Senior Manager, Governance Risk & Compliance

Sound Physicians

Northern (KY)

Hybrid

USD 130,000 - 160,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
PTO 15 days/year
10 company-paid holidays

Job summary

Sound Physicians is seeking a Senior Manager of Governance, Risk, and Compliance to lead the enterprise information security GRC program and report to the CISO. This role translates cybersecurity strategy into measurable processes, risk visibility, and a defensible compliance posture, owning day-to-day security risk management and governance.

You will mentor GRC staff, collaborate with Security, IT, Legal, Privacy, and business teams, and help advance the Strategic Information Security Program

Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or related field.
  • 7+ years of experience in information security GRC or risk management.
  • Preferred: CISSP, CISM, CRISC, CISA, or similar certifications; experience in a CISO led security organization or regulated environment.

Responsibilities

  • GRC Program Execution: Operate and mature the enterprise GRC program aligned to the CISO’s strategy and risk appetite.
  • Security Risk Management: Own the security risk lifecycle, including assessments, tracking, remediation, and escalation of material risks to the CISO.
  • Governance & Policy: Maintain the security policy framework and translate standards (e.g., NIST CSF, ISO 27001, SOC 2) into actionable control requirements.
  • Compliance & Audit: Manage security related compliance activities and audits; maintain evidence and track remediation to closure.
  • Third Party Risk: Operate the vendor security risk management program and escalation high risk vendors and systemic issues.
  • Metrics & Reporting: Produce concise risk and compliance metrics and dashboards for the CISO and senior leadership.
  • Enablement & Leadership: Mentor GRC staff and act as a trusted advisor to Security, IT, Legal, Privacy, and business teams.
  • Security Program Direction: Partner with the CISO and Sr. Manager of Security Operations to update the Strategic Information Security Program.

Skills

HIPAA Security rule
NIST CSF
ISO 27001
SOC 2
Security risk practices
Risk assessments
Audits and control testing
Communicate risk to leaders
Mentor GRC team
Technology risk awareness

Education

Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or related field
7+ years in information security GRC or risk management
CISSP, CISM, CRISC, CISA or similar certifications (preferred)

Job description

About Sound

Founded in 2001 and headquartered in Nashville, TN, Sound Physicians is a nationally respected, physician-led medical group practicing in 400+ hospitals across 45 states. Our team of 4,000+ clinicians and 1,000+ business professionals across the country is united by one mission: to build exceptional clinical partnerships that unlock quality, affordable, dignified care for everyone - no matter who they are or where they live. With physician-led clinical teams and more than two decades of operational expertise, we’ve refined what it takes to consistently deliver exceptional care in hospital medicine, emergency medicine, critical care, anesthesia, and telemedicine.

Why join us?
  • A remote-first culture that values flexibility and collaboration
  • Opportunities to grow your career while making a real impact
  • A team that champions inclusivity, innovation, and excellence

Whether working virtually or onsite at one of our practices, you’ll be part of a purpose-driven organization shaping the future of healthcare.

Sound Physicians offers a competitive benefits package inclusive of the items below, and more:
  • Medical insurance, Dental insurance, and Vision insurance
  • Health care and dependent care flexible spending account
  • 401(k) retirement savings plan with a company match
  • Paid time off (PTO) begins accruing immediately upon start date at a rate of 15 days per year, in accordance with Sound's PTO policy
  • Ten company-paid holidays per year
About the Role

The Senior Manager, Governance, Risk, and Compliance (GRC) leads the execution of the enterprise information security GRC program and report directly to the CISO. This role translates the CISO’s cybersecurity strategy and risk tolerance into scalable and defined processes, measurable outcomes, and defensible compliance posture. The Senior Manager serves as the primary owner of day to day security risk management, governance, and compliance activities, providing clear risk visibility and enabling informed executive decision making.

Essential Duties and Responsibilities
  • GRC Program Execution: Operate and mature the enterprise GRC program aligned to the CISO’s strategy and risk appetite.
  • Security Risk Management: Own the security risk lifecycle, including assessments, tracking, remediation, and escalation of material risks to the CISO.
  • Governance & Policy: Maintain the security policy framework and translate standards (e.g., NIST CSF, ISO 27001, SOC 2) into actionable control requirements.
  • Compliance & Audit: Manage security related compliance activities and audits; maintain evidence and track remediation to closure.
  • Third Party Risk: Operate the vendor security risk management program and escalation high risk vendors and systemic issues.
  • Metrics & Reporting: Produce concise risk and compliance metrics and dashboards for the CISO and senior leadership.
  • Enablement & Leadership: Mentor GRC staff and act as a trusted advisor to Security, IT, Legal, Privacy, and business teams.
  • Security Program Direction: Partner with the CISO and Sr. Manager of Security Operations to update the Strategic Information Security Program.
What we are looking for:

A successful candidate will have a demonstrated track record of a combination of these values, knowledge, and experience:

Values
  • Persistence: Demonstrates the ability to "keep at it" even when obstacles or challenges are present; returns to the work at hand after a change of course.
  • Collaboration: Demonstrates the ability to work well with others to accomplish a goal and get the work done; takes opinions of others into consideration; includes others in the decision-making process
  • Trustworthiness: Demonstrates a high degree of integrity; keeps confidences; does what they say they will do.
  • Resourcefulness: Proactive willingness to utilize available information and tools to figure things out.
  • Strategic thinking: Demonstrates the ability to look at the big picture and proactively develop a plan of action.
Knowledge, Skills, and Abilities
  • Strong knowledge of HIPAA Security rule, NIST CSF, ISO 27001, SOC 2, and security risk practices.
  • Experience with risk assessments, audits, and control testing.
  • Ability to clearly communicate security risk to senior leaders.
  • Proven ability to mentor and develop GRC team members and develop working relationships across organizations.
  • Broad knowledge of technology and security risks.
Education and Experience
  • Bachelor’s degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or a related field
  • 7+ years of experience in information security GRC or risk management.
  • Preferred: CISSP, CISM, CRISC, CISA, or similar certifications. Experience in a CISO led security organization or regulated environment.
Salary Range

This position offers an annual salary range of $130,000-$160,000. Exact salary will depend on the candidate’s experience, education and geographic location. This position is eligible for additional compensation beyond base pay.

Sound Physicians is an Equal Employment Opportunity (EEO) employer and is committed to diversity, equity, and inclusion at the bedside and in our workforce. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, gender identity, sexual orientation, age, marital status, veteran status, disability status, or any other characteristic protected by federal, state, or local laws.

This job description reflects the present requirements of the position. As duties and responsibilities change and develop, the job description will be reviewed and subject to amendment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Manager — Remote, Risk & Compliance Strategy
Senior GRC Manager — Remote, Risk & Compliance Strategy

Sound Physicians • United States

On-site
USD 130,000 - 160,000
Remote GRC Leader: Governance, Risk & Compliance
Remote GRC Leader: Governance, Risk & Compliance

Sound Physicians • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical, dental & vision insurance
FSA (healthcare & dependent care)
401(k) with company match
+2
Application Security Analyst
Application Security Analyst

Sound Physicians • United States

Hybrid
USD 75,000 - 110,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off (PTO)
Internal Controls IT Manager (Contract-To-Hire)
Internal Controls IT Manager (Contract-To-Hire)

Sound Physicians • Northern (KY)

Hybrid
USD 69,000 - 96,000
Senior Financial Analyst
Senior Financial Analyst

Sound Physicians • Northern (KY)

Hybrid
USD 95,000 - 115,000
Medical, Dental, and Vision insurance
Health care and dependent care FSA
401(k) retirement with company match
+2
Director, Benefits & Wellbeing
Director, Benefits & Wellbeing

Sound Physicians, Inc. • Nashville (TN)

Hybrid
USD 135,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+3
SVP, Strategic Business Development, Health Systems
SVP, Strategic Business Development, Health Systems

Sound Physicians, Inc. • Nashville (TN)

Hybrid
USD 200,000 - 230,000
Medical insurance
Dental insurance
Vision insurance
+4
Practice Coordinator
Practice Coordinator

Silversmith Capital Partners • Manhattan (KS)

On-site
USD 33,000 - 48,000
Operations Staff Accountant
Operations Staff Accountant

Sound Physicians, Inc. • Nashville (TN)

Hybrid
USD 65,000 - 80,000
Medical/Dental/Vision insurance
Flexible spending account
401(k) with company match
+2
Practice Coordinator
Practice Coordinator

Sound Physicians, Inc. • San Bernardino (CA)

On-site
Medical insurance
Dental insurance
Vision insurance
+4