
Director, Governance, Risk & Compliance
Posted Aug 1

Posted Aug 1
This is a fully remote position, open to applicants in United States.
• The enterprise policy and ISMS framework, with controls mapped and maintained in Vanta, governed by a formal annual review and approval cycle.
• The enterprise risk register, including the scoring methodology, along with quarterly risk reporting to the executive team and board.
• The certification roadmap encompassing SOC 2 Type II, followed by HITRUST CSF and PCI DSS, with ISO 27001 to be introduced subsequently. You will select the auditors, manage the programs, and deliver the accompanying opinions.
• The third-party risk program, featuring a centralized response capability for incoming client security questionnaires across SIG Lite, CAIQ, and custom formats.
• Compliance-as-a-Service, a tiered, recurring compliance offering for our client base, ranging from SOC 2 readiness for SMBs to multi-framework managed compliance for enterprises. You will design, launch, and expand this service.
• Support for the compliance program in our CMMC practice, which caters to defense industrial base clients and is pursuing C3PAO authorization.
• A position on the Security Steering Committee alongside the CEO, CFO, CTO, and VP of Operations.
• A minimum of eight years in security, risk, or compliance, with at least three years in a leadership role for a GRC function or multi-framework program.
• Experience in compliance programs within an MSP, MSSP, or another multi-tenant service provider, as service provider compliance differs significantly from single enterprise compliance.
• At least one SOC 2 Type II engagement managed from readiness to a clean opinion, with your direct ownership of the process.
• Extensive expertise in two or more of the following: HITRUST CSF, PCI DSS, NIST CSF, NIST SP 800-171 and CMMC, ISO 27001.
• Practical experience with a compliance automation platform, preferably Vanta, where you are the one configuring integrations rather than merely observing others.
• Proficiency in formal risk methodologies and a proven ability to maintain a risk register that executives actively utilize for decision-making.
• Capability to articulate risk as a business decision to a CEO or board, rather than merely a compliance requirement.
• Leadership experience, including hiring and developing analysts, with a desire to build a cohesive team rather than just a program.
• Nice to have:
• CISA, CRISC, CISM, or CISSP certifications; HITRUST CCSFP; PCI ISA or QSA; CMMC RP or CCP.
• Experience in creating a compliance service that clients were willing to pay for, not merely a program that meets auditor standards.
• Background in a private equity-backed growth environment, including support for diligence processes.
• Competitive pay
• Quarterly Bonuses
• Progressive PTO
• Medical/Dental/Vision/Life/Disability options available
• Tax-deferred retirement plan with company match
• Career Development and Coaching
• Fun work environment!
InnovAge
Cardinal Health
Parexel
HealthEdge
Get handpicked remote jobs straight to your inbox weekly.