... ...administration and evaluation of a unit program for incarcerated federal offenders. Must... ...various correspondence with probation officers, attorneys, judges and other law...Hourly payWork at officeRelocationTrial period- ...Counsel individuals who seek guidance Oversee religious education programs, such as Sunday school and youth groups Visit and provide... ...Education Program while being paid full-time as a Navy Officer. Beyond professional credentials and certifications, Navy Chaplains...Full timePart time
- ...This program allows full-time seminary students (pursuing Master of Divinity (MDiv)) to be commissioned as a Navy Officer while completing theological studies at an accredited seminary or graduate school. You’ll receive on-the-job training under the direct supervision...Full time
- ...Chief Programs Officer (CPO) About the Company Mission-driven alliance of landowners committed to the health & prosperity of working... ...of leadership experience in conservation, natural resource management, public policy, or a related field. The ideal candidate will...
$47.05 - $73.04 per hour
Description The Program Manager, Foundation Liaison will serve as a patient advocate and a liaison between the Swedish Foundation Benefactor Delivery Program and Providence Swedish Medical Center. This newly developed role will be responsible for developing a comprehensive...Minimum wageFull timeLocal areaShift workNight shiftWeekend workAfternoon shift- The Program Manager, Foundation Liaison will serve as a patient advocate and a liaison between the Swedish Foundation Benefactor Delivery Program and Providence Swedish Medical Center. This newly developed role will be responsible for developing a comprehensive strategic...Night shiftWeekend workAfternoon shift
- A leading healthcare provider in Seattle is seeking a Program Manager, Foundation Liaison. This role involves patient advocacy, strategic planning, and the delivery of high-quality service to donors. The ideal candidate should have a Bachelor's degree and significant experience...
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We... ...practitioners who know how compliance and risk management actually work inside real organizations.... ...Familiarity with control testing or third-party risk assessments Why Join Us...Hourly payOngoing contractContract workFreelanceRemote workWorldwideFlexible hours
- Posted on December 20, 2023 The Roots & Wings Foundation is looking for a Hospital Partnerships Manager (aka Program Officer) to help shape our growing foundation. This position will help make a positive impact on the lives of many people living in under-resourced communities...
- ...Chief Brand Officer (CBO) About the Company Reputable political party advocating for social & economic justice issues Industry Political Organization Type Non... ...beloved by everyday working people. This includes managing a team of Department Directors, providing strategic...
- Governance, Risk, & Compliance (GRC) Analyst (Senior or Lead) Company: The Boeing Company... ...initiatives, ServiceNow IRM policy management, and control automation efforts to improve... ...prepare governance reporting, and communicate program status, priorities, and progress to...Permanent employmentWork experience placementRelocation packageFlexible hoursShift work
$35 per hour
...be employed as contract workers through a Boeing approved 3rd party for the duration of the specified project. Job Overview The Boeing... ...and processes to verify or validate compliance with Quality Management System requirements, applicable company procedures, contract requirements...Hourly payFull timeContract workWork experience placementShift workRotating shift- ...Administrative Services Associate Director. As the Quality/Compliance Program Coordinator this position will support the program and provide technical expertise in quality management, compliance and risk management. Utilizing technical expertise, analytical skills and...Local area
$57k - $87k
...resides near KeyBank office (non‑branch location),... ...servicing and mitigating risk in all aspects of the... ...with Relationship Managers, Credit partners and NSF... ...partners, client and other third‑party partners. Works to... ...including the BSA/AML program, USA Patriot Act, OFAC...Work experience placementWork at officeWork from homeHome officeFlexible hours2 days per week- ...HUD Project-Based Section 8 programs, along with strong analytical... ...communication skills. This is a home office-based role supporting onsite... ...Director and Compliance Manager. Communicate daily with... ...concern, and coordinate with third-party agencies on audit findings....Full timeInterim roleRemote workWork from homeHome office
$48.21 - $87.11 per hour
...nursing facility staff, physician office staff and the Home Care... ...communication between the EHCS management and referral sources. #... ...~ Graduate of a nursing program (Diploma or Associate Degree... ...Standards ~ Must be familiar with Third party insurance and Medicare HMO's....Hourly payLive inWork at officeFlexible hoursShift work$101.9k - $173.2k
...Blue Cross' Regulatory Compliance & Ethics program through focused advocacy, detailed regulatory... ...interest groups. Assist the business and third parties with the implementation of new and changing laws and regulations. Manage inquiries and exams from state and federal...Work experience placement- ...Small Business is seeking a Senior Information System Security Officer to oversee cybersecurity efforts for complex systems in... ...DC. This role requires 10+ years in the field, expertise in risk management frameworks, and the ability to obtain Top Secret/SCI clearance...
$87.9k - $146.5k
...without putting you at risk. As such, applications... ...to join our Privacy Office within the Enterprise... ...maturity of our privacy program and helps ensure that... ...with a team dedicated to managing privacy risks,... ...initiatives, AI tools and third-party vendor solutions, via...Remote jobFull timeWork at officeImmediate startWork from homeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third-Party Risk Management Program Officer. Be the first to apply!
- senior quantitative risk analyst Seattle, WA
- risk analyst Seattle, WA
- it risk analyst Seattle, WA
- operational risk consultant Seattle, WA
- risk officer Seattle, WA
- risk consultant Seattle, WA
- third party risk analyst Seattle, WA
- operational risk specialist Seattle, WA
- antepartum high risk ob nurse Seattle, WA
- technology risk Seattle, WA


