Assistant Vice President (AVP) Governance, Risk & Compliance (GRC)
CVS Health
We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time. Position Summary The AVP Governance, Risk & Compliance (GRC) leads the strategy, design, and execution of CVS Health's enterprise information security governance, risk management, technology compliance, and regulatory compliance program, including the modernization of GRC through automation, evidence reuse, and AI-assisted risk quantification and reporting. Reporting to the Deputy CISO and partnering closely with the CISO, this leader manages cybersecurity risk posture, controls, technology compliance, and regulatory obligations while driving continuous improvement. The AVP builds trusted relationships across Security, Third-Party Risk, Audit, Legal, Finance, regulators, vendors, and business leaders to translate risk into clear, actionable priorities. Key Responsibilities Lead the development and execution of CVS Health's enterprise information security governance, risk, technology compliance, and regulatory compliance strategy, aligned to business objectives and enterprise risk appetite, working in close partnership with both the CISO and Deputy CISO. Drive the cybersecurity risk assessment program - identification, quantification, tracking, and remediation of risk - and report risk posture and trends to the Deputy CISO, CISO, and leadership committees. Lead the modernization and automation of GRC capabilities, including evidence reuse, automated control testing, and AI-assisted risk quantification and reporting, to improve speed, accuracy, and scalability of the program. Ensure the security program's continued compliance with the full range of regulatory and industry requirements applicable to cybersecurity in healthcare - including HIPAA, HITECH, 42 CFR Part 2, CMS security and privacy requirements, FDA requirements where applicable, state insurance and privacy laws, PCI DSS, SOX, SOC 1/SOC 2, and SEC cybersecurity disclosure requirements - as well as other frameworks relevant to CVS Health's retail, pharmacy, and health services lines of business. Own enterprise technology compliance for cybersecurity, ensuring technology controls, configurations, and platforms across the enterprise meet applicable regulatory, contractual, and internal policy requirements. Direct the lifecycle of enterprise information security policies, standards, and procedures, ensuring they remain current, enforceable, and aligned to NIST CSF, ISO 27001, HITRUST CSF, and other adopted control frameworks. Serve as the primary GRC liaison to Internal Audit, external auditors, and regulators; coordinate audit and examination responses and drive timely remediation of findings. Oversee SOX cybersecurity and IT general control support, including coordination with Finance, Internal Audit, control owners, and external auditors to define control scope, validate evidence, track deficiencies, and support timely remediation. Lead SOC 1 and SOC 2 readiness and attestation support for applicable services and platforms, including control mapping, evidence management, audit coordination, exception handling, and continuous improvement of trust services control coverage. Own the security exception and risk acceptance process, ensuring appropriate executive visibility and accountability for accepted risk. Establish and lead enterprise AI risk governance, including oversight of AI-related security, privacy, and regulatory risk across internally developed and third‑party AI capabilities. Partner with Security Risk Management leadership to ensure the enterprise risk framework, control taxonomy, and reporting are aligned with the vendor risk program, without duplicating ownership. Build strong partnerships with internal and external stakeholders to strengthen alignment, resolve issues, and advance enterprise risk and compliance objectives. Prepare and deliver regular cybersecurity risk posture reporting to the Board Risk/Audit Committee and other executive governance forums. Manage and mature GRC tooling and platforms to support risk quantification, control testing, and reporting automation. Lead and develop the GRC team, building succession bench strength, and fostering a culture of accountability, continuous improvement, business partnership, and effective change leadership through organizational transformation. Required Qualifications Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent professional experience. 10+ years of progressive experience in information security, IT risk management, or regulatory compliance, including 5+ years in a leadership role. Deep working knowledge of regulatory and control frameworks applicable to a large, regulated enterprise, including HITRUST CSF, SOX IT general controls, SOC 1/SOC 2, NIST CSF, ISO 27001, and related cybersecurity control frameworks. Demonstrated experience building or scaling an enterprise GRC program, including risk assessment and policy management. Hands‑on experience with GRC platforms and risk quantification/reporting tools, including automation and evidence reuse capabilities. Proven ability to communicate risk and compliance matters clearly to executive leadership, Board committees, auditors, and regulators. Demonstrated executive presence, with the ability to influence senior leaders, represent the GRC function in executive forums, and communicate complex risk and compliance matters with clarity, credibility, and sound judgment. Experience partnering with Internal Audit and managing external regulatory examinations. Experience supporting SOX control testing, SOC readiness or attestation activities, audit evidence collection, control deficiency remediation, and executive‑level reporting on compliance posture. Experience operating within a matrixed, multi‑business‑unit enterprise (e.g., retail, pharmacy, health services, or similarly complex organizational structures). Proven ability to lead through influence and build trusted relationships across internal and external partner groups, including senior business leaders, technology teams, Legal, Finance, Internal Audit, regulators, external auditors, consultants, and third‑party service providers. Proven enterprise people leadership and talent management experience, including building, developing, coaching, and retaining high‑performing teams; cultivating succession bench strength; and leading leaders through organizational change. Preferred Qualifications Advanced degree (MBA or MS) in a related discipline, or JD with cybersecurity and risk focus. Relevant certifications such as CISSP, CISM, CISA, CRISC, or CIPP. Experience in healthcare, pharmacy, health insurance, or retail industries. Experience with AI governance, model risk management, or emerging AI regulation. Familiarity with SEC cybersecurity disclosure requirements and materiality assessment processes. This pay range represents the base hourly rate or base annual full‑time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short‑term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program. Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong. Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families. This full‑time position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial well‑being of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility. Additional details about available benefits are provided during the application process and on Benefits Moments. We anticipate the application window for this opening will close on: 09/02/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws. #J-18808-Ljbffr CVS Health
- Responsibilities responsible for assisting in the protection of the value of the Company’s... ...servicers lead a team of Servicing QC and Compliance auditors manage the Servicing QC Program... ...reviews manage and oversee functional risk appetite through creation and ongoing maintenance...Suggested
- ...Executive Search Operating Model Set enterprise-wide strategic direction for executive talent acquisition Establish governance, quality, and compliance standards across five global regions Drive innovation through AI-enabled tools, assessment platforms, and data-driven...SuggestedWork experience placement
- Assistant Vice President, Workers Compensation Tangram is a portfolio company of Balavant. Tangram Insurance... .... Identify operational challenges or risks and communicate them to the EVP with... ...portfolio, ensuring quality, compliance, and consistency in all submissions, quotes...Suggested
- Vice President - Client Growth & Engagement Location: Bay Area, CA (Hybrid/In-Person Preferred... ..., account management, and delivery governance to scale enterprise relationships and... ...annual planning, forecasting, and contract compliance. Manage account‑level commercial...SuggestedContract work
$250k
...infrastructure to deploy it consistently, govern it responsibly, and measure it at the... ...overview: AI Collaborator is seeking a Vice President of Sales (North America) to lead the... ...alongside the client's internal IT and compliance teams. Serve as a credible peer in conversations...Suggested$200k - $240k
...customer decisioning — to manage risk, drive growth, and transform... ..., intelligence, agents and governance into a single decisioning... ...reliability and regulatory compliance. Trusted by 120+ institutions... ...For We are looking for a Vice President of Sales (West Coast) to lead...Remote workFlexible hours- Jobtailor is seeking a Senior Director of Governance, Risk, and Compliance to lead our GRC program for a regulated financial services environment. You will own security metrics, executive reporting, and alignment with SEC/FINRA obligations and global data protection laws...
$110k - $125k
...operational excellence. The Opportunity Martin Brower is seeking an experienced Executive Assistant to support Chief Operating Officer Yves-Marie and provide additional support to the Vice President, Global Projects, while partnering closely with other executive leaders as...Work at officeRemote workWorldwide- ...markets. You will identify operational risks and implement solutions quickly. You will... ...employment opportunities. If you require assistance during the application process or in... ...Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) at In compliance with...Full timeContract workFor contractorsWork at office
$225k - $250k
...the executive leadership team, ensuring that our back-office, compliance, technology, and client service teams run with precision and scale... ...(SOPs) to maximize efficiency and minimize operational risk. Establish Key Performance Indicators (KPIs) and utilize data...- ...CEO Life is seeking a Chapter President in Orange County (CA) to lead a 5-person Executive Leadership Pod and enroll CEOs, founders, and C‑suite executives. You will build a premium executive community, drive recurring revenue, and guide a high-performance team across...
- We believe in transforming every purchase into a force for good. Together, we empower communities, uplift causes, and change lives—one micro-donation at a time. Grateful Giving is a new technology platform that empowers individuals, businesses, and nonprofits to create...Local areaRemote work
$120k - $150k
...responsibilities will be to maintainand driving operational results within thecompany with a focus on organizational structure, compliance and asset management. A successful candidate will have a solid understanding of key business functions like HR, Finance, Fundraising...- ...regulatory requirements across all operating sites Proactively manage risk and crisis response planning Stakeholder Engagement Partner... ...7 Palo Alto, CA $206,000.00-$230,000.00 1 month ago Associate Vice President, Enterprise Portfolio Santa Clara, CA $226,176.00-$353,400.00...Full time
$225k - $275k
...finance, R&D and engineering functions. Working closely with the President and CEO, this is a key executive role for a proven operations... ..., yield, waste reduction, and cost optimization. Ensure full compliance with food safety, regulatory, and quality standards (FDA, USDA...Full time- Jobtailor is seeking a senior Risk leader to drive the Risk Appetite Statement (RAS) program and oversee the Enterprise Metric Policy... ...risk pillars and business leaders to design metrics, manage governance, and report performance. Travel as needed for cross-functional...
$300k - $390k
...language. Build clear, credible narratives around AI‑powered software creation, developer productivity, enterprise adoption, security, governance, education, and the future of work. Partner with the CEO, executive team, and functional leaders on positioning, reputation,...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours- ...forecasting, budgeting, performance analytics, risk management, and internal and external... ...performance, and lifecycle management Ensure compliance with all contractual, regulatory, market, operational, financing, and governance requirements across the global portfolio Drive...
- Versant Media seeks a VP of Content & Platform to drive enterprise platform growth, monetization, editorial direction, and brand governance across Rotten Tomatoes’ web and app ecosystem. The role collaborates with Editorial, Product, Ad Sales, Content, Marketing, Finance...
- ...is seeking a senior legal ethics advisor to guide AI governance and information governance risk within a major law firm environment. The role focuses... ...on ethical AI use, professional responsibility, and compliance, while collaborating with Risk Management, IT, and knowledge...
- ...daily operations and execute the firm’s strategic vision. The role partners with the CEO and executive team to ensure back-office, compliance, technology, and client service run with precision at scale. The ideal candidate has extensive wealth management experience,...
- A leading logistics firm is seeking a President to drive long-term strategic commercial growth and operational excellence. The ideal candidate will have proven experience in an executive role with P&L responsibility for a significant business. Responsibilities include overseeing...
$215k - $230k
...plant ramp-ups, and automation initiatives. Assist with architecting additional factory... ...efficiency across the organization. Ensure compliance with industry regulations, quality standards... ...to identify opportunities and mitigate risks. Develop and manage budgets, forecasts,...RelocationRelocation package$120k - $150k
Napa Valley Community Housing is seeking a Chief Operating Officer (COO) to lead operational strategies and improve organizational efficiency. This pivotal role requires collaborating with departmental leaders to drive operational success and ensure systemic stability. ...- LPL Financial LLC is seeking a Vice President, Divisional Administrative Manager to lead the branch administrative function across Linsco and L&S. You will shape vision, strategy, and execution, oversee a regional leadership team, and partner with senior executives to...
- Jobtailor is seeking an experienced Internal Audit/Risk and Compliance leader to protect the value of the company’s MSR assets by overseeing AmeriHome’s Servicing QC vendor reviews and sub-servicers. You will lead a team of Servicing QC and Compliance auditors, manage the...
$200k
...for a Regulatory Strategy, Vice President (Bay Area, Boston) to join our... ...regulations, and guidelines governing the conduct of clinical... ...programs and maintaining full compliance with all regulatory requirements... ...in complex reasoning, risk management, risk‑benefit and...- ...Lead the organization's AI transformation strategy for design — defining how AI tools, workflows, and capabilities are adopted, governed, and scaled across teams, while overseeing design systems governance and implementation across all products Establish research,...Work at office2 days per week
$80k - $110k
A global insurance brokerage is seeking a Personal Risk Specialist to serve affluent clients. The role, based in Los Angeles, focuses on establishing client relationships, managing risk, and achieving sales goals. Candidates should have robust experience in personal insurance...Flexible hours- ...Experience within eCommerce, online marketplaces, trust & safety, risk, compliance, or seller ecosystems Preferred: Experience building... ...with customer journey mapping, communication strategy, content governance, and change management Preferred: MBA or advanced degree in...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Assistant Vice President (AVP) Governance, Risk & Compliance (GRC). Be the first to apply!
- ultrasound assistant California, MO
- night assistant California, MO
- field assistant California, MO
- safety assistant California, MO
- nutrition assistant California, MO
- special assistant California, MO
- graduate assistant basketball California, MO
- grading assistant California, MO
- patient safety assistant California, MO
- work assistant California, MO


