Director, GRC & Information Security — Hybrid Leader

Surescripts

Minneapolis (MN)

Hybrid

USD 209,000 - 255,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Comprehensive healthcare
Infertility coverage
Paid time off
Parental leave
Mental health days
Pet insurance
401(k) matching

Job summary

Surescripts seeks a Director of Governance, Risk and Compliance to lead the GRC information security program and ensure compliance with regulatory and contractual requirements. You will own policy, standards, risk assessments, and training across the enterprise.

You will build a risk-aware culture, manage third-party security, and oversee business continuity while partnering with executives to align security with business objectives in a flexible hybrid work environment.

Qualifications

  • Bachelor’s degree in a technical field, statistics, or risk management field or equivalent related experience.
  • 10+ years of experience in related, progressive roles.
  • Cyber security certification such as CISM, CGEIT, CRISC, CISA, CISSP.
  • 5+ years of people management experience in roles showing progressive leadership.
  • 5+ years of experience in information security risk management.

Responsibilities

  • Provide strategic oversight of information security compliance initiatives to ensure rigorous alignment with all applicable information security regulatory standards and contractual obligations.
  • Oversee and provide leadership direction for the Information Security GRC program, aligning with business objectives.
  • Own the Information Security control framework and the annual assurance calendar —including scoping, evidence collection, control testing, auditor management, and remediation tracking to closure.
  • Lead third-party risk management for vendors and downstream partners handling PHI, including due diligence, BAA security terms, and ongoing monitoring; serve as the security escalation point for customer and partner security reviews, questionnaires, and contractual security obligations.
  • Advance organizational cyber security awareness by developing and implementing tactical strategies that foster a risk-intelligent culture.

Skills

Governance risk and compliance
Information security risk management
Security certifications (CISM/CGEIT/CR

Education

Bachelor’s degree in technical field / risk management

Tools

GRC platforms

Job description

Surescripts seeks a Director of Governance, Risk and Compliance to lead the GRC information security program and ensure compliance with regulatory and contractual requirements. You will own policy, standards, risk assessments, and training across the enterprise.

You will build a risk-aware culture, manage third-party security, and oversee business continuity while partnering with executives to align security with business objectives in a flexible hybrid work environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & InfoSec Director: Strategy, Risk & Compliance
GRC & InfoSec Director: Strategy, Risk & Compliance

Surescripts, LLC • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
Head of GRC & Enterprise Security Risk
Head of GRC & Enterprise Security Risk

HCSC • Chicago (IL)

On-site
USD 178,000 - 330,000
GRC Lead — Hybrid, Strategic Compliance & Risk
GRC Lead — Hybrid, Strategic Compliance & Risk

Acuren Inspection, Inc. • Houston (TX)

Hybrid
USD 120,000 - 180,000
Sr. Director, Governance, Risk, and Compliance (GRC)
Sr. Director, Governance, Risk, and Compliance (GRC)

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
GRC Leader - Information Security & Compliance
GRC Leader - Information Security & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000
Enterprise GRC & Security Strategy Executive Director
Enterprise GRC & Security Strategy Executive Director

Information Security • Richardson (TX)

On-site
USD 178,000 - 330,000
Senior GRC Director: Security Governance & Risk Lead
Senior GRC Director: Security Governance & Risk Lead

Health Care Service Corp. • Richardson (TX)

On-site
USD 133,000 - 248,000
Health benefits
401(k) plan
Pension plan
+8