The Director of Information Security Governance, Risk & Compliance (GRC) is responsible for leading the enterprise-wide information security and IT GRC program, ensuring protection of electronic Protected Health Information (ePHI) and alignment with regulatory, contractual, and risk management obligations. This role drives the design, implementation, and continuous improvement of a comprehensive GRC program that delivers measurable risk reduction, audit readiness, and control maturity across clinical, operational, and corporate environments. The Director works closely with IT, Business Operations, Compliance, Privacy, Legal, Internal Audit, and Enterprise Risk Management. The role has direct accountability for HIPAA security governance, NIST framework adoption, third-party risk management, SOX IT controls coordination, and business continuity and incident readiness.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Director