Jobs · Information Technology

Senior Director, Security Governance Risk and Identity

Healthmap Solutions · United States · 1 mo ago
RemoteRemoteInformation TechnologyFull-time

Responsibilities

  • Serve as a bridge between technical teams (like IT and Security) and executive leadership, turning complex risk landscapes into clear business insights
  • Implement measures and governance frameworks to manage data use in compliance with laws and regulations
  • Develop, enhance, operationalize enterprise-level information security, IT security policies and procedures and controls to mitigate risk and comply with applicable laws and regulations
  • Lead use of and overall adoption of HITRUST Common Security Framework (CSF) to ensure and maintain continued certification and SOC2 Type II reporting
  • Identify, track, monitor and report on Information Security controls providing recommendations and remediation strategies to stakeholders when appropriate
  • Monitor the regulatory and statutory landscape on GRC and data security issues, keeping Healthmap personnel and senior leadership apprised of any relevant developments impacting the company’s business goals and objectives, and recommending appropriate courses of action as needed
  • Review projects, business critical systems and provide guidance and work with process owners to identify and remediate control weaknesses to ensure compliance with regulatory requirements and ensure client contractual commitments and industry best practices
  • Maintain IT/Security questionnaires and associated client required audit and assessment activities
  • Direct Disaster Recovery planning and testing to ensure recovery strategies meet or exceed business resiliency requirements and align with strategic objectives
  • Direct and manage our 3rd Party Risk Management program to ensure that vendors comply with all relevant security regulations, standards, and best practices
  • Maintain vendor security performance and identify areas for improvement
  • Work collaboratively with other functions, including Legal, Privacy, Finance and, IT and the business to ensure proper use of vendors to achieve strategic goals
  • Draft and manage content for the Information Security training of all employees and contractors
  • Direct and manage staff ensuring coach, development and performance management is in alignment with department goals, ensuring key performance metrics are attained and adjusting efforts to ensure target attainment
  • Define a multi-year roadmap for IAM, including transitioning to modern frameworks like Zero Trust and Passwordless Authentication
  • Oversee Identity Governance and Administration (IGA) processes—managing joiners, movers, and leavers to ensure least-privilege access across the entire enterprise
  • Manage Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Adaptive Access policies that determine how users log in and what context-aware security checks are applied
  • Secure high-risk "keys to the kingdom" for administrators and service accounts to prevent lateral movement during a breach
  • Oversee the security and user experience of customer-facing identity (e.g., social login, profile management, and secure registration flows)
  • Perform other duties as assigned

Requirements

  • Bachelor’s degree in cyber security (or) related degree or equivalent work experience
  • 10-15 years’ experience in Information Security which includes 7 years’ experience managing and leading staff in an GRC discipline and Identity
  • Or other areas of cyber security
  • Certified Information Security Systems Professional (CISSP), Certified Information Security Manager (CISM) or Global Information Assurance Certifications (GIAC) certifications are preferred
  • Managing risk scoring methodologies to establish risk scores against risk appetite
  • Experience managing non-IT and outside vendor partner staff to achieve GRC goals and objectives
  • Experience reviewing contracts and managing audit activities both as assessor and assessed. Healthcare and HITRUST v11 experience
  • Performing Information Security/Information Technology risk assessments experience
  • Able to align security and compliance objectives with the broader business goals and growth strategy
  • Proven track record of scaling GRC programs, often using tools like ServiceNow GRC, Archer, or OneTrust
  • Deep knowledge of frameworks such as NIST, ISO 27001, and various regional/industry-specific regulations
  • Effectively partnering with Legal, HR, Finance, and IT to embed risk management into day-to-day operations
  • Leading teams to automate access request workflows to reduce manual overhead and human error
  • Hands on experience with Access Management workflows for all identity transactions (Moves, Adds, Tranfers, and Changes)

Similar jobs

Director, Security Governance

Beth Israel Lahey HealthBoston, Massachusetts, United States· 2 wk ago
Information Technology$177k/yrapply on jobs.bilh.org