Location
Minneapolis MN, Hybrid remote
Job Type
Full Time
Target Salary Range
200000 230000
Position Overview
Our client is seeking a Director of Governance and Compliance to join our dynamic Regulatory Affairs team. This position will lead the strategic development and implementation of a comprehensive Compliance and Privacy framework tailored to corporate business objectives, regulatory frameworks and compliance best practices. This role is critical to ensure company operations and practices are compliant with state, federal and international regulatory requirements and industry standards while effectively managing organizational risk.
Environment
The Director of Governance and Compliance will partner with the Director of Information Security to integrate compliance initiatives with the overall departmental and organizational strategies and collaborate cross-functionally to manage and mitigate compliance related risks. We are highly responsive to customer needs and constantly strive to make a positive contribution to the biomedical and life sciences communities we serve. Team members are recognized and rewarded when advocating for customer success and satisfaction over other concerns. We value self-motivated creative individuals who work well in a collaborative environment, constantly generating and sharing innovative ideas and solutions with the team. Our client has a comprehensive benefits package and encourages a balanced work life and home life.
Key Responsibilities
- Maintain a clear understanding of business activities and all applicable and changing state, federal, and international laws and regulations.
- Serve as the organization’s SME to ensure regulatory practices are built into business unit initiatives for the entire development lifecycle.
- Identify, plan and prioritize organizational compliance and privacy activities based on risk and manage according to a prescribed cycle eg through the development of the annual compliance plan.
- Manage compliance efforts across the organization ensuring adherence to laws, regulations and standard such as GDPR, 21 CFR Part 11, HITRUST, ISO 27001, HIPAA, NIST 800-53 and AI Frameworks.
- Assist with preparing the Regulatory Affairs Departmental briefing for Executive Committee, Board of Directors and Compliance Committees.
- Develop and maintain the organization’s GRC policies and procedures ensuring they align with business objectives and regulatory requirements.
- Serve as a trusted advisor with business unit leadership and translate regulatory requirements into business unit initiatives and priorities.
- Develop and implement our Client’s Compliance Risk and Privacy Framework with plans to enable effective and resilient business services architectures and processes ensuring the company adheres to all relevant laws, standards and regulatory requirements.
- Collaborate with cross departmental business unit stakeholders to integrate compliance and risk management into the security and compliance program organization wide.
- Respond to customer requests for compliance questionnaires in a timely and thorough manner including the development of customer-facing materials explaining our Client’s compliance policies and positions.
- Lead the company-wide Enterprise Risk Management program working closely and cross-functionally with other operational departments (Product Engineering, Business Operations, Sales Support, Legal and Human Resources) to develop strategies to identify, evaluate and mitigate risks and ensure ongoing risk assessment and monitoring.
- Oversee Internal and External Audit Assessments to evaluate compliance with internal policies, regulatory requirements and contractual obligations.
- Lead Third Party Supplier Management Risk Assessments and program ensuring alignment with business objectives and organizational risk tolerances.
- Manage supply chain management processes including vendor assessments, due diligence and ongoing monitoring.
- Comply with company policies including security, confidentiality and data protection requirements to maintain a secure work environment.
Qualifications
- Minimum of 8-10 years of experience in regulatory compliance preferably with healthcare or technology related industry.
- Deep knowledge of industry specific regulations, standards and best practices HITRUST, ISO 27001, SOC 2, 21 CFR Part 11, NIST 800-53.
- Proven track record of developing, implementing and overseeing governance frameworks and programs in a complex multi regulatory environment.
- A strong understanding of IT security standards, privacy laws and compliance regulations.
- Detail oriented with a proven ability to spot inconsistencies or potential issues in a complex regulatory environment.
- Strong analytical skills to assess compliance risks and demonstrated experience developing and implementing effective mitigation strategies.
- Proactive in identifying potential compliance issues and devising solutions before they arise.
- Proficient in using compliance management software and tools.
- Familiarity with information security practices and how they intersect with compliance requirements.
- Excellent project management and communication skills including expertise in presenting complex regulatory frameworks to various audiences.
- Advanced education or certification indicating a deeper understanding of compliance and regulatory affairs and a commitment to professional development.