Director of Information Security GRC & Risk

Surescripts

Minneapolis (MN)

Hybrid

USD 209,000 - 255,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Healthcare
Paid time off
Parental leave
Mental health days
Pet insurance
401(k)

Job summary

Surescripts is seeking a Director of Governance, Risk and Compliance to oversee the GRC information security team, ensure regulatory and contractual compliance, and lead risk assessment, control testing, and training on information security policies. The role also manages business continuity and crisis management and drives a risk-aware culture across the enterprise.

The candidate will work with executives, manage third-party risk, and ensure policy alignment with standards like NIST CSF,

Qualifications

  • Bachelor's degree in a technical, statistics, risk management field or equivalent.
  • 10+ years of experience in related, progressive roles.
  • Cyber security certification such as CISM, CGEIT, CRISC, CISA, CISSP.
  • 5+ years of people management experience.
  • 5+ years of information security risk management experience.
  • Experience with AI and GRC Platforms.
  • Experience communicating with senior executives.
  • Strong understanding of control frameworks and certifications (NIST CSF, DirectTrust, HITRUST, SOC-2).
  • Healthcare industry risk management experience.

Responsibilities

  • Provide strategic oversight of information security compliance initiatives.
  • Lead the Information Security GRC program alignment with business objectives.
  • Own the information security control framework and assurance calendar.
  • Lead third-party risk management for vendors handling PHI and security reviews.
  • Advance security awareness and build a risk-intelligent culture.
  • Establish and govern a comprehensive risk management program.
  • Provide leadership oversight for continuous improvement and compliance.
  • Collaborate cross-functionally to document risks, controls and report findings.
  • Oversee business continuity planning and contingency testing across the enterprise.
  • Develop and communicate the risk appetite framework and tolerance models.
  • Build and lead the Information Security GRC team.

Skills

Governance
Risk Management
Policy Development
Security Awareness
Third-party risk
Leadership
Communication

Education

Bachelor's degree

Tools

GRC Platforms
NIST CSF
DirectTrust
HITRUST
SOC-2

Job description

Surescripts is seeking a Director of Governance, Risk and Compliance to oversee the GRC information security team, ensure regulatory and contractual compliance, and lead risk assessment, control testing, and training on information security policies. The role also manages business continuity and crisis management and drives a risk-aware culture across the enterprise.

The candidate will work with executives, manage third-party risk, and ensure policy alignment with standards like NIST CSF,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & InfoSec Director: Strategy, Risk & Compliance
GRC & InfoSec Director: Strategy, Risk & Compliance

Surescripts, LLC • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
Director of Cybersecurity GRC - Healthcare & Research
Director of Cybersecurity GRC - Healthcare & Research

Insight Global • United States

On-site
USD 170,000 - 256,000
Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
Sr. Director, Governance, Risk, and Compliance (GRC)
Sr. Director, Governance, Risk, and Compliance (GRC)

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
Senior GRC Director: Security Governance & Risk Lead
Senior GRC Director: Security Governance & Risk Lead

Health Care Service Corp. • Richardson (TX)

On-site
USD 133,000 - 248,000
Health benefits
401(k) plan
Pension plan
+8
GRC Director: Information Security Governance & Risk
GRC Director: Information Security Governance & Risk

Information Security • Richardson (TX)

On-site
USD 133,000 - 248,000
Senior Director, GRC & Information Security
Senior Director, GRC & Information Security

HCSC Group • Richardson (TX)

On-site
USD 133,000 - 248,000
GRC Leader - Information Security & Compliance
GRC Leader - Information Security & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000