
Assistant Vice President – Governance, Risk & Compliance
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in California.
• Oversee CVS Health's strategy for enterprise information security governance, risk management, technology compliance, and regulatory compliance.
• Lead the cybersecurity risk assessment program, focusing on the identification, quantification, tracking, remediation, and executive reporting of risks.
• Enhance and automate GRC capabilities through evidence reuse, automated control testing, and AI-driven risk quantification and reporting.
• Ensure adherence to healthcare cybersecurity regulations, industry standards, and relevant control frameworks.
• Manage enterprise technology compliance concerning cybersecurity controls, configurations, and platforms.
• Direct the development and lifecycle management of enterprise information security policies, standards, and procedures.
• Act as the main GRC liaison for Internal Audit, external auditors, and regulatory bodies.
• Supervise SOX cybersecurity and IT general control support.
• Lead the readiness and attestation support for SOC 1 and SOC 2.
• Oversee the security exception and risk acceptance processes.
• Establish and lead a governance framework for enterprise AI risk.
• Align the enterprise risk framework, control taxonomy, and reporting with the vendor risk management program.
• Foster collaborative relationships with internal and external stakeholders to enhance risk and compliance initiatives.
• Prepare and present cybersecurity risk posture reports to the Board Risk/Audit Committee and executive governance forums.
• Manage and enhance GRC tools and platforms.
• Lead and develop the GRC team, focusing on succession planning, continuous improvement, and organizational transformation.
• Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent professional experience.
• Over 10 years of progressive experience in information security, IT risk management, or regulatory compliance.
• At least 5 years in a leadership capacity.
• Extensive knowledge of HITRUST CSF, SOX IT general controls, SOC 1/SOC 2, NIST CSF, ISO 27001, and other cybersecurity control frameworks.
• Proven experience in building or scaling an enterprise GRC program, encompassing risk assessment and policy management.
• Practical experience with GRC platforms and risk quantification/reporting tools, along with automation and evidence reuse.
• Skilled in communicating risk and compliance issues to executive leadership, Board committees, auditors, and regulators.
• Possess executive presence and the capability to influence senior leadership.
• Experienced in collaborating with Internal Audit and managing external regulatory examinations.
• Familiar with SOX control testing, SOC readiness or attestation, audit evidence collection, control deficiency remediation, and executive-level compliance reporting.
• Experience in a matrixed, multi-business-unit enterprise.
• Ability to lead by influence and cultivate trusted relationships across internal and external partner groups.
• Experience in enterprise people leadership and talent management.
• Preferred: advanced degree (MBA or MS) or JD focusing on cybersecurity and risk.
• Preferred: certifications such as CISSP, CISM, CISA, CRISC, or CIPP.
• Preferred: experience in healthcare, pharmacy, health insurance, or retail sectors.
• Preferred: experience with AI governance, model risk management, or emerging AI regulations.
• Preferred: knowledge of SEC cybersecurity disclosure requirements and materiality assessment processes.
• CVS Health bonus, commission or short-term incentive program in addition to base salary.
• Award target in the company’s equity award initiative.
• Medical insurance coverage.
• Dental insurance coverage.
• Vision insurance coverage.
• Paid time off.
• Retirement savings options.
• Wellness programs.
• Additional resources to support physical, emotional, and financial well-being.
ICON plc
US Anesthesia Partners
MultiplyMii
Paychex
Get handpicked remote jobs straight to your inbox weekly.