Risk & Compliance Engineer

WebMD
Newark
Workplace: OnsiteFull timeUSD 82,000 - 97,000 annuallyFunction: Legal, Risk & ComplianceExperience: 4-6 yearsEducation: bachelorsSkills: ["Communication","Organizational skills","Judgment","Prioritization","Cross-functional collaboration"]

Own vendor security risk and compliance assessments end to end, using AI to improve accuracy, evaluate control effectiveness, and quantify business risk. Lead vendor risk reviews, coordinate with procurement and legal, and partner with risk owners on risk treatment plans to drive remediation to closure. Manage risk reporting in OneTrust, including KRIs/KPIs, and continuously improve assessment methodology and questionnaires based on NIST RMF and NIST 800-53r5. Support audits and embed security-by-design.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
WebMD
WebMD
2 months ago

Risk & Compliance Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Own vendor security risk and compliance assessments end to end, using AI to improve accuracy, evaluate control effectiveness, and quantify business risk. Lead vendor risk reviews, coordinate with procurement and legal, and partner with risk owners on risk treatment plans to drive remediation to closure. Manage risk reporting in OneTrust, including KRIs/KPIs, and continuously improve assessment methodology and questionnaires based on NIST RMF and NIST 800-53r5. Support audits and embed security-by-design.
Location: Newark
Workplace: Onsite
Employment Type: Full time
Job Function: Legal, Risk & Compliance
Seniority: Mid level

Key Responsibilities

  • •Continuously improve vendor risk management using AI across assessment and reporting.
  • •Lead and independently prioritize vendor security risk assessments scoped by service type and integration profile to verify contractual and internal policy compliance.
  • •Coordinate vendor information risk activities across procurement, legal, and business teams, with focus on SOC 2-dependent vendors.
  • •Partner with risk owners to design, negotiate, and track risk treatment plans to closure, prioritizing real risk reduction.
  • •Own risk reporting in OneTrust by ensuring remediation tracking and building/maintaining KRIs and KPIs.

Pay and Benefits

Salary: USD 82,000 - 97,000 annually
Perks:Health InsurancePaid Leave401kLife InsuranceDisability InsuranceEapCommuter Benefits

Key Requirements

  • •4–6 years leading vendor and third-party risk assessments (security, vendor, HIPAA) and managing risks to resolution.
  • •Strong command of risk/control concepts and GRC frameworks such as NIST RMF and NIST 800-53r5.
  • •Experience leading discussions with risk owners to develop, negotiate, and close out risk treatment plans.
  • •Hands-on experience with GRC/risk/compliance tooling such as OneTrust and Archer.
  • •Bachelor’s or advanced degree in a relevant field (Science, Engineering, Information Systems, or Cybersecurity) is preferred (not required).
Experience:4-6 yearsVendor riskThird-party riskGRCHealthcare
Education:Bachelor's
Skills:CommunicationOrganizational skillsJudgmentPrioritizationCross-functional collaboration
Certifications:CISACRISCCISSPCCSP
Tech Stack:AIOneTrustArcherNIST 800-53r5NIST RMFSOC 2HIPAAISO/IEC 42001NIST AI RMFKRIsKPIs

Company Brief

WebMD
Operates a leading online health information and health services platform offering medical news, symptom checkers, drug information, and physician directory services to consumers and healthcare professionals.
Industry: HealthTech
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: New York, United States
Founded: 1996
WebsiteLinkedIn