Executive Director, Governance Risk & Compliance

Health Care Service CorporationChicago, IL
$177,500 - $329,800

About The Position

This position provides enterprise leadership for security risk and compliance by setting strategy, owning GRC outcomes, and ensuring regulatory alignment across the company and its subsidiaries. The Executive Director builds and sustains the enterprise GRC framework and leads all enterprise attestations and certifications, including SOX, HIPAA, and HITRUST, supported by clear C suite and Board reporting. The role governs security policy, exceptions, security awareness initiatives, and third party risk management, while enabling consistent identification, tracking, remediation, and reporting of security risks across the enterprise. Responsibilities also include overseeing processes for threat and vulnerability management, ensuring adherence to established risk policies and standards, and continuously improving security risk management capabilities and controls. The Executive Director owns the enterprise information security risk posture, budget stewardship, and cross functional alignment with Legal, Compliance, IT, and Business stakeholders.

Requirements

  • Bachelor’s degree and 15 years of experience in IT/Information Security; or 19 years of experience without a degree.
  • Minimum 7 years of people leadership experience (multi‑team leadership preferred).
  • Proven experience leading enterprise GRC programs (risk, compliance, policy, third‑party risk, subsidiary governance).
  • Demonstrated success briefing executives/Board, owning budgets, and driving cross‑functional outcomes.

Nice To Haves

  • Executive experience with regulatory regimes (e.g., HIPAA/HITRUST, SOX) and enterprise control frameworks (NIST CSF/800‑53, ISO 27001).

Responsibilities

  • Setting strategy for security risk and compliance.
  • Owning GRC outcomes.
  • Ensuring regulatory alignment across the company and its subsidiaries.
  • Building and sustaining the enterprise GRC framework.
  • Leading all enterprise attestations and certifications (SOX, HIPAA, HITRUST).
  • Providing clear C suite and Board reporting.
  • Governing security policy, exceptions, security awareness initiatives, and third party risk management.
  • Enabling consistent identification, tracking, remediation, and reporting of security risks across the enterprise.
  • Overseeing processes for threat and vulnerability management.
  • Ensuring adherence to established risk policies and standards.
  • Continuously improving security risk management capabilities and controls.
  • Owning the enterprise information security risk posture.
  • Budget stewardship.
  • Cross-functional alignment with Legal, Compliance, IT, and Business stakeholders.

Benefits

  • Health and wellness benefits
  • 401(k) savings plan
  • Pension plan
  • Paid time off
  • Paid parental leave
  • Disability insurance
  • Supplemental life insurance
  • Employee assistance program
  • Paid holidays
  • Tuition reimbursement
  • Other incentives
  • Annual incentive bonus plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service