Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Third-Party Risk Management Program Officer

Heritage Bank

Third-Party Risk Management Program Officer

Heritage Bank has an exciting opportunity to join our organization!

We are seeking a Third-Party Risk Management Program Officer to join our Risk and Compliance team. The third-party risk management program officer is responsible for the design, execution, and continuous improvement of the bank's third-party risk management program across the full vendor lifecycle, from onboarding through offboarding. Operating within the Second Line of Defense (2LoD), this role provides governance and oversight to ensure operational alignment of the bank's TPRM processes across Information Security, Legal, Procurement, Business Units, and Internal Audit.

This position is accountable for ensuring third-party risks, including cybersecurity, operational, compliance, reputational, and concentration risks, are appropriately identified, assessed, and monitored in alignment with regulatory expectations.

The geographical location for this position is Tacoma, WA, Seattle, WA, Spokane, WA, or Portland, OR.

Base Salary Range: $100,884.00 - $126,105.00 - $151,326.00 annual

The Role at a Glance:

  • Leads and manages the Third-Party Risk Management (TPRM) Program, including development and continuous refinement of TPRM policies and procedures, risk tiering and segmentation models, risk rating methodologies, and vendor lifecycle control checkpoints.
  • Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks.
  • Oversees execution of inherent risk assessments, due diligence reviews, and control assessments across all third-party risk domains (cybersecurity, privacy, operational resilience, etc.).
  • Ensures appropriate engagement of cross-functional subject matter experts (e.g., Information Security, Legal, Compliance) and that roles and responsibilities are clearly defined within established processes.
  • Defines and maintains program tools, templates, escalation protocols, and residual risk acceptance processes.
  • Integrates and aligns TPRM program with related programs (e.g., Vendor Management, procurement, Business Continuity Planning, Information Security Risk Assessments, Cloud Governance, AI/Model Risk).
  • Establishes and tracks key risk indicators (KRIs).
  • Provides executive-level reporting on third-party risk posture, program maturity, and systemic exposures (e.g., concentration risk, critical service dependency).
  • Monitors and escalates open risk issues, overdue assessments, and policy exceptions.
  • Serves as the primary contact for regulatory exams and internal/external audits related to third-party risk.
  • Performs continuous monitoring of Critical and High risk third parties.
  • Maintains audit-ready documentation, evidence of program execution, and continuous improvement roadmap.
  • Monitors regulatory changes (e.g., OCC Bulletins, FFIEC updates, DORA, NYDFS, etc.) and updates program controls to align with evolving requirements.

Core Skills and Qualifications:

  • Bachelor's degree in Business, Risk Management, Information Security or related field preferred.
  • 5+ years of recent experience in a vendor risk management, third-party oversight, or enterprise risk program role within a financial services environment required.
  • Proven experience leading the development, implementation, and ongoing management of an enterprise-scale third-party risk management program required.
  • Professional certifications as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or equivalent preferred.
  • Equivalent combination of education, training, certifications, and/or relevant work experience may be considered.
  • Provide an exceptional level of service for internal and external customers, with the ability to build and maintain positive, professional relationships, to successfully interact with and influence all levels of management and functional and cross-functional areas across the organization.
  • Highly effective listening, verbal, written, and telephone etiquette business communication skills, including effective questioning strategies, negotiation and presentation skills to communicate security-related concepts in a variety of settings, to a broad range of technical and non-technical staff. Ability to read, write, speak, and understand English well.
  • Risk based mindset and strong analytical and critical thinking skills, with the ability to independently assess risk decisions and constructively challenge assumptions and conclusions.
  • Thorough knowledge and understanding of regulatory frameworks (e.g. FFIEC, GLBA, PCI-DSS, SOX, FFIEC, HIPAA etc.) and of NIST CSF, ISO 27001, COBIT, COSO and vendor risk management frameworks.
  • Strong knowledge of information security assessment and auditing practices, including the ability to evaluate technical and business controls using established frameworks and methodologies, and to effectively interpret results from security tools and subject matter expert assessments.
  • Thorough knowledge and understanding of related statutory banking compliance regulations issued by the FDIC, FinCEN, and Federal Reserve Board, with strong knowledge of privacy laws, such as GLBA and SOX.
  • Strong project management, planning, organizational, time management, and follow-up skills, demonstrating a strong sense of urgency and ability to execute quickly, timely and efficiently; independently ensuring that priorities are set and commitments and deadlines are met with minimal direction and oversight.
  • Unquestionable integrity in handling sensitive and confidential information required.
  • Proficient and advanced use and understanding of MS Office products (Word, Excel, Outlook), with the ability to adapt to and learn new technologies quickly.
  • Proficient use and understanding of third-party risk management software (ex. UpGuard, Tandem, Gartner, etc.).

Work Environment/Conditions:

  • Climate controlled office environment.
  • Work involves being able to concentrate on the matter at hand, under sometimes distracting work conditions, and frequent employee and customer contacts and interruptions during the day.

Physical Demands/Effort:

  • Work may involve the constant use of computer screens, reading of reports, and sitting throughout the day.
  • Ability to operate a computer keyboard, multi-line telephone, photocopier, scanner and facsimile which often requires dexterity of hands and fingers with repetitive wrist and hand motion.
  • Typically sitting at a desk or table; intermittently standing, stooping, bending at the waist, walking, climbing, kneeling or crouching to file materials.
  • Occasional lifting up to 20 lbs. (files, boxes, etc.).

At Heritage Bank, we work hard, but we also know how important it is to take time off to stay healthy, relax, and spend time doing what makes your heart happy!

As part of our team, you'll enjoy a total rewards package, which includes base salary based on the role, experience, and skill set, along with an exceptional benefits package (medical, dental, vision, life insurance, 401(k), community volunteer time), and generous time off policy. Full-time team members receive a minimum of 10 paid vacation days annually* and eight hours of paid sick leave per month*, while also enjoying 11 paid holidays each calendar year, and an annual float day. *pro-rated from start date and/or hours worked.

Heritage Bank is an Equal Opportunity Employer

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other basis protected by applicable law.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Third-Party Risk Management Program Officer in Hillsboro, OR vacancy
  •  ...guidance export compliance program — from ECCN classification and export license management to OFAC sanctions...  ...KYC) due diligence, and risk management. The ideal candidate...  ..., including restricted party screening, end‑use/end‑...  .... Conduct customer and third‑party due diligence,... 
    Suggested
    Live in
    Local area
    Remote work
    Shift work
    Day shift

    FormFactor Inc.

    Beaverton, OR
    2 days ago
  •  ...from talent agencies or third-party sources. Any resumes...  ...regulations, and develop and manage effective policies and...  ...activities, mitigate risks, and minimize costs....  ...of Trade Compliance programs. Review and...  ...Routine use of standard office equipment, prolonged periods... 
    Suggested
    Temporary work
    Work at office
    Local area
    Worldwide
    Flexible hours

    Biamp Systems

    Tigard, OR
    3 days ago
  • $60 per hour

    24 Seven Talent is seeking an Embedded Program Manager in the Portland area. This freelance position supports consultant operations and recruiter collaboration. Responsibilities include acting as an on‑site liaison, onboarding consultants, and maintaining client relationships... 
    Suggested
    Freelance

    24 Seven Talent

    Beaverton, OR
    5 days ago
  •  ...This position will support any third party billing staff in areas...  ...the direction of the Billing Manager. o Performing audits and analyses...  ...in developing education programs for providers around coding....  ...communication skills Microsoft office suite including Microsoft... 
    Suggested
    Seasonal work
    Work at office

    Virginia Garcia Memorial Health Center

    Hillsboro, OR
    5 days ago
  •  ...safety vendor approval program. Essential Position...  ...Act, as well as review third‑party audits such as SQF and...  ...document food safety risk analysis of vendor documentation...  ...Technical Compliance Manager with projects as...  ...Foods - Corporate offices 15570 SW Jenkins Rd Beaverton... 
    Suggested
    Full time

    Reser's Fine Foods, Inc.

    Beaverton, OR
    4 days ago
  • $57k - $87k

     ...candidate resides near KeyBank office (non-branch location),...  ...and mitigating risk in all aspects of the client...  ...with Relationship Managers, Credit partners and NSF...  ..., client and other 3rd party partners. Works to resolve...  ...including the BSA/AML program, USA Patriot ACT, OFAC... 
    Work experience placement
    Work at office
    Work from home
    Home office
    Flexible hours
    2 days per week

    KeyBank

    Beaverton, OR
    1 day ago
  •  ...Administrator: Tristin Burnett GENERAL DUTIES: Provide support to families by connecting with available resources and programs. Facilitate engagement in school activities to promote student achievement. REQUIRED QUALIFICATIONS: ~ High school... 
    Summer work
    Monday to Friday
    Flexible hours

    Hillsboro School District 1J

    Hillsboro, OR
    1 day ago
  • $36 - $40 per hour

     ...functional teams to analyze product and sourcing data, support trade programs, and help drive duty savings through effective use of Free...  ...~ Strong analytical and Excel skills ~ Ability to manage multiple priorities in a fast-paced environment ~ Strong attention... 
    Hourly pay
    Contract work
    Temporary work
    Work from home

    Aquent

    Beaverton, OR
    1 day ago
  •  ...medical equipment, we empower patients to manage their health from the comfort of home....  ...planning Provide in-service training and CEU programs as needed Represent the company at...  ..., Word, and Excel Operate standard office equipment (fax, copier, printer, phone, computer... 
    Work experience placement
    Work at office
    Local area
    Shift work

    Rotech Healthcare

    Beaverton, OR
    3 days ago
  •  ...medical equipment, we empower patients to manage their health from the comfort of home....  ...planning Provide in-service training and CEU programs as needed Represent the company at...  ..., Word, and Excel Operate standard office equipment (fax, copier, printer, phone, computer... 
    Work experience placement
    Work at office
    Local area
    Shift work

    Rotech Healthcare

    Beaverton, OR
    3 days ago
  • HSQE Compliance Officer - Health, Safety and Environmental Tampa, FL, USA Job Description...  ...U.S. flag vessels operated by OSG Ship Management, Inc. The incumbent will be expected to...  ...internal and external safety recognition programs and ensure vessel efforts, contributions... 
    Work at office
    Local area
    Long distance
    Night shift

    OSG Ship Management

    Beaverton, OR
    3 days ago
  • $22 - $23 per hour

    Multi Site Security Officer - Full Time - Hillsboro, OR **Must be...  ...from security officers to management! Make Us Apart Of Your Career...  ...Pay!! * Employee Assistance Program. * DailyPay Access Program!...  ...order to be aware of potential risks or incidents that may take... 
    Weekly pay
    Full time
    Local area
    Shift work
    Day shift

    Securitas Security Services

    Hillsboro, OR
    2 days ago
  •  ...support for various labeling programs/updates, changes to regulatory...  .... Supports audits by third parties (FDA, BSI, and Others) as required...  ...including experience with MS Office and working knowledge of...  ...Ability to work well with others, manage multiple projects... 

    Acumed

    Hillsboro, OR
    10 days ago
  • $100k - $115k

     ...relentless hunters, shooters, law enforcement officers, and military personnel. Regardless of...  ...an internal skills development program for all manufacturing team members A generous...  ...requirements. Prepares, tracks, and manages a wide range of contract documents (MRs,... 
    Contract work
    Work experience placement

    Leupold & Stevens, Inc.

    Beaverton, OR
    2 days ago
  • Aquent is seeking a Human Research Coordinator in Beaverton, OR, to support the NSRL Athlete Protection Program. This role involves ensuring ethical conduct in human subjects research and compliance with federal regulations. The ideal candidate will hold a Bachelor’s degree... 
    Work from home

    Aquent

    Beaverton, OR
    1 day ago
  •  ...embedded in the TransplantCARE Quality programs for nearly 15 years, and the management team decided to refill that...  ...workgroup based from the Hillsboro office that performs many internal and external...  ...the team who manipulates SRTR (risk adjusted) data into INTERLINK's... 
    Full time
    Part time
    Work at office

    INTERLINK COE Networks & Programs

    Hillsboro, OR
    4 days ago
  • $47.82k - $55.64k

     ...well as CFPB and FNMA guidelines Demonstrated effective time management skills and the ability to work independently or in a...  ...functions, products & services Intermediate knowledge of Microsoft Office Suite; advanced knowledge of Excel Certification/License :... 
    Work at office

    First Technology Federal Credit Union

    Hillsboro, OR
    7 hours ago
  •  ...Oregon, to support global trade compliance and supply chain efficiency. This hybrid role involves collaborating with internal teams to manage customs processes and documentation, optimizing Free Trade Agreement utilization, and contributing to operational improvements. The... 
    Contract work
    Work from home

    Aquent

    Beaverton, OR
    4 days ago
  •  ...Trade Specialist in Beaverton, OR. This role involves supporting Free Trade Optimization (FTO) and ensuring compliance across APLA by managing accurate product data, classifications, and Free Trade Agreements. The ideal candidate should have 25 years of experience in... 
    Remote work

    eTeam

    Beaverton, OR
    5 days ago
  •  ...regulations while collaborating with internal stakeholders to mitigate financial risks. Responsible for completing Currency Transaction Reports, investigating suspicious activities, and managing watch list alerts, the ideal candidate will have a background in finance or... 
    Contract work

    TEKsystems

    Beaverton, OR
    5 days ago
  • Aquent is looking for a Trade Specialist in Beaverton, Oregon. In this role, you will support global trade compliance and free trade optimization within a dynamic supply chain environment. You will analyze product sourcing data and assist with customs documentation, ensuring...

    Aquent

    Beaverton, OR
    2 days ago
  • Nike is seeking a Trade Specialist - APLA in Beaverton, OR, for a 1-year contract. This role focuses on supporting Free Trade Optimization (FTO) and customs compliance by ensuring accurate product data and effective use of Free Trade Agreements (FTAs). The ideal candidate...
    Contract work

    Nike

    Beaverton, OR
    4 days ago
  •  ...environment. The ideal candidate will have 2-5 years of trade compliance experience, strong analytical skills, and proficiency in Excel. Excellent communication and the ability to manage multiple priorities are essential for success in this role. #J-18808-Ljbffr Skill
    Contract work

    Skill

    Beaverton, OR
    4 days ago
  • BrickRed Systems is seeking a detail-oriented Trade Specialist in Beaverton, Oregon, to support Free Trade Optimization and Customs & Trade Compliance operations. This role involves analyzing trade data, ensuring compliance, and collaborating with internal teams to drive...

    BrickRed Systems

    Beaverton, OR
    5 days ago
  • inSync Staffing is seeking a Trade Specialist in Beaverton, OR to support Free Trade Optimization and customs compliance initiatives. This hybrid role involves customs documentation, product classification, and analysis for international trade operations. The ideal candidate...

    inSync Staffing

    Beaverton, OR
    5 days ago
  •  ...abuse (CSA Centre) as our new Principal Researcher and Evaluation Officer - Impact. This is a key role within the CSA Centre, central to...  ...and tools for gathering data and interpreting evidence, and managing multiple impact and evaluation projects simultaneously, ensuring... 
    Permanent employment
    Contract work
    Local area
    Immediate start
    Work from home
    Home office
    Flexible hours

    Guardian Jobs

    Beaverton, OR
    2 days ago
  •  ...reputable supply chain consulting firm in Beaverton, Oregon is looking for a Supply Planner 3. This mid-senior level role involves managing supply planning, collaborating with demand planning and manufacturing teams, and leveraging data insights for decision-making.... 
    Contract work

    ADN Group

    Beaverton, OR
    2 days ago
  •  ...and customs compliance. The role requires extensive experience in trade compliance and collaboration with cross-functional teams to manage product data and FTA opportunities. Candidates should have a Bachelor's degree in a related field and at least 25 years of... 

    Sunrise Systems

    Beaverton, OR
    5 days ago
  • $22.59 per hour

     ...Operations Associate in Beaverton, Oregon. In this role, you’ll manage onboarding processes and compliance documentation, ensuring a smooth...  ...You will also provide exceptional customer service and maintain office supplies and paperwork. The position offers a competitive hourly... 
    Hourly pay
    Work at office

    Aerotek

    Beaverton, OR
    5 days ago
  •  ...audits, supplier audits, and 3rd party certification audits....  ...and ISO 14001 requirements. Manage and coordinate Corrective and...  ...process improvements. Manage program documentation required for conformance...  .... Proficient at MS Office applications. Ability to work... 

    Jireh Semiconductor

    Hillsboro, OR
    10 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Third-Party Risk Management Program Officer. Be the first to apply!