The Director Information Security - Governance, Risk, and Compliance (GRC) will lead the IT Governance, Risk, and Compliance teams and oversee the services and processes for establishing effective IT risk management in an academic provider healthcare environment. This role collaborates with executive leadership, clinical and operational teams, and external partners to proactively identify, assess, and manage cybersecurity risks, ensure regulatory compliance, and foster a culture of security awareness throughout the health system. This role will oversee and continuously mature the information security risk management program including assessment of cyber and IT risk management and exceptions, maintenance of a registry of significant IT risks, third-party risk management (TPRM), data governance, disaster recovery and business continuity (DR/BC), cyber insurance and other assessments, coordination of internal and external audits and completion of the associated corrective action plans, security metrics and dashboards, internal phishing simulations and tabletop exercises (TTX), and on-going security awareness education.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director
Industry
Executive, Legislative, and Other General Government Support
Number of Employees
101-250 employees