Director, Security - GRC

Concentra

Town of Texas (WI)

On-site

USD 150,000 - 190,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Concentra, a leading occupational health care company, seeks a Director of Security - GRC to lead governance, risk, and compliance efforts across the organization. The role requires coordinating regulatory frameworks, vendor risk reviews, and internal audits while collaborating with stakeholders to strengthen security posture.

The ideal candidate has a deep understanding of privacy and security controls in cloud and SaaS environments, with extensive leadership and project management experience.

Qualifications

  • Minimum 8–10 years of risk management experience.
  • 3–4 years of project management experience.
  • Experience developing GRC programs in cloud and SaaS environments.
  • Experience with privacy frameworks such as SOX, SOC2 Type 2, PCI, NIST and HIPAA.

Responsibilities

  • Create and maintain Security Compliance policies.
  • Perform security risk assessments to identify gaps and address them.
  • Lead Third Party Risk Management (TPRM) program.
  • Set up internal audits for various security needs.
  • Oversee platform security compliance audits for new regions.
  • Drive complex security projects with multiple stakeholders.
  • Develop metrics to track security program effectiveness and report risk.
  • Create governance programs for Infrastructure, Application, SOC, and other areas.
  • Identify critical audit areas and complete audits.
  • Roll out security awareness trainings for company and GRC team.
  • Ensure compliance with PCI and SOX and educate teams accordingly.

Skills

Risk management
Project management
Regulatory compliance
Third party risk management
Security policy development
Stakeholder communication
Privacy frameworks

Education

Bachelor’s Degree in Computer Science / Information Security

Job description

Concentra is recognized as the nation’s leading occupational health care company.

With more than 40 years of experience, Concentra is dedicated to our mission to improve the health of America’s workforce, one patient at a time. With a wide range of services and proactive approaches to care, Concentra colleagues provide exceptional service to employers and exceptional care to their employees.


The Director, Security - GRC (Governance, Risk Management, and Compliance) will lead the efforts in maintaining compliance with various regulatory and security frameworks. This role requires a deep understanding of security, compliance, regulatory frameworks, platform management, vendor security reviews, third party risk management and customer interactions. Requires a strong ability to collaborate across functions and provide valuable insights and leadership in enhancing our security and compliance environment (s)

  • .
    Create and maintain Security Compliance policies
  • Perform security risk assessments to identify gaps, develop recommendations and close the gaps to completion and resolution
  • Lead and maintain and Third Party Risk Management (TPRM) program
  • Setup Internal audit processes for various security needs
  • Oversee platform security compliance audits for new regions to comply with legal regulations
  • Project management that includes the knowledge to initiate and drive complex security projects requiring various stakeholders
  • Develop metrics to track security program effectiveness and to report risk
  • Create a governance program for different security areas like Infrastructure, Application, SOC and others
  • Identify critical security audit areas, establish the audit process and have completed audit of few areas
  • Create and update security risk metrics to measure the risk levels across systems and processes
  • Conduct security awareness and educational trainings for the company and specific teams
  • Facilitate and participate in internal audits of critical processes and as required for PCI and SOX
  • Complete risk assessments of high-risk processes and come up with gaps and recommendations
  • Rollout security awareness trainings for the company and GRC team
  • Education Level: Bachelor’s Degree Major: Computer Science, Information Security
  • Minimum of 8-10 years of experience related to risk management
  • Three to four years of project management experience
  • Experience developing GRC programs in a cloud and SaaS environment.
  • Concentra Core Competencies of Service Mentality, Attention to Detail, Sense of Urgency, Initiative and Flexibility
  • Ability to make decisions or solve problems by using logic to identify key facts, explore alternatives, and propose quality solutions
  • Outstanding customer service skills as well as the ability to deal with people in a manner which shows tact and professionalism
  • The ability to properly handle sensitive and confidential information (including HIPAA and PHI) in accordance with federal and state laws and company policies
  • Experience with privacy frameworks, such as SOX, SOC2 Type 2, PCI, NIST and HIPAA
  • Experience with third party risk management
  • Strong collaborator, with experience working on teams composed of both technical and non technical members
  • Demonstrated ability to lead large projects, problem-solve, multitask, and have excellent organizational skills
  • Excellent written and verbal communication skills, with experience presenting to key stakeholders and partnering with internal collaborators and external auditors
  • Thrive in a data-driven, fast-paced and innovative environment
  • Strong prioritization skills and the ability to handle multiple job duties in a fast-paced environment
  • Exceptional communication skills and the ability to communicate appropriately at all levels of the organization, written and ver
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Security - GRC
Director, Security - GRC

Concentra, Inc. • Addison (TX), Northern (KY)

Hybrid
USD 180,000 - 260,000
401(k) Retirement Plan with Employer
Life & Disability Insurance
Paid Time Off
+4
Director of Security & GRC Strategy
Director of Security & GRC Strategy

Concentra • Town of Texas (WI)

On-site
USD 150,000 - 190,000
Director of Security & GRC
Director of Security & GRC

Concentra, Inc. • Addison (TX), Northern (KY)

Hybrid
USD 180,000 - 260,000
401(k) Retirement Plan with Employer
Life & Disability Insurance
Paid Time Off
+4
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,000 - 220,000
Annual incentive bonus
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

LexisNexis • Raleigh (NC)

On-site
USD 118,000 - 220,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
IT Technical Lead
IT Technical Lead

Concentra • Dallas (TX)

On-site
USD 120,000 - 170,000
Sr. Director, Governance, Risk, and Compliance (GRC)
Sr. Director, Governance, Risk, and Compliance (GRC)

Brobston Group LLC • Seattle (WA)

On-site
USD 180,000 - 260,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000