Responsible for managing and growing a comprehensive third-party risk management program across the organization.
Ensuring that Privia Health's information assets are safeguarded against cyber threats originating from third and fourth parties.
Leading the Third Party Access Committee (TPAC), driving compliance with regulations and implementing industry best practices for vendor risk management.
Privia Health is a technology-driven, national physician enablement company that collaborates with medical groups, health plans, and health systems to optimize physician practices, improve patient experiences, and reward doctors for delivering high-value care. The Privia Platform is led by top industry talent and exceptional physician leadership.
Support CapIntel’s Governance, Risk, and Compliance program
Manage third-party risk and customer security reviews
Support operational security, privacy, and security awareness initiatives
CapIntel is a software platform built for wealth management enterprises to help financial advisors explain complex investment strategies to their clients. Since launching in 2019, CapIntel has seen rapid adoption and industry recognition, earning top placements in Deloitte’s Technology Fast 50 Canada and Fast 500 North America in 2025, ranking us among the fastest -growing technology companies.
Support all stages of the third-party lifecycle, including vendor intake, onboarding, and risk assessments.
Assist in the implementation, enhancement, and administration of TPRM tools and risk management platforms.
Partner with other risk managers to support the development and use of a consistent risk taxonomy across risk domains.
New American Funding (NAF) is responsible for the governance and oversight of third-party risk. They assess the effectiveness of controls used to identify, monitor, and manage third-party risk throughout the third-party lifecycle.
Own and lead the end-to-end Security Supply Chain Risk Management program.
Perform detailed third-party security risk assessments aligned with industry frameworks.
Drive cross-functional alignment serving as the subject matter expert on external supply chain risk.
Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company built on trust, transparency, and creativity. They empower teams to design, launch, and optimize for the web without barriers and believe the future of the web, and work, is more open, more creative, and more equitable.
Lead and manage the Third Party Findings Management process across key risk impact categories.
Drive the optimization of the Due Diligence and Ongoing Monitoring risk assessment process across regulated and non-regulated Anchorage Digital legal entities.
Lead and manage the TPRM Quality Control process across regulated and non-regulated Anchorage Digital legal entities.
Anchorage Digital is building the world’s most advanced digital asset platform allowing institutions to participate in crypto. The company has over 600 employees and is funded by leading institutions including Andreessen Horowitz, GIC, Goldman Sachs, KKR, and Visa.
Mature and execute the enterprise risk management framework.
Lead day-to-day execution of Akoya’s cybersecurity program.
Oversee corporate IT governance in partnership with the IT Systems Administrator.
Akoya is building a secure API-driven open finance network. They value diverse experiences and encourage everyone to apply, especially those who will bring something new to the table.
Perform GRC functions and maintain the Cyber Security Risk register.
Execute third party risk processes for cyber and perform/execute on awareness programs and phishing processes.
Liaise with the vendor management (VM) team to conduct security assessments of existing and prospective vendors.
Warner Music Group is a global collective of music makers and music lovers, tech innovators and inspired entrepreneurs, game-changing creatives and passionate team members. They turn dreams into stardom and audiences into fans. WMG is committed to creating a work environment that actively values, appreciates, and respects everyone and encourages applications from people with a wide variety of backgrounds and experiences.
Execute end-to-end third-party and vendor risk assessments.
Develop, maintain, and enhance risk metrics, dashboards, and reporting.
Assist with additional GRC activities as needed, including policy management, risk assessments, control testing, and compliance initiatives
Aprio is a Top 20 CPA and advisory firm that accounts for anything. With over 3,200 team members and 40 U.S. office locations, plus international offices, they bring proven expertise and strategic foresight to fast-growing industries.
Lead and grow a team of the best security engineers.
Define the strategy for Vanta’s application security program.
Work with Engineering and Product Development to assess and mitigate risk.
Vanta helps businesses earn and prove trust by providing continuous security monitoring and verification. They aim to empower companies to practice better security with their automation and orchestration tools. Vanta has a kind and talented team, embracing individuals with and without prior security experience.
Responsible for comprehensive information security risk assessments of third-party vendors.
Evaluate vendors to ensure they meet internal information security policies, HIPAA, PCI DSS requirements, and applicable regulatory standards.
Thoughtfully analyze vendor-provided documentation, proactively identify potential risks, and produce detailed and accurate assessment reports.
Planned Parenthood is the nation’s leading provider and advocate of high-quality, affordable sexual and reproductive health care. They have health centers, programs in schools and communities, and online resources, and are a trusted source of reliable education and information.
Responsible for assessing, monitoring, and managing risks associated with global third-party relationships to ensure compliance.
Supports the Global Head of Third Party Risk by preparing regular metrics and other risk reports.
Facilitates issue escalation and risk acceptance processes to ensure appropriate stakeholders are involved.
Liberty Mutual is an insurance company. At Liberty Mutual, their goal is to create a workplace where everyone feels valued, supported, and can thrive; they achieve this through comprehensive benefits, workplace flexibility, and professional development opportunities.
Conduct structured interviews with partner organizations, operational teams, and technical stakeholders.
Documents end‑to‑end operational workflows and surface implicit, non‑documented practices.
Identify workflow fragility zones, handoff risks, and transition‑period vulnerabilities.
Element serves as a partner at the intersection of innovation and our clients' needs, efficiently crafting meaningful user experiences for government and commercial customers. Our talented professionals bring unparalleled energy engagement, setting a higher standard for impactful work.
Deploy AI into our GRC processes where appropriate
Smartsheet helps people and teams achieve their goals with seamless work management and scalable solutions. They empower teams to automate manual tasks, uncover insights, and scale smarter, fostering a culture where challenge meets purpose and passion turns into progress.
Support security and compliance programs aligned with frameworks such as NIST, ISO, PCI DSS, and HIPAA.
Assist in maintaining alignment with global privacy regulations (GDPR, CCPA, and similar frameworks).
Assist in the development, implementation, and maintenance of security, privacy, and AI governance policies, standards, and procedures.
Hims & Hers is a health and wellness platform with a mission to help the world feel great through the power of better health. They are redefining healthcare by putting the customer first and delivering access to care that is affordable, accessible, and personal.