> Markdown version of [/jobs/ext/2638611-ai-vendor-governance-manager](https://www.wearedevelopers.com/jobs/ext/2638611-ai-vendor-governance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Vendor Governance Manager - **Company:** Omnicell, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Cyber Security, Machine Learning, Data Processing, Model Validation, Servicenow - **Published:** August 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=387479626bb4182d ## About the Role * 6+ years of experience in third-party or vendor risk management, IT or security risk, compliance, or a related governance function * Demonstrated experience building or substantially maturing a vendor risk or governance program, including intake and risk-tiering processes * Strong knowledge of third-party and vendor risk management principles and lifecycle, from intake and due diligence through monitoring and offboarding * Familiarity with AI and machine learning concepts and the risks they raise, including bias, transparency, data privacy, security, and model reliability * Working knowledge of AI governance frameworks and standards, such as the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act * Familiarity with security and privacy frameworks commonly used in vendor assessments, such as SOC 2, ISO 27001, HIPAA, and GDPR * A talent for designing clear, repeatable processes and operationalizing them across a cross-functional organization * The ability to assess complex risk and make pragmatic, risk-calibrated recommendations that balance innovation with protection of the business * A track record of partnering across Procurement, Legal, Privacy, Security, and business owners, with excellent stakeholder management skills * The ability to explain technical and risk concepts clearly to both technical and non-technical audiences * The ability to operate independently in a fast-moving environment, manage competing priorities, and stay highly organized, with sharp attention to detail and a commitment to thorough documentation Preferred Qualifications * Bachelor's degree, or equivalent practical experience * Experience assessing AI or machine learning solutions, or building AI-specific risk controls * Healthcare, life sciences, or other regulated-industry experience * Relevant certifications, such as AIGP, CIPP, CIPM, CTPRP, CRISC, CISA, or CISSP * Experience with third-party risk, GRC, or AI governance tooling, such as ServiceNow, OneTrust, or similar platforms * Familiarity with AI assurance artifacts, such as model cards, system cards, and impact assessments, and with vendor monitoring tools * Relevant advanced education, such as a degree or coursework in law, risk management, information security, data science, or a related field, or equivalent experience Work Conditions * Flexibility in working hours as needed * Some travel, ~10% ## Description As a foundational member of Omnicell's AI Governance Program, you will design and operate a third-party intake process that identifies AI solutions entering the organization, evaluates them against the company's responsible-AI and risk standards, and determines the level of risk each presents to the business. Working closely with Procurement, Legal, Privacy, Security, Quality, and business owners, you will establish questionnaires, risk-tiering criteria, and review workflows that allow Omnicell to adopt AI tools quickly and responsibly., As a Manager, AI Vendor Governance, you will: * Primary Impact - Give Omnicell a clear, defensible view of every AI solution entering the business through a third party, so that teams can adopt AI tools quickly and with confidence, and so that customers, regulators, and patients can trust how those tools are vetted and governed. * Program build-out - Build, implement, and mature Omnicell's AI vendor governance program, including its policies, standards, intake process, and review workflows * Third-party AI intake - Design and operate a third-party intake process that identifies AI solutions entering the organization, including AI embedded within broader products and services, and routes them for risk review * Risk tiering and classification - Develop risk-tiering and classification criteria that account for the AI use case, the sensitivity of the data involved, and the potential business impact of failure, bias, or misuse * Due diligence design - Create and maintain AI-specific due diligence questionnaires and assessment criteria covering model design, training data, transparency and explainability, bias mitigation, security, and ongoing monitoring * Vendor evidence review - Evaluate vendor documentation and control evidence, such as SOC 2 reports, ISO/IEC 42001 certifications, model cards, and impact assessments, and identify gaps that require remediation or compensating controls * Risk decisions - Determine and communicate the level of risk each AI solution presents, and partner with business owners on remediation, risk acceptance, or alternative approaches * AI inventory and shadow AI - Maintain an inventory of third-party AI in use across the organization, working to surface and govern shadow AI * Contractual requirements - Partner with Procurement and Legal to define contractual requirements for AI vendors, including disclosure of AI use, data handling, and responsible-AI commitments * Continuous monitoring - Establish continuous monitoring and periodic reassessment of AI vendors across the relationship lifecycle, from onboarding through offboarding * Metrics and regulatory tracking - Develop program metrics, reporting, and dashboards that demonstrate coverage, maturity, and risk posture to leadership, and track evolving AI regulations and standards, such as the EU AI Act and the NIST AI Risk Management Framework, that affect third-party AI ## Related Videos - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Fireside Chat: Deep Learning, Deep Impact: Harnessing AI for Language Innovation](https://www.wearedevelopers.com/videos/612-fireside-chat-deep-learning-deep-impact-harnessing-ai-for-language-innovation) - [Rethinking Recruiting: What you didn’t know about Responsible AI](https://www.wearedevelopers.com/videos/1090-rethinking-recruiting-what-you-didn-t-know-about-responsible-ai) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer)