Director Governance Risk and Compliance

SurescriptsMinneapolis, MN
Hybrid

About The Position

Surescripts serves the nation through simpler, trusted health intelligence sharing, in order to increase patient safety, lower costs and ensure quality care. We deliver insights at critical points of care for better decisions — from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between providers. The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk and Compliance (GRC) information security team to ensure compliance with regulatory and contractual requirements. This role is responsible for creating, maintaining, and training on all Information Security Policy and Standards. This role leads a team that provides project risk assessment, project security subject matter expertise, and third-party security risk assessment. This role also oversees all business continuity and crisis management efforts across the enterprise along with overseeing and managing the information security training and awareness program.

Requirements

  • Bachelor’s degree in a technical field, statistics, or risk management field or equivalent related experience.
  • 10+ years of experience in related, progressive roles.
  • Cyber security certification such as CISM, CGEIT, CRISC, CISA, CISSP.
  • 5+ years of people management experience in roles showing progressive leadership.
  • 5+ years of experience in information security risk management.
  • Experience with AI and GRC Platforms
  • Experience working with senior executives in a demanding and dynamic business environment with access to highly confidential and proprietary information.
  • Skilled at effectively communicating with a broad range of audiences (executives, technical teams, non-technical business partners)
  • Advanced skills in the areas of project management and implementing initiatives including proven experience with control frameworks and certifications such as NIST CSF, DirectTrust, HITRUST, SOC-2, EHNAC, etc.
  • Strong decision-making skills.
  • Experience with educating the workforce on current risk/information security policies, standards, and procedures to ensure understanding.
  • Ability to effectively communicate business risk as it relates to information security.
  • Broad understanding of common risks and risk management strategies across many domains such as finance, technology, human resources, cybersecurity, competition, and environmental
  • Experience managing a risk program in the healthcare industry.

Nice To Haves

  • Experience with Business Continuity Planning
  • Ability to guide governance, risk, and compliance decisions related to AI‑enabled technologies, including oversight of risk assessments, controls, and policy alignment.
  • Up-to-date understanding of a wide range of incident responses, system configuration, vulnerability management and hardening guidelines
  • One or more AI cyber security certifications such as AAISM, AAIA, AAIR
  • Demonstrated ability to lead AI risk assessments, control design, and policy/standard alignment.

Responsibilities

  • Provide strategic oversight of information security compliance initiatives to ensure rigorous alignment with all applicable information security regulatory standards and contractual obligations.
  • Oversee and provide leadership direction for the Information Security GRC program, aligning with business objectives.
  • Own the Information Security control framework and the annual assurance calendar —including scoping, evidence collection, control testing, auditor management, and remediation tracking to closure.
  • Lead third-party risk management for vendors and downstream partners handling PHI, including due diligence, BAA security terms, and ongoing monitoring; serve as the security escalation point for customer and partner security reviews, questionnaires, and contractual security obligations.
  • Advance organizational cyber security awareness by developing and implementing tactical strategies that foster a risk-intelligent culture.
  • Lead and coordinate security awareness initiatives to consistently enhance cyber security knowledge and practices throughout the organization.
  • Establish and govern a comprehensive risk management program—covering internal and external risk assessments—to strengthen organizational resilience, compliance, and decision‑making.
  • Provide leadership oversight to ensure continuous improvement and organizational compliance.
  • Collaborate cross functionally with subject matter experts to document the risks and controls, measure the control effectiveness and report the findings through key risk and performance indicators.
  • Provide oversight to ensure that business continuity plans are reviewed annually.
  • Collaborate with cross-functional teams across Surescripts to develop, test, and validate contingency plans for critical business operations, thereby strengthening organizational resilience and preparedness.
  • Develop, maintain and communicate the risk appetite framework and corresponding model(s) of risk tolerance, including the design process and protocol for routine monitoring of risk metrics against limits and escalation.
  • Build and lead the Information Security GRC team — hiring, developing, and retaining analysts across policy, risk assessment, control testing, and audit response.
  • Foster a culture of continuous learning and ensure institutional knowledge (control rationale, audit history, regulatory and customer commitments) is documented and transferable rather than person-dependent.

Benefits

  • comprehensive healthcare (including infertility coverage)
  • generous paid time off including paid childbirth and parental leave and mental health days
  • pet insurance
  • 401(k) with company match and immediate vesting
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service