Risk & Compliance Engineer
Quick Summary
WebMD is the most recognized and trusted brand of health information and the leading provider of health information services, serving consumers, physicians, healthcare professionals,
WebMD is the most recognized and trusted brand of health information and the leading provider of health information services, serving consumers, physicians, healthcare professionals, employers and health plans through our public and private online portals and WebMD the Magazine. The WebMD Health Network includes WebMD, Medscape, MedicineNet, eMedicine, RxList, theheart.org and Medscape Education. Our consumer portals and mobile health applications provide engaging, relevant and credible health and wellness information, personalized health assessment tools and access to online communities.
WebMD is an Equal Opportunity/Affirmative Action employer and does not discriminate on the basis of race, ancestry, color, religion, sex, gender, age, marital status, sexual orientation, gender identity, national origin, medical condition, disability, veterans status, or any other basis protected by law.
About the Role
~1 min read- Continuous improvement using AI into all aspects of vendor risk management
- Lead and independently prioritize a range of vendor security risk assessments — scoped by service type and integration profile (HIPAA, infrastructure, application, etc.) — to verify compliance with contracts and internal security policies and standards.
- Coordinate vendor information risk activities across procurement, legal, and the business, including assessment criteria and re-assessments, with a focus on SOC 2-dependent vendors.
- Partner with risk owners to design and negotiate risk treatment plans that prioritize genuine risk reduction over check-the-box control enhancements, and track them to closure.
- Lead vendor risk reviews in bi-weekly management meetings to drive accountability for remediation.
- Own risk reporting in OneTrust: ensure risk managers are tracking remediations, and develop and maintain KRIs and KPIs.
- Build, maintain, and improve assessment methodology and questionnaires based on NIST 800-53r5 and the NIST RMF.
- Embed security-by-design into projects and products to mitigate risk before it materializes.
- Support internal assessments and external audits.
- AI Proficiency aiming to improve accuracy and accelerate process improvement
- 4 –6 years leading vendor and third-party risk assessments (security, vendor, HIPAA, etc.) and managing identified risks to resolution. Security Assurance / Assessments experience is also acceptable
- Strong, practical command of risk and control concepts and GRC frameworks — NIST RMF, NIST 800-53r5, and related standards.
- Experience leading discussions with risk owners to develop, negotiate, and close out risk treatment plans.
- Hands-on experience with GRC / risk / compliance tooling (e.g., OneTrust, Archer).
- Experience building and maintaining organizational security risk metrics.
- Strong written and verbal communication and the organizational skills to manage competing deadlines with limited oversight.
- Ability to work independently while fostering cross-functional collaboration, with a consistent customer-first mindset and solid business acumen.
- Bachelor's or advanced degree in a Science, Engineering, Information Systems, or Cybersecurity field (preferred, not required).
Nice to Have
~1 min read- Familiarity with AI/agentic systems and emerging AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) — helpful for assessing AI vendors, but not required.
- Relevant certifications (e.g., CISA, CRISC, CISSP, CCSP).
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- July 10, 2026
- First seen
- September 26, 2026
- Last seen
- September 26, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 14%
- Scored at
- September 26, 2026
Signal breakdown
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.