Executive Director, Governance Risk & Compliance
Core
Enterprise leadership for security risk and compliance, setting strategy, owning GRC outcomes, and ensuring regulatory alignment across the company and subsidiaries.
Role type
Executive Director, Governance Risk & Compliance (GRC)
Builds
Enterprise GRC framework, attestations, certifications (SOX, HIPAA, HITRUST), security policy, exception management, security awareness initiatives, third-party risk management, threat and vulnerability management processes.
Domain
Healthcare / Information Security / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Enterprise GRC program leadership, security risk management, regulatory compliance (SOX, HIPAA, HITRUST), budget stewardship, cross-functional stakeholder alignment, executive/Board briefing, multi-team leadership.
Preferred skills
Executive experience with regulatory regimes (HIPAA/HITRUST, SOX), enterprise control frameworks (NIST CSF/800-53, ISO 27001).
Technologies
SOX, HIPAA, HITRUST, NIST CSF, 800-53, ISO 27001
Responsibilities
Setting enterprise security risk and compliance strategy, leading enterprise attestations and certifications, governing security policy and exceptions, overseeing threat and vulnerability management, managing third-party risk, briefing executives and the Board, stewarding the security risk budget.
Seniority
Executive, strategic leadership & cross-functional alignment
