Jobs · OTHR · Texas

Director, Security - GRC

Concentra · Addison, TX · 2 wk ago
OTHRFull-time

About the role

The Director, Security - GRC (Governance, Risk Management, and Compliance) will lead efforts in maintaining compliance with various regulatory and security frameworks. This role requires a deep understanding of security, compliance, regulatory frameworks, platform management, vendor security reviews, third-party risk management, and customer interactions. Requires a strong ability to collaborate across functions and provide valuable insights and leadership in enhancing our security and compliance environment(s).

Responsibilities

  • Create and maintain Security Compliance policies
  • Perform security risk assessments to identify gaps, develop recommendations, and close the gaps to completion and resolution
  • Lead and maintain the Third Party Risk Management (TPRM) program
  • Set up internal audit processes for various security needs
  • Oversee platform security compliance audits for new regions to comply with legal regulations
  • Project management that includes the knowledge to initiate and drive complex security projects requiring various stakeholders
  • Develop metrics to track security program effectiveness and to report risk
  • Create a governance program for different security areas like Infrastructure, Application, SOC, and others
  • Identify critical security audit areas, establish the audit process, and complete audits of key areas
  • Create and update security risk metrics to measure risk levels across systems and processes
  • Conduct security awareness and educational trainings for the company and specific teams
  • Facilitate and participate in internal audits of critical processes and as required for PCI and SOX
  • Complete risk assessments of high-risk processes and develop gaps and recommendations
  • Roll out security awareness trainings for the company and GRC team

Requirements

  • Bachelor’s Degree in Computer Science, Information Security, or related field
  • Minimum of 8-10 years of experience related to risk management
  • Three to four years of project management experience
  • Experience developing GRC programs in a cloud and SaaS environment
  • Experience with privacy frameworks, such as SOX, SOC2 Type 2, PCI, NIST, and HIPAA
  • Experience with third-party risk management
  • Strong collaborator, with experience working on teams composed of both technical and non-technical members
  • Demonstrated ability to lead large projects, problem-solve, multitask, and have excellent organizational skills
  • Excellent written and verbal communication skills, with experience presenting to key stakeholders and partnering with internal collaborators and external auditors
  • Ability to make decisions or solve problems by using logic to identify key facts, explore alternatives, and propose quality solutions
  • Outstanding customer service skills as well as the ability to deal with people in a manner which shows tact and professionalism
  • The ability to properly handle sensitive and confidential information (including HIPAA and PHI) in accordance with federal and state laws and company policies
  • Thrive in a data-driven, fast-paced, and innovative environment
  • Strong prioritization skills and the ability to handle multiple job duties in a fast-paced environment
  • Exceptional communication skills and the ability to communicate appropriately at all levels of the organization, written and verbal

Concentra Core Competencies: Service Mentality, Attention to Detail, Sense of Urgency, Initiative, and Flexibility.

Benefits

  • 401(k) Retirement Plan with Employer Match
  • Medical, Vision, Prescription, Telehealth, & Dental Plans
  • Life & Disability Insurance
  • Paid Time Off
  • Colleague Referral Bonus Program
  • Tuition Reimbursement
  • Commuter Benefits
  • Dependent Care Spending Account
  • Employee Discounts

Similar jobs