FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Director, Governance Risk and Compliance
Surescripts. Provide strategic oversight of information security compliance initiatives .
Posted 9/16/2026full-timeMinneapolis • Minnesota • United StatesLead💰 $208,550 - $254,850 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Information Security Governance, Risk, and Compliance (GRC) with a strong focus on risk management strategies, compliance frameworks, and cybersecurity initiatives. Proven ability to lead teams, manage third-party risks, and communicate effectively with stakeholders across technical and non-technical domains.
Highest-signal resume keywords
Information Security GovernanceRisk ManagementCybersecurity CertificationPeople ManagementBusiness Continuity Planning
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information Security Control FrameworkControl TestingRisk Appetite FrameworkIncident ResponseVulnerability ManagementProject ManagementControl FrameworksAI Risk AssessmentsCybersecurity Awareness StrategiesRegulatory Compliance
Soft Skills
Effective CommunicationDecision-MakingLeadershipAttention to DetailJudgment
Tools & Technologies
GRC PlatformsAI-Enabled TechnologiesBusiness Continuity Planning ToolsPerformance Indicators
Certifications & Qualifications
CISMCGEITCRISCCISACISSPAAISMAAIAAAIR
Industry Keywords
Healthcare IndustryPHI ManagementNIST CSFHITRUSTSOC-2DirectTrustEHNAC
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Provide strategic oversight of information security compliance initiatives
- Lead the Information Security Governance, Risk, and Compliance program in alignment with business objectives
- Own the Information Security control framework and annual assurance calendar, including scoping, evidence collection, control testing, auditor management, and remediation tracking
- Lead third-party risk management for vendors and downstream partners handling PHI
- Serve as the security escalation point for customer and partner security reviews, questionnaires, and contractual obligations
- Develop and implement cybersecurity awareness strategies and initiatives
- Establish and govern a comprehensive internal and external risk management program
- Collaborate with subject matter experts to document risks and controls, measure control effectiveness, and report findings through key risk and performance indicators
- Oversee annual business continuity plan reviews and collaborate on contingency planning, testing, and validation
- Develop, maintain, and communicate the risk appetite framework and risk tolerance models
- Monitor risk metrics against limits and manage escalation protocols
- Build and lead the Information Security GRC team, including hiring, developing, and retaining analysts
- Ensure institutional knowledge regarding controls, audits, regulations, and customer commitments is documented and transferable
- Provide leadership oversight for continuous improvement and organizational compliance
Requirements
What you’ll need- Bachelor’s degree in a technical field, statistics, or risk management field or equivalent related experience
- 10+ years of experience in related, progressive roles
- Cyber security certification such as CISM, CGEIT, CRISC, CISA, or CISSP
- 5+ years of people management experience in roles showing progressive leadership
- 5+ years of experience in information security risk management
- Experience with AI and GRC Platforms
- Experience working with senior executives in a demanding and dynamic business environment with access to highly confidential and proprietary information
- Ability to communicate effectively with executives, technical teams, and non-technical business partners
- Advanced project management skills and experience implementing initiatives
- Proven experience with control frameworks and certifications such as NIST CSF, DirectTrust, HITRUST, SOC-2, EHNAC, etc.
- Strong decision-making skills
- Experience educating the workforce on current risk/information security policies, standards, and procedures
- Ability to communicate business risk as it relates to information security
- Broad understanding of common risks and risk management strategies across finance, technology, human resources, cybersecurity, competition, and environmental domains
- Experience managing a risk program in the healthcare industry
- Experience with Business Continuity Planning
- Ability to guide governance, risk, and compliance decisions related to AI-enabled technologies
- Up-to-date understanding of incident response, system configuration, vulnerability management, and hardening guidelines
- One or more AI cybersecurity certifications such as AAISM, AAIA, or AAIR
- Demonstrated ability to lead AI risk assessments, control design, and policy/standard alignment
- Valid U.S. work authorization allowing work without restrictions in the U.S.; no immigration sponsorship available
- Ability to attend meetings in and out of the office, travel, communicate effectively orally and in writing, and use computers and standard office equipment
- Ability to use judgment, withstand moderate stress, and maintain attention to detail
Benefits
Comp & perks- Comprehensive healthcare, including infertility coverage
- Generous paid time off
- Paid childbirth and parental leave
- Mental health days
- Pet insurance
- 401(k) with company match and immediate vesting
- Flexible Hybrid Work model
- Opportunities for employee development
- Competitive compensation packages
- Extensive benefits