GRC & InfoSec Director: Strategy, Risk & Compliance

Surescripts, LLC

Minneapolis (MN)

Hybrid

USD 209,000 - 255,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Surescripts, LLC is seeking a strategic Director of Governance, Risk and Compliance to lead our GRC information security team and ensure regulatory and contractual obligations are met, while creating and maintaining policies and training programs.

You will oversee third‑party risk, business continuity, and security awareness initiatives, partnering with executives to strengthen risk management and incident response across the enterprise.

Qualifications

  • Bachelor’s degree in a technical field, statistics, or risk management field or equivalent related experience.
  • 10+ years of experience in related, progressive roles.
  • Cyber security certification such as CISM, CGEIT, CRISC, CISA, CISSP.
  • 5+ years of people management experience in roles showing progressive leadership.
  • 5+ years of experience in information security risk management.
  • Experience with AI and GRC Platforms Experience working with senior executives in a demanding and dynamic business environment with access to highly confidential and proprietary information.
  • Skilled at effectively communicating with a broad range of audiences (executives, technical teams, non-technical business partners)
  • Advanced skills in the areas of project management and implementing initiatives including proven experience with control frameworks and certifications such as NIST CSF, DirectTrust, HITRUST, SOC‑2, EHNAC, etc.
  • Strong decision-making skills.
  • Experience with educating the workforce on current risk/information security policies, standards, and procedures to ensure understanding.
  • Ability to effectively communicate business risk as it relates to information security.
  • Broad understanding of common risks and risk management strategies across many domains such as finance, technology, human resources, cybersecurity, competition, and environmental.
  • Experience managing a risk program in the healthcare industry.

Responsibilities

  • Provide strategic oversight of information security compliance initiatives to ensure rigorous alignment with all applicable information security regulatory standards and contractual obligations.
  • Oversee and provide leadership direction for the Information Security GRC program, aligning with business objectives.
  • Own the Information Security control framework and the annual assurance calendar —including scoping, evidence collection, control testing, auditor management, and remediation tracking to closure.
  • Lead third‑party risk management for vendors and downstream partners handling PHI, including due diligence, BAA security terms, and ongoing monitoring; serve as the security escalation point for customer and partner security reviews, questionnaires, and contractual security obligations.
  • Advance organizational cyber security awareness by developing and implementing tactical strategies that foster a risk‑intelligent culture.
  • Lead and coordinate security awareness initiatives to consistently enhance cyber security knowledge and practices throughout the organization.
  • Establish and govern a comprehensive risk management program—covering internal and external risk assessments to strengthen organizational resilience, compliance, and decision‑making.
  • Provide leadership oversight to ensure continuous improvement and organizational compliance.
  • Collaborate cross functionally with subject matter experts to document the risks and controls, measure the control effectiveness and report the findings through key risk and performance indicators.
  • Provide oversight to ensure that business continuity plans are reviewed annually.
  • Collaborate with cross-functional teams across Surescripts to develop, test, and validate contingency plans for critical business operations, thereby strengthening organizational resilience and preparedness.
  • Develop, maintain and communicate the risk appetite framework and corresponding model(s) of risk tolerance, including the design process and protocol for routine monitoring of risk metrics against limits and escalation.
  • Build and lead the Information Security GRC team — hiring, developing, and retaining analysts across policy, risk assessment, control testing, and audit response.
  • Foster a culture of continuous learning and ensure institutional knowledge (control rationale, audit history, regulatory and customer commitments) is documented and transferable rather than person‑dependent.

Skills

Leadership
Risk management
Information security
Regulatory compliance
Vendor risk management
Auditing
Control frameworks
Project management
Communication

Education

Bachelor’s degree in a technical field, statistics, or risk management field

Tools

CISM
CGEIT
CRISC
CISA
CISSP

Job description

Surescripts, LLC is seeking a strategic Director of Governance, Risk and Compliance to lead our GRC information security team and ensure regulatory and contractual obligations are met, while creating and maintaining policies and training programs.

You will oversee third‑party risk, business continuity, and security awareness initiatives, partnering with executives to strengthen risk management and incident response across the enterprise.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, GRC & Information Security — Hybrid Leader
Director, GRC & Information Security — Hybrid Leader

Surescripts • Minneapolis (MN)

Hybrid
USD 209,000 - 255,000
Comprehensive healthcare
Infertility coverage
Paid time off
+4
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
InfoSec GRC Leader: Governance, Risk & Compliance
InfoSec GRC Leader: Governance, Risk & Compliance

Servier • Boston (MA)

On-site
USD 180,000 - 240,000
GRC Leader - Information Security & Compliance
GRC Leader - Information Security & Compliance

Servier Pharmaceuticals • Boston (MA)

Hybrid
USD 179,000 - 212,000
Head of GRC & Enterprise Security Risk
Head of GRC & Enterprise Security Risk

HCSC • Chicago (IL)

On-site
USD 178,000 - 330,000
Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
GRC Executive Director: Enterprise Risk & Compliance
GRC Executive Director: Enterprise Risk & Compliance

HCSC Group • Town of Texas (WI)

Hybrid
USD 178,000 - 330,000
Senior GRC Director: Security Governance & Risk Lead
Senior GRC Director: Security Governance & Risk Lead

Health Care Service Corp. • Richardson (TX)

On-site
USD 133,000 - 248,000
Health benefits
401(k) plan
Pension plan
+8
Senior Director, GRC & Information Security
Senior Director, GRC & Information Security

HCSC Group • Richardson (TX)

On-site
USD 133,000 - 248,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1