Director Governance Risk and Compliance
$208.55k - $254.85kSurescripts
Surescripts serves the nation through simpler, trusted health intelligence sharing, in order to increase patient safety, lower costs and ensure quality care. We deliver insights at critical points of care for better decisions — from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between providers.Job Summary:The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk and Compliance (GRC) information security team to ensure compliance with regulatory and contractual requirements. This role is responsible for creating, maintaining, and training on all Information Security Policy and Standards. This role leads a team that provides project risk assessment, project security subject matter expertise, and third-party security risk assessment. This role also oversees all business continuity and crisis management efforts across the enterprise along with overseeing and managing the information security training and awareness program.Responsibilities:Provide strategic oversight of information security compliance initiatives to ensure rigorous alignment with all applicable information security regulatory standards and contractual obligations.Oversee and provide leadership direction for the Information Security GRC program, aligning with business objectives.Own the Information Security control framework and the annual assurance calendar —including scoping, evidence collection, control testing, auditor management, and remediation tracking to closure.Lead third-party risk management for vendors and downstream partners handling PHI, including due diligence, BAA security terms, and ongoing monitoring; serve as the security escalation point for customer and partner security reviews, questionnaires, and contractual security obligations.Advance organizational cyber security awareness by developing and implementing tactical strategies that foster a risk-intelligent culture. Lead and coordinate security awareness initiatives to consistently enhance cyber security knowledge and practices throughout the organization.Establish and govern a comprehensive risk management program—covering internal and external risk assessments—to strengthen organizational resilience, compliance, and decision‑making.Provide leadership oversight to ensure continuous improvement and organizational compliance.Collaborate cross functionally with subject matter experts to document the risks and controls, measure the control effectiveness and report the findings through key risk and performance indicators.Provide oversight to ensure that business continuity plans are reviewed annually. Collaborate with cross-functional teams across Surescripts to develop, test, and validate contingency plans for critical business operations, thereby strengthening organizational resilience and preparedness.Develop, maintain and communicate the risk appetite framework and corresponding model(s) of risk tolerance, including the design process and protocol for routine monitoring of risk metrics against limits and escalation.Build and lead the Information Security GRC team — hiring, developing, and retaining analysts across policy, risk assessment, control testing, and audit response. Foster a culture of continuous learning and ensure institutional knowledge (control rationale, audit history, regulatory and customer commitments) is documented and transferable rather than person-dependent.Qualifications: Basic Requirements:Bachelor’s degree in a technical field, statistics, or risk management field or equivalent related experience.10+ years of experience in related, progressive roles.Cyber security certification such as CISM, CGEIT, CRISC, CISA, CISSP.5+ years of people management experience in roles showing progressive leadership.5+ years of experience in information security risk management.Experience with AI and GRC PlatformsExperience working with senior executives in a demanding and dynamic business environment with access to highly confidential and proprietary information.Skilled at effectively communicating with a broad range of audiences (executives, technical teams, non-technical business partners)Advanced skills in the areas of project management and implementing initiatives including proven experience with control frameworks and certifications such as NIST CSF, DirectTrust, HITRUST, SOC-2, EHNAC, etc.Strong decision-making skills.Experience with educating the workforce on current risk/information security policies, standards, and procedures to ensure understanding.Ability to effectively communicate business risk as it relates to information security.Broad understanding of common risks and risk management strategies across many domains such as finance, technology, human resources, cybersecurity, competition, and environmentalExperience managing a risk program in the healthcare industry.Preferred Qualifications:Experience with Business Continuity PlanningAbility to guide governance, risk, and compliance decisions related to AI‑enabled technologies, including oversight of risk assessments, controls, and policy alignment.Up-to-date understanding of a wide range of incident responses, system configuration, vulnerability management and hardening guidelinesOne or more AI cyber security certifications such as AAISM, AAIA, AAIRDemonstrated ability to lead AI risk assessments, control design, and policy/standard alignment.Keywords: risk, SOC-2, DirectTrust, HITRUST, crisis management, GRCSurescripts embraces flexibility through its Flexible Hybrid Work model for most positions. This model allows employees to work virtually while still utilizing our offices as collaboration centers. With alignment and agreement from your leadership, you can come and go from the office as needed.To be considered for employment, applicants must have a valid U.S. work authorization allowing work without restrictions with Surecripts in the U.S. At this time, we are unable to provide support or provide sponsorship for immigration benefits such as work visas. Additionally, we do not participate in academic training programs or work-study programs through an academic institution that require employer endorsement of F-1/CPT or F-1/STEM.What You’re Like You’re technical. Analytical. Imaginative. Maybe you’re building your own crypto-mining rig—or not. Either way, your mind works to anticipate vulnerabilities and protect the company and its information against those vulnerabilities. You do the right thing because it’s the right thing without seeking to point fingers or brag. And of course, you’re always willing to keep learning. What We’re Like We’re a team of friendly folks who do serious work. Our best work is done by rising to the occasion under stress, but we keep each other cool under pressure. We’re a tight team but we also look for ways to partner across the business. Our style is casual and laid back, but we shoulder our responsibility to protect patient data from sophisticated adversaries, which sometimes means delivering a difficult truth.What the Work is Like Our challenge is to protect our customers’ data and our company. This requires anomaly analysis, risk reviews, pen testing of our controls, red-teaming and tabletops, policy and procedure work, documentation, and audits. We also engineer and maintain our security products and tools. It’s not always a typical 9-to-5 gig, of course, but then again, you work in information security, so you already know that.Why Wait? Apply NowWe’re a midsize company. This means you’re not just another employee ID number. Here, you can build real relationships and feel supported by truly awesome people with diverse backgrounds and talents in an innovative and collaborative work culture. We strive to create an environment where you can be yourself, share your ideas and work your way. We offer opportunities for employee development, as well as competitive compensation packages and extensive benefits.At Surescripts, base pay is one part of our Total Rewards Package (which may also include bonus, benefits etc.) and is determined within a range. The base pay range for this position is $208,550 - $254,850 per year. Your base pay may vary within or outside of this range depending on a number of factors, including (but not limited to) your qualifications, skills, experience, and location.Benefits include, but are not limited to, comprehensive healthcare (including infertility coverage), generous paid time off including paid childbirth and parental leave and mental health days, pet insurance, and 401(k) with company match and immediate vesting. To learn more, review the Keep You and Yours Healthy, Balancing Work and Life, and Where Talent Takes Shape links under the Better Benefits. Better Work. Better Life section of our careers site.Physical and Mental Requirements While performing duties of this job, an employee may be required to perform any, or all of the following: attend meetings in and out of the office, travel, communicate effectively (both orally and in writing), and be able to effectively use computers and other electronic and standard office equipment with, or without, a reasonable accommodation. Additionally, this job requires certain mental demands, including the ability to use judgement, withstand moderate amounts of stress and maintain attention to detail with, or without, a reasonable accommodation.Work EnvironmentSurescripts embraces flexibility through its Flexible Hybrid Work model for most positions. This model allows employees to work virtually while still utilizing our offices as collaboration centers. With alignment and agreement from your leadership, you can come and go from the office as needed.Surescripts is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate on the basis of race, color, religion, age, national origin, ancestry, disability, medical condition, marital status, pregnancy, genetic information, gender, sexual orientation, parental status, gender identity, gender expression, veteran status, or any other status protected under federal, state, or local law.SummaryLocation: Minneapolis, Minnesota; Arlington, VirginiaType: Full time
$86.58 - $119.04 per hour
...and a chance to learn, effect change, and make meaningful contributions at work and in communities. The Director, Global Cybersecurity Governance, Risk, Compliance & Identity is accountable for defining and executing Donaldson’s enterprise cybersecurity governance and...SuggestedFull timeWork experience placement$93.4k - $128.4k
....Job DescriptionSupport the centralized risk function for Wealth Management Solutions... ...regulatory reporting, controls, committee governance, risk program coordination, policy... ...partners with business leaders, risk partners, Compliance, Legal, Internal Audit, and other...SuggestedFull timeContract workH1bWork at officeWork from homeVisa sponsorship1 day per week$127.2k - $246.9k
...others. If you're as passionate about your future as we are, join our team.KPMG is currently seeking a Manager, Security Governance, Risk and Compliance to join our Enterprise Security Services organization.Responsibilities:Lead technology, data, operations, artificial...SuggestedH1bLocal area$46.11 - $85.62 per hour
...and has opportunities to grow and learnWhat Youll Do:Enterprise Risk Management ExecutionLead components of the Enterprise Risk... ...summaries, dashboards, and presentations for senior leadership and governance forumsTranslate risk insights into actionable recommendations to...SuggestedMinimum wageFull timeContract workWork at officeFlexible hours$133.5k - $207.5k
...dynamic team that's transforming the global retail supply chain!Position Summary:We're hiring a Senior Manager, Risk & Controls to own and elevate our SOX compliance program at SPS Commerce. This is a high-visibility role where you'll serve as the organization's subject...SuggestedFull timeRemote workFlexible hoursShift work$133.37k - $156.9k
...Day One.Job DescriptionThe Prepaid Fraud Risk Manager serves as the designated fraud... ...partners closely with product, operations, compliance, technology, risk management, issuing... ...validating outputs and ensuring compliance with governance, privacy, and risk management standards....Full timeWork experience placementLocal area3 days per week$101k - $203k
...like RSM.The PositionAs a manager in RSM’s growing Healthcare Risk Consulting Practice, you will have the opportunity to draw from... ...frequently work as or alongside a client’s internal audit and compliance function, the chief risk officer or risk function, and various...Full timeWork experience placementInternshipLocal areaRemote workShift work$114.5k - $157.4k
...DescriptionSupport initiatives to enable the operational / non-financial risk efforts for RiverSource Insurance and Annuities. Lead the... ..., best practices, issues, and concerns. · Establish and lead a governance framework designed to monitor and ensure efficacy of...Full timeH1bWork at officeWork from homeVisa sponsorship1 day per week- ...large and growing Commercial Bank, is looking for an accomplished risk and controls leader to strengthen first-line risk oversight... ...practical, scalable approaches for control monitoring, testing, and governance within a banking environment while partnering closely with...
$99k - $176k
...management products and capabilities. As a Risk Advice Senior Manager, Business Risk... ...business line and Enterprise formal risk governance requirementsLead and participate in risk... ..., as well as functional groups, such as Compliance, Law Group and Enterprise Group RiskWhat...Full timeFlexible hours$111.2k - $190.3k
...across the U.S. and the global network. The Manager of Risk & Compliance supports Assurance Digital by executing certification... ...assigned initiatives, escalating complex issues to Associate Directors or Directors.Governance and Reporting Support - Support compliance governance...Full timeWork experience placementInternshipLocal area- ...organization’s total enterprise reinvention.We are:Risk, and we give finance execs the sounding... ..., or building from current risk and compliance models to get ready for the future, we... ...Credit risk management § Policy and governance§ Portfolio management and analytics (risk...Full timeLive inWork at officeLocal areaFlexible hours
- ...accomplished, detail-oriented Business Risk Officer within a banking environment. This... ...objectives are supported by effective governance and controls.• Partner with leaders across... ...and progress on action plans.• Support compliance reviews, examinations, and risk program...
$148.2k - $292.3k
...better for humans and humans better at work. The teamDeloitte’s Government and Public Services (GPS) practice - our people, ideas,... ..., Medicaid policy, budget forecasting and fiscal analyses, and risk adjustmentLead and manage end-to-end business development efforts...Local area$122.4k - $168.3k
...around the world.Job DescriptionThe Senior Manager, Technology Risk is a Second Line of Defense (2LOD) role reporting to the VP, Technology... ...risk themes and escalate concerns appropriately.Support governance forums and risk committees through preparation of materials,...Full timeH1bWork at officeWork from homeVisa sponsorship1 day per week$119.77k - $140.9k
...management, financial controls, and marketing governance activities across PCS Product &... ...disciplines, quality controls, and regulatory compliance while enabling business growth and... ...Finance, Compliance, Operations, and Credit Risk teams to support successful execution of...Full timeTemporary workWork experience placementWork at officeLocal area$93.8k - $122k
...work and in communities. Position Summary: The Risk Manager partners closely with the Director of Risk Management to support the administration and... ...of insurance, policy documentation, and related compliance activities Coordinate with brokers and insurers to...Full timeWork experience placementH1bLocal areaRemote workRelocationShift work- ...organizational wide management responsibilities as a key risk manager for the system This role provides guidance and best... ...assessment, drug screen, background investigation, and compliance with the U.S. Government Form I-9, Employment Eligibility Verification. Children...Full timePart timeWork experience placementLocal areaShift workNight shiftWeekend work
$100k - $110k
...treasury operations, supporting daily cash management, banking governance, reporting, and continuous process improvement. This role... ...resilience by executing strong internal controls, supporting compliance, and providing actionable insight into cash and liquidity trends...Full timeTemporary workWork at officeRemote work2 days per week3 days per week$133.37k - $156.9k
...(WCIB) and Institutional Client Group (ICG) Credit and Lending Risk group. The purpose of the program is to ensure a consistent and... ...across all levels of the organization. Lead projects that ensure compliance with Credit Policy, BU Procedures, applicable federal...Full timeWork experience placementWork at officeLocal area3 days per week$157.5k - $205k
...the reinvention of how Circle’s Global Risk Management (GRM) organization operates —... ...will partner with process owners across compliance, financial crime, security, financial risk... ...building AI solutions with appropriate governance, controls, and guardrails from day one.Preferred...Flexible hoursShift work$141.2k - $278.3k
Position Summary Technical Manager - AI & Data Risk Management - Financial Services Our Deloitte Regulatory, Risk & Forensic... ...capabilities such as data architecture, data platforms, data governance, data quality, and data securityApply knowledge of Financial Services...- ...organization’s total enterprise reinvention.We are:Risk, and we give Chief Financial Officers, Chief Risk Officers, Chief Compliance Officers, Chief Data Officers and their execs... ...for better and more efficient ways to govern and manage information to improve business and...Full timeLive inWork at officeLocal area
$101k - $203k
...’s why there’s nowhere like RSM.The ERP Risk and Automation Services (ERAS) Consulting... ...and standards including accounting, government, and data privacy to meet the needs of our... ...security and GRC (governance, risk and compliance) Proven experience managing project financials...Full timeWork experience placementInternshipLocal area$150k - $180k
...and machine learning.Build and refine pricing models to improve risk segmentation, profitability, and competitive positioning.Ensure... ...assistance program that includes free counseling sessions. Eligibility for benefits is governed by the applicable plan documents and policies....Full timeTemporary workPart timeLocal area$141.89k - $243.24k
...new hires. Role Summary The Model Risk Manager is responsible for leading and advancing... ...Model Risk Management Program to ensure compliance with regulatory requirements and... ...independent challenge, and enhance model risk governance. The position offers the opportunity to...Hourly payFull timeShift work- ...Safety & Risk ManagerWhat began as an idea between two brothers to open a Mexican restaurant has since grown into one of the largest... ....Maintain accurate claim documentation, reporting and compliance requirements.Identify emerging areas of risk and recommend strategies...Temporary workInterim role
$133.37k - $156.9k
...support Comprehensive Capital Analysis & Review (CCAR) and Capital Risk Management teams focusing on risk identification in processes... ...with leaders in their assigned Line of Business, Risk/Compliance/Audit (RCA) Consultants, and other RCA Managers to, depending on...Full timeWork experience placementWork at officeLocal area3 days per week$200k - $260k
...Manager at Circle, you will own the strategy and execution of our risk platform, ensuring it scales to support new products, markets,... .... You will act as a cross-functional leader, partnering with compliance, legal, engineering, data science, and business stakeholders to...Remote workFlexible hours- ...Job Description Job Description Position Summary The Risk Manager is responsible for leading and administering the company... ...and implements risk management strategies, oversees insurance compliance and claims administration, and provides guidance to project teams...For subcontractorWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director Governance Risk and Compliance. Be the first to apply!
- enterprise risk manager Minneapolis, MN
- senior risk manager Minneapolis, MN
- risk management associate Minneapolis, MN
- director credit risk Minneapolis, MN
- director of risk management Minneapolis, MN
- head of risk management Minneapolis, MN
- operational risk manager Minneapolis, MN
- risk management manager Minneapolis, MN
- risk management specialist Minneapolis, MN
- training and compliance manager Minneapolis, MN



