Director, Security - GRC
concentraGranite Heights (WI)
About the role
Concentra is recognized as the nation’s leading occupational health care company.
With more than 40 years of experience, Concentra is dedicated to our mission to improve the health of America’s workforce, one patient at a time. With a wide range of services and proactive approaches to care, Concentra colleagues provide exceptional service to employers and exceptional care to their employees. The Director, Security - GRC (Governance, Risk Management, and Compliance) will lead the efforts in maintaining compliance with various regulatory and security frameworks. This role requires a deep understanding of security, compliance, regulatory frameworks, platform management, vendor security reviews, third party risk management and customer interactions. Requires a strong ability to collaborate across functions and provide valuable insights and leadership in enhancing our security and compliance environment (s)
.
Create and maintain Security Compliance policies
Perform security risk assessments to identify gaps, develop recommendations and close the gaps to completion and resolution
Lead and maintain and Third Party Risk Management (TPRM) program
Setup Internal audit processes for various security needs
Oversee platform security compliance audits for new regions to comply with legal regulations
Project management that includes the knowledge to initiate and drive complex security projects requiring various stakeholders
Develop metrics to track security program effectiveness and to report risk
Create a governance program for different security areas like Infrastructure, Application, SOC and others
Identify critical security audit areas, establish the audit process and have completed audit of few areas
Create and update security risk metrics to measure the risk levels across systems and processes
Conduct security awareness and educational trainings for the company and specific teams
Facilitate and participate in internal audits of critical processes and as required for PCI and SOX
Complete risk assessments of high-risk processes and come up with gaps and recommendations
Rollout security awareness trainings for the company and GRC team
Education Level:
Bachelor’s Degree Major: Computer Science, Information Security
Minimum of 8-10 years of experience related to risk management
Three to four years of project management experience
Experience developing GRC programs in a cloud and SaaS environment.
Concentra Core Competencies of Service Mentality, Attention to Detail, Sense of Urgency, Initiative and Flexibility
Ability to make decisions or solve problems by using logic to identify key facts, explore alternatives, and propose quality solutions
Outstanding customer service skills as well as the ability to deal with people in a manner which shows tact and professionalism
The ability to properly handle sensitive and confidential information (including HIPAA and PHI) in accordance with federal and state laws and company policies
Experience with privacy frameworks, such as SOX, SOC2 Type 2, PCI, NIST and HIPAA
Experience with third party risk management
Strong collaborator, with experience working on teams composed of both technical and non technical members
Demonstrated ability to lead large projects, problem-solve, multitask, and have excellent organizational skills
Excellent written and verbal communication skills, with experience presenting to key stakeholders and partnering with internal collaborators and external auditors
Thrive in a data-driven, fast-paced and innovative environment
Strong prioritization skills and the ability to handle multiple job duties in a fast-paced environment
Exceptional communication skills and the ability to communicate appropriately at all levels of the organization, written and ver
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
