Director, Security - GRC
Concentra · Addison, TX · 2 wk ago
OTHRFull-time
About the role
The Director, Security - GRC (Governance, Risk Management, and Compliance) will lead efforts in maintaining compliance with various regulatory and security frameworks. This role requires a deep understanding of security, compliance, regulatory frameworks, platform management, vendor security reviews, third-party risk management, and customer interactions. Requires a strong ability to collaborate across functions and provide valuable insights and leadership in enhancing our security and compliance environment(s).
Responsibilities
- Create and maintain Security Compliance policies
- Perform security risk assessments to identify gaps, develop recommendations, and close the gaps to completion and resolution
- Lead and maintain the Third Party Risk Management (TPRM) program
- Set up internal audit processes for various security needs
- Oversee platform security compliance audits for new regions to comply with legal regulations
- Project management that includes the knowledge to initiate and drive complex security projects requiring various stakeholders
- Develop metrics to track security program effectiveness and to report risk
- Create a governance program for different security areas like Infrastructure, Application, SOC, and others
- Identify critical security audit areas, establish the audit process, and complete audits of key areas
- Create and update security risk metrics to measure risk levels across systems and processes
- Conduct security awareness and educational trainings for the company and specific teams
- Facilitate and participate in internal audits of critical processes and as required for PCI and SOX
- Complete risk assessments of high-risk processes and develop gaps and recommendations
- Roll out security awareness trainings for the company and GRC team
Requirements
- Bachelor’s Degree in Computer Science, Information Security, or related field
- Minimum of 8-10 years of experience related to risk management
- Three to four years of project management experience
- Experience developing GRC programs in a cloud and SaaS environment
- Experience with privacy frameworks, such as SOX, SOC2 Type 2, PCI, NIST, and HIPAA
- Experience with third-party risk management
- Strong collaborator, with experience working on teams composed of both technical and non-technical members
- Demonstrated ability to lead large projects, problem-solve, multitask, and have excellent organizational skills
- Excellent written and verbal communication skills, with experience presenting to key stakeholders and partnering with internal collaborators and external auditors
- Ability to make decisions or solve problems by using logic to identify key facts, explore alternatives, and propose quality solutions
- Outstanding customer service skills as well as the ability to deal with people in a manner which shows tact and professionalism
- The ability to properly handle sensitive and confidential information (including HIPAA and PHI) in accordance with federal and state laws and company policies
- Thrive in a data-driven, fast-paced, and innovative environment
- Strong prioritization skills and the ability to handle multiple job duties in a fast-paced environment
- Exceptional communication skills and the ability to communicate appropriately at all levels of the organization, written and verbal
Concentra Core Competencies: Service Mentality, Attention to Detail, Sense of Urgency, Initiative, and Flexibility.
Benefits
- 401(k) Retirement Plan with Employer Match
- Medical, Vision, Prescription, Telehealth, & Dental Plans
- Life & Disability Insurance
- Paid Time Off
- Colleague Referral Bonus Program
- Tuition Reimbursement
- Commuter Benefits
- Dependent Care Spending Account
- Employee Discounts