Risk & Compliance Engineer
WebMD - Newark, NJ
Hiring: Risk & Compliance Engineer Company: WebMD Location: Newark, NJ Job Posted Time: 2026-09-10 13:05:15 Employment Type: Full-time Target Skills & Keywords : HIPAA, Risk Management, SOC 2 About the job Experience: •6 years leading vendor and third-party risk assessments and managing identified risks to resolution. Security Assurance / Assessments experience is also acceptable Required Skills: •The ideal candidate demonstrates the ability to continuously identify & integrate AI to improve all aspects of the program, strong and practical GRC fundamentals and the judgment to prioritize real risk reduction over check-the-box control work. •Continuous improvement using AI into all aspects of vendor risk management •Lead and independently prioritize a range of vendor security risk assessments — scoped by service type and integration profile — to verify compliance with contracts and internal security policies and standards. •Coordinate vendor information risk activities across procurement, legal, and the business, including assessment criteria and re-assessments, with a focus on SOC 2-dependent vendors. •Partner with risk owners to design and negotiate risk treatment plans that prioritize genuine risk reduction over check-the-box control enhancements, and track them to closure. •Lead vendor risk reviews in bi-weekly management meetings to drive accountability for remediation. •Own risk reporting in OneTrust: ensure risk managers are tracking remediations, and develop and maintain KRIs and KPIs. •Build, maintain, and improve assessment methodology and questionnaires based on NIST 800-53r5 and the NIST RMF. Qualifications: •AI Proficiency aiming to improve accuracy and accelerate process improvement •4 –6 years leading vendor and third-party risk assessments and managing identified risks to resolution. Security Assurance / Assessments experience is also acceptable •Strong, practical command of risk and control concepts and GRC frameworks — NIST RMF, NIST 800-53r5, and related standards. •Applied hands-on capability in GRC / risk / compliance tooling (e.g., OneTrust, Archer). •Strong written and verbal communication and the organizational skills to manage competing deadlines with limited oversight. •Demonstrated capacity to work independently while fostering cross-functional collaboration, with a consistent customer-first mindset and solid business acumen. •Bachelor's or advanced degree in a Science, Engineering, Information Systems, or Cybersecurity field (preferred, not required). •Operational familiarity with AI/agentic systems and emerging AI governance frameworks (e.g., NIST AI RMF, ISO/IEC 42001) — helpful for assessing AI vendors, but not required. •Relevant certifications (e.g., CISA, CRISC, CISSP, CCSP). Compensation: •$82,000 - $97,000 / year Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!