We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary The Senior Manager of Cybersecurity Compliance will lead and execute strategic initiatives related to Regulatory Compliance for CVS Health’s Enterprise Information Security team, guiding colleagues in facilitating regulatory assessments and compliance activities across the enterprise. This role develops, implements, and manages procedures, controls, and reporting to ensure compliance with regulations. Consults on efforts to continuously improve internal controls, processes, and systems to enhance the effectiveness and efficiency of the program. Partners with IT and business colleagues to educate on risk and provide actionable metrics that measure control effectiveness. This role also coordinates and manages activities of process owners to support regulatory audits, including supporting audit requests and tracking remediation. Collaborates with key stakeholders, including senior management, Legal, Internal Audit, and external assessors, to ensure alignment and support of the Regulatory Compliance Program. Specifically, this role: Manages and executes procedures to facilitate and support various cybersecurity regulatory audits and compliance activities, establishing schedules and plans to ensure deadlines are met. Develops efficient processes to facilitate and support regulatory, internal audit, and industry standard assessments and audits. Provides coaching, feedback, and education to stakeholders and colleagues on regulatory compliance requirements and industry best practices. Defines and develops risk management policies and procedures to support the implementation of technology controls across the enterprise. Oversees preparation and submission of regulatory compliance reports to management, auditors, assessors, and regulators. Oversees audits and assessments to measure the effectiveness of security controls, providing results back to the responsible party/owner. Educates key stakeholders on risk management frameworks and top risks related to regulatory compliance.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
Associate degree