Director, IT Security Risk — Third-Party & GRC Leader

R1 RCM Holdco Inc.

Pennsylvania

Hybrid

USD 122,000 - 179,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

R1 RCM Inc. is seeking a Director of IT Security Risk to lead governance, risk, and compliance programs protecting patient data and technology assets. You will manage a US- and India-based team and own programs for third-party risk, customer assessments, and risk registers.

The role reports to the Deputy CISO and emphasizes hands-on leadership, automation, and collaboration with Procurement, Compliance, IT, and Security teams across global operations.

Qualifications

  • Bachelor’s degree or an equivalent combination of education and relevant experience.
  • 10+ years of cybersecurity, technology risk, governance, risk and compliance, or related experience, including at least five years in a people‑management role.
  • Experience leading cybersecurity governance, risk, and compliance programs, with significant responsibility for third‑party cyber risk management.
  • Experience building a new cyber GRC or third‑party risk capability from the ground up, or materially rebuilding and maturing an existing program.
  • Experience managing customer cybersecurity questionnaires, risk assessments, exceptions, and risk‑register processes.
  • Experience leading and developing teams across geographies, ideally including US- and India‑based employees.
  • Strong customer‑facing and stakeholder‑management skills, with the ability to work effectively with senior leaders, business partners, Procurement, Compliance, IT, Product Development, and Security teams.
  • Ability to translate cybersecurity risk into clear business impact, recommendations, metrics, and executive‑level reporting.
  • Experience improving processes through standardization, workflow design, and automation.
  • Strong judgment, organization, responsiveness, and the ability to manage multiple priorities and rapid‑turnaround requests.

Responsibilities

  • Develop and implement strategy for assessing, monitoring, and mitigating cybersecurity risk from third parties and suppliers.
  • Lead US- and India-based team, directing direct reports and broader staff.
  • Oversee responses to customer cybersecurity questionnaires, risk assessments, and risk‑register maintenance.
  • Build scalable governance and third‑party risk capabilities with clear procedures and controls.
  • Automate and optimize risk processes to improve efficiency and effectiveness.
  • Collaborate with customers and internal teams to address inquiries and time-sensitive needs.
  • Ensure alignment with regulatory requirements, standards, policies, and best practices.
  • Document program procedures, standards, and supporting materials.
  • Communicate performance, risk trends, and priorities to senior leadership.

Skills

Cybersecurity leadership
GRC programs
Third-party risk
Customer questionnaires
Cross-geography teams
Stakeholder management
Business impact analysis
Process automation
Project management

Education

Bachelor’s degree or equivalent

Job description

R1 RCM Inc. is seeking a Director of IT Security Risk to lead governance, risk, and compliance programs protecting patient data and technology assets. You will manage a US- and India-based team and own programs for third-party risk, customer assessments, and risk registers.

The role reports to the Deputy CISO and emphasizes hands-on leadership, automation, and collaboration with Procurement, Compliance, IT, and Security teams across global operations.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director, IT Security Risk & GRC Leader
Director, IT Security Risk & GRC Leader

Socket.dev • Illinois

On-site
USD 122,000 - 179,000
Director, IT Security Risk & Third-Party Governance
Director, IT Security Risk & Third-Party Governance

R1-Rc • Illinois

On-site
USD 122,000 - 179,000
Annual bonus plan
Competitive benefits package
Global IT Security Risk Director - GRC & Third-Party
Global IT Security Risk Director - GRC & Third-Party

R1 RCM • Illinois

On-site
USD 122,000 - 179,000
Director, IT Security Risk
Director, IT Security Risk

Socket.dev • Illinois

Hybrid
USD 122,000 - 179,000
Director, IT Security Risk
Director, IT Security Risk

R1 RCM • Illinois

On-site
USD 122,000 - 179,000
Director, IT Security Risk
Director, IT Security Risk

R1-Rc • Illinois

On-site
USD 122,000 - 179,000
Annual bonus plan
Competitive benefits package
Director of Information Security GRC & Risk
Director of Information Security GRC & Risk

Surescripts • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Healthcare
Paid time off
Parental leave
+3
GRC Leader - Information Security & Compliance
GRC Leader - Information Security & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000
Global Director, Security GRC & Compliance
Global Director, Security GRC & Compliance

Tricentis Americas, Inc. • Austin (TX)

On-site
USD 170,000 - 260,000
Director, IT Security Risk
Director, IT Security Risk

R1 RCM Holdco Inc. • Pennsylvania

Hybrid
USD 122,000 - 179,000