Third-Party Risk Management Program Officer
Heritage Bank
Third-Party Risk Management Program Officer
Heritage Bank has an exciting opportunity to join our organization!
We are seeking a Third-Party Risk Management Program Officer to join our Risk and Compliance team. The third-party risk management program officer is responsible for the design, execution, and continuous improvement of the bank's third-party risk management program across the full vendor lifecycle, from onboarding through offboarding. Operating within the Second Line of Defense (2LoD), this role provides governance and oversight to ensure operational alignment of the bank's TPRM processes across Information Security, Legal, Procurement, Business Units, and Internal Audit.
This position is accountable for ensuring third-party risks, including cybersecurity, operational, compliance, reputational, and concentration risks, are appropriately identified, assessed, and monitored in alignment with regulatory expectations.
The geographical location for this position is Tacoma, WA, Seattle, WA, Spokane, WA, or Portland, OR.
Base Salary Range: $100,884.00 - $126,105.00 - $151,326.00 annual
The Role at a Glance:
- Leads and manages the Third-Party Risk Management (TPRM) Program, including development and continuous refinement of TPRM policies and procedures, risk tiering and segmentation models, risk rating methodologies, and vendor lifecycle control checkpoints.
- Ensures alignment of the TPRM program with enterprise risk management (ERM), information security, compliance, and legal frameworks.
- Oversees execution of inherent risk assessments, due diligence reviews, and control assessments across all third-party risk domains (cybersecurity, privacy, operational resilience, etc.).
- Ensures appropriate engagement of cross-functional subject matter experts (e.g., Information Security, Legal, Compliance) and that roles and responsibilities are clearly defined within established processes.
- Defines and maintains program tools, templates, escalation protocols, and residual risk acceptance processes.
- Integrates and aligns TPRM program with related programs (e.g., Vendor Management, procurement, Business Continuity Planning, Information Security Risk Assessments, Cloud Governance, AI/Model Risk).
- Establishes and tracks key risk indicators (KRIs).
- Provides executive-level reporting on third-party risk posture, program maturity, and systemic exposures (e.g., concentration risk, critical service dependency).
- Monitors and escalates open risk issues, overdue assessments, and policy exceptions.
- Serves as the primary contact for regulatory exams and internal/external audits related to third-party risk.
- Performs continuous monitoring of Critical and High risk third parties.
- Maintains audit-ready documentation, evidence of program execution, and continuous improvement roadmap.
- Monitors regulatory changes (e.g., OCC Bulletins, FFIEC updates, DORA, NYDFS, etc.) and updates program controls to align with evolving requirements.
Core Skills and Qualifications:
- Bachelor's degree in Business, Risk Management, Information Security or related field preferred.
- 5+ years of recent experience in a vendor risk management, third-party oversight, or enterprise risk program role within a financial services environment required.
- Proven experience leading the development, implementation, and ongoing management of an enterprise-scale third-party risk management program required.
- Professional certifications as Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or equivalent preferred.
- Equivalent combination of education, training, certifications, and/or relevant work experience may be considered.
- Provide an exceptional level of service for internal and external customers, with the ability to build and maintain positive, professional relationships, to successfully interact with and influence all levels of management and functional and cross-functional areas across the organization.
- Highly effective listening, verbal, written, and telephone etiquette business communication skills, including effective questioning strategies, negotiation and presentation skills to communicate security-related concepts in a variety of settings, to a broad range of technical and non-technical staff. Ability to read, write, speak, and understand English well.
- Risk based mindset and strong analytical and critical thinking skills, with the ability to independently assess risk decisions and constructively challenge assumptions and conclusions.
- Thorough knowledge and understanding of regulatory frameworks (e.g. FFIEC, GLBA, PCI-DSS, SOX, FFIEC, HIPAA etc.) and of NIST CSF, ISO 27001, COBIT, COSO and vendor risk management frameworks.
- Strong knowledge of information security assessment and auditing practices, including the ability to evaluate technical and business controls using established frameworks and methodologies, and to effectively interpret results from security tools and subject matter expert assessments.
- Thorough knowledge and understanding of related statutory banking compliance regulations issued by the FDIC, FinCEN, and Federal Reserve Board, with strong knowledge of privacy laws, such as GLBA and SOX.
- Strong project management, planning, organizational, time management, and follow-up skills, demonstrating a strong sense of urgency and ability to execute quickly, timely and efficiently; independently ensuring that priorities are set and commitments and deadlines are met with minimal direction and oversight.
- Unquestionable integrity in handling sensitive and confidential information required.
- Proficient and advanced use and understanding of MS Office products (Word, Excel, Outlook), with the ability to adapt to and learn new technologies quickly.
- Proficient use and understanding of third-party risk management software (ex. UpGuard, Tandem, Gartner, etc.).
Work Environment/Conditions:
- Climate controlled office environment.
- Work involves being able to concentrate on the matter at hand, under sometimes distracting work conditions, and frequent employee and customer contacts and interruptions during the day.
Physical Demands/Effort:
- Work may involve the constant use of computer screens, reading of reports, and sitting throughout the day.
- Ability to operate a computer keyboard, multi-line telephone, photocopier, scanner and facsimile which often requires dexterity of hands and fingers with repetitive wrist and hand motion.
- Typically sitting at a desk or table; intermittently standing, stooping, bending at the waist, walking, climbing, kneeling or crouching to file materials.
- Occasional lifting up to 20 lbs. (files, boxes, etc.).
At Heritage Bank, we work hard, but we also know how important it is to take time off to stay healthy, relax, and spend time doing what makes your heart happy!
As part of our team, you'll enjoy a total rewards package, which includes base salary based on the role, experience, and skill set, along with an exceptional benefits package (medical, dental, vision, life insurance, 401(k), community volunteer time), and generous time off policy. Full-time team members receive a minimum of 10 paid vacation days annually* and eight hours of paid sick leave per month*, while also enjoying 11 paid holidays each calendar year, and an annual float day. *pro-rated from start date and/or hours worked.
Heritage Bank is an Equal Opportunity Employer
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any other basis protected by applicable law.
- ...This program allows full-time seminary students (pursuing Master of Divinity (MDiv)) to be commissioned as a Navy Officer while completing theological studies at an accredited seminary or graduate school. You’ll receive on-the-job training under the direct supervision...SuggestedFull time
$100k - $130k
...project-specific Quality Control program within a designated... ...extension of the Quality Control Manager, you'll help ensure work complies... ...job may be performed in the office or on the jobsite and... ...authorized to bind the company to any third-party recruitment agreements....SuggestedContract workFor contractorsFor subcontractorWork at officeLocal area- ...seeking a Threat Oversight Officer to join our Compliance... ...of cybersecurity risk across the bank, while... ...the Cybersecurity Risk Management Framework, aligning to... ...and Cyber Security Program. Maintains and continuously... ...efforts, and cloud or third‑party onboarding. Leads and...SuggestedWork experience placement
- ...organization! We are seeking a Data Management Officer to join our team. The data management officer... ...of the Bank's data management program within the first line of defense 1(LoD)... ...KRI metrics. Identifies data-related risks, documents and reports to second line of...SuggestedHourly payFull timePart timeMonday to FridayFlexible hours
- ...treatment of inmates and guidance to lower-graded Correctional Officers. Incumbent is concerned with maintenance of institution security... ...to operations and procedures is provided by post orders, BOP program statements, local supplements, custodial manual, internal correspondence...SuggestedLocal areaRelocation packageFlexible hoursShift work
$1,000 per month
...Museum (TAM) seeks a dedicated Major Gifts Officer to join our Development team to help... ...Major Gifts Officer is responsible for managing TAM's development and stewardship... ...artworks through innovative interpretive and programming strategies. Named by USA Today as one of...- ...Tuition Reimbursement Reduced Tuition Rates Employee Assistance Program Pet Insurance Paid Training Farmers Auto Insurance Employee... ...in order before beginning a trip. Notifies the Transportation Manager if there are problems before initiating a trip. Ensures that...16 hoursPermanent employmentTemporary workImmediate startFlexible hoursShift workNight shift
- Job Highlights Title: Special Assets Officer III Type: Full Time Experience: 4-7 Years Function... ..., business banking/lending, and wealth management services. Job Profile The bank is hiring... ...Tuition reimbursement Virtual work program Employer’s Statement Umpqua Bank is an...Full timeWork experience placementBank staffFlexible hours
$27.33 - $32.66 per hour
...Specialist- Part-time Administration Office - Tacoma, WA 98402 Overview Salary... ...Continuing Education, Employee Assistant Program and more! We are looking for a Clinic... ...guidelines of the QI Team and the Clinic Manager. Included is the responsibility for monitoring...Hourly payDaily paidPart timeWork at officeFlexible hoursShift work$82.5k - $92.5k
...very little time spent in an office. This position is best suited... ...reimbursement ~ Employee referral program ~ Flexible scheduling;... ...One Another I ntelligent Risk Taking C elebration O... ...subsidiary that has its own management, employees and assets. More information...Work at officeFlexible hours- ...-35C Lightning II. AIRCRAFT HANDLING OFFICER - Every performance needs a choreographer... ...DUTY OFFICER - You’re in charge of managing the repair and upkeep of our most lethal... ...financial assistance and continuing education programs, including: Post-9/11 GI Bill Navy...Part time
$150k
...Position Summary: The Chief Advancement Officer for Goodwill of the Olympics & Rainier... ...awareness for our workforce development programs and services, driving customers to our thrift... ...functions of our Goodwill and manage a team of specialists in relevant supporting...Work at office- ...serves as front line contact for clients of the court and for program participants of the courts. Will do registration, intake, specimen... ...diploma or equivalent, good customer service skills, clerical office experience and excellent communication skills both orally and...Work at office
- ...Cook Officer GEO provides complementary, turnkey solutions for numerous government partners... ...the-art facilities and the provision of management services and evidence-based... ...areas. Ensures the sanitation and safety program is actively practiced in all areas of the...16 hoursPermanent employmentWork experience placementWorldwideFlexible hoursShift work
- ...Analyst IV / Medical Liaison to provide support to the Project Manager Soldier Medical Devices (PM SMD), Force Integration... ...optimal healthcare readiness. You will work closely with the Program Executive Office Soldier, Project Manager Soldier Medical Devices, and other...Full timePart timeWork at officeLocal areaWorldwide
$95.2k - $128.8k
...operations and processes to Quality Management System requirements,... ...coordinates with the responsible parties for internal/external... ...years of experience in Microsoft Office Suite (Excel, Word, Outlook,... ...enroll in a variety of benefit programs, generally including health insurance...Contract workWork at officeRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workAfternoon shift$82.89k - $119.29k
...career development to invest in you. Well-being and support Generous PTO, Code Lavender and Employee Assistance Programs to help you maintain balance and feel cared in your work and life. Living our values Respect, integrity,...Contract workLocal areaShift work$125.8k - $170.2k
...Reviews proposals, contracts, regulatory, program and customer requirements ensuring early... ..., developing coordinated responses for management review and approval. Conducts hardware,... ...years of experience using the Microsoft Office Application Suite such as Microsoft...Permanent employmentContract workWork at officeVisa sponsorshipWork visaRelocation packageDay shift$30 per hour
...area. Reporting to the Northwest Regional Manager, you will be given extensive and... ...full‑time employees. Our on‑site training program focuses on adult learning models and includes... ...comfortable with technology including MS Office IATA, IMDG, 49-CFR qualifications (not required...Hourly payPermanent employmentFull timeTemporary workMonday to FridayShift workWeekend workWeekday work$28.13 - $40.89 per hour
...fellowships and career development to invest in you. Well-being and support Generous PTO, Code Lavender and Employee Assistance Programs to help you maintain balance and feel cared in your work and life. Living our values Respect, integrity, kindness and...Daily paidContract workReliefLocal areaImmediate startShift work$81.5k - $112k
...maintain strong professional relationships with hospitals, physician offices, skilled nursing facilities, and other referral sources. Serve... .... Facilitate timely and seamless admissions into the hospice program. Promote the organization as a high-quality, compassionate...Full timeMonday to Friday- ...Analyst IV / Medical Liaison to provide support to the Project Manager Soldier Medical Devices (PM SMD), Force Integration... ...optimal healthcare readiness. You will work closely with the Program Executive Office Soldier, Project Manager Soldier Medical Devices, and other...Full timePart timeWork at officeLocal areaWorldwide
$41 - $67 per hour
...Applicants should possess a Clinical Licensure, a bachelor's degree, and ideally, have previous clinical and sales experience. The position offers competitive pay ranging from $41 to $67 hourly and various employee wellness programs. #J-18808-Ljbffr Lifepoint Health®Hourly pay$100k - $130k
...Company, located in Tacoma, WA, is seeking a Quality Control Specialist. This role involves supporting the execution of quality control programs across various engineering disciplines including Civil, Mechanical, Electrical, and Structural. Ideal candidates will possess a...$24 - $26 per hour
...be scanned and batched at the Branch. Manages all follow-up functions with the account,... ...and promotes company products/services at office visits, as appropriate. Proactively... ...fit your life. Our comprehensive benefits program is designed to meet you where you are through...Hourly payContract workWork at officeFlexible hoursNight shift- MultiCare is seeking a BHN Data & Onboarding Specialist in Tacoma, WA. This role involves overseeing licensing programs, coordinating employee onboarding, and ensuring regulatory compliance within the Behavioral Health Network. The ideal candidate has 3 to 5 years of relevant...
$329.6k - $376.8k
...psychosis, delirium). # Diagnose and manage delirium, including hypoactive and hyperactive... .... # Evaluate and manage suicide risk and other safety concerns in hospitalized... ...accredited medical school and residency program Licensure to practice medicine in Washington...Contract workLocal areaFlexible hoursShift work$41 - $67 per hour
...and benefits. Functions as initial contact for external case management and discharge planner personnel with payors and hospital facilities... ...Employee Well-being: Mental, physical, and financial wellness programs, free gym memberships, virtual care appointments, mental...Hourly payReliefImmediate start$41 - $67 per hour
...and benefits Functions as initial contact for external case management and discharge planner personnel with payors and hospital facilities... ...through comprehensive physical medicine and rehabilitation programs. Our rehabilitation programs provide ongoing care and...Hourly payRelief$28 - $32 per hour
...proactive coordination with Production, Warehouse, and Project Management teams. The ideal candidate demonstrates GRIT — the ability to... ...Safety Equipment Frontier Door and Cabinet’s Safety Program and all established safety rules must be followed, and equipment...Hourly payRemote workShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Third-Party Risk Management Program Officer. Be the first to apply!



