677,021open jobs
39,228companies
99,226added this week
Browse all
Salary
$209k – $255k per year
Location
Remote/Hybrid (Minneapolis, Arlington, United States)
Seniority
Architect · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Surescripts is a health information network headquartered in Arlington, Virginia, and founded in 2001 by pharmacy and pharmacy benefit industry organisations. The company routes electronic prescriptions, medication histories, benefit checks, and clinical records between prescribers, pharmacies, health plans, and electronic health record vendors across the United States. It handles a very large share of national e-prescribing traffic and operates as shared infrastructure rather than a clinical application.

Surescripts serves the nation through simpler, trusted health intelligence sharing, in order to increase patient safety, lower costs and ensure quality care. We deliver insights at critical points of care for better decisions - from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between providers.

Job Summary:

The Director of Governance, Risk and Compliance provides strategic oversight of the Governance Risk and Compliance (GRC) information security team to ensure compliance with regulatory and contractual requirements. This role is responsible for creating, maintaining, and training on all Information Security Policy and Standards. This role leads a team that provides project risk assessment, project security subject matter expertise, and third-party security risk assessment. This role also oversees all business continuity and crisis management efforts across the enterprise along with overseeing and managing the information security training and awareness program.

Responsibilities:

  • Provide strategic oversight of information security compliance initiatives to ensure rigorous alignment with all applicable information security regulatory standards and contractual obligations.

  • Oversee and provide leadership direction for the Information Security GRC program, aligning with business objectives.

  • Own the Information Security control framework and the annual assurance calendar -including scoping, evidence collection, control testing, auditor management, and remediation tracking to closure.

  • Lead third-party risk management for vendors and downstream partners handling PHI, including due diligence, BAA security terms, and ongoing monitoring; serve as the security escalation point for customer and partner security reviews, questionnaires, and contractual security obligations.

  • Advance organizational cyber security awareness by developing and implementing tactical strategies that foster a risk-intelligent culture. Lead and coordinate security awareness initiatives to consistently enhance cyber security knowledge and practices throughout the organization.

  • Establish and govern a comprehensive risk management program-covering internal and external risk assessments-to strengthen organizational resilience, compliance, and decision-making.

  • Provide leadership oversight to ensure continuous improvement and organizational compliance.

  • Collaborate cross functionally with subject matter experts to document the risks and controls, measure the control effectiveness and report the findings through key risk and performance indicators.

  • Provide oversight to ensure that business continuity plans are reviewed annually. Collaborate with cross-functional teams across Surescripts to develop, test, and validate contingency plans for critical business operations, thereby strengthening organizational resilience and preparedness.

  • Develop, maintain and communicate the risk appetite framework and corresponding model(s) of risk tolerance, including the design process and protocol for routine monitoring of risk metrics against limits and escalation.

  • Build and lead the Information Security GRC team - hiring, developing, and retaining analysts across policy, risk assessment, control testing, and audit response. Foster a culture of continuous learning and ensure institutional knowledge (control rationale, audit history, regulatory and customer commitments) is documented and transferable rather than person-dependent.

Qualifications:

Basic Requirements:

  • Bachelor’s degree in a technical field, statistics, or risk management field or equivalent related experience.

  • 10+ years of experience in related, progressive roles.

  • Cyber security certification such as CISM, CGEIT, CRISC, CISA, CISSP.

  • 5+ years of people management experience in roles showing progressive leadership.

  • 5+ years of experience in information security risk management.

  • Experience with AI and GRC Platforms

  • Experience working with senior executives in a demanding and dynamic business environment with access to highly confidential and proprietary information.

  • Skilled at effectively communicating with a broad range of audiences (executives, technical teams, non-technical business partners)

  • Advanced skills in the areas of project management and implementing initiatives including proven experience with control frameworks and certifications such as NIST CSF, DirectTrust, HITRUST, SOC-2, EHNAC, etc.

  • Strong decision-making skills.

  • Experience with educating the workforce on current risk/information security policies, standards, and procedures to ensure understanding.

  • Ability to effectively communicate business risk as it relates to information security.

  • Broad understanding of common risks and risk management strategies across many domains such as finance, technology, human resources, cybersecurity, competition, and environmental

  • Experience managing a risk program in the healthcare industry.

Preferred Qualifications:

  • Experience with Business Continuity Planning

  • Ability to guide governance, risk, and compliance decisions related to AI-enabled technologies, including oversight of risk assessments, controls, and policy alignment.

  • Up-to-date understanding of a wide range of incident responses, system configuration, vulnerability management and hardening guidelines

  • One or more AI cyber security certifications such as AAISM, AAIA, AAIR

  • Demonstrated ability to lead AI risk assessments, control design, and policy/standard alignment.

Keywords: risk, SOC-2, DirectTrust, HITRUST, crisis management, GRC

Surescripts embraces flexibility through its Flexible Hybrid Work model for most positions. This model allows employees to work virtually while still utilizing our offices as collaboration centers. With alignment and agreement from your leadership, you can come and go from the office as needed.

To be considered for employment, applicants must have a valid U.S. work authorization allowing work without restrictions with Surecripts in the U.S. At this time, we are unable to provide support or provide sponsorship for immigration benefits such as work visas. Additionally, we do not participate in academic training programs or work-study programs through an academic institution that require employer endorsement of F-1/CPT or F-1/STEM.

What You’re Like

You’re technical. Analytical. Imaginative. Maybe you’re building your own crypto-mining rig-or not. Either way, your mind works to anticipate vulnerabilities and protect the company and its information against those vulnerabilities. You do the right thing because it’s the right thing without seeking to point fingers or brag. And of course, you’re always willing to keep learning.

What We’re Like

We’re a team of friendly folks who do serious work. Our best work is done by rising to the occasion under stress, but we keep each other cool under pressure. We’re a tight team but we also look for ways to partner across the business. Our style is casual and laid back, but we shoulder our responsibility to protect patient data from sophisticated adversaries, which sometimes means delivering a difficult truth.

What the Work is Like

Our challenge is to protect our customers’ data and our company. This requires anomaly analysis, risk reviews, pen testing of our controls, red-teaming and tabletops, policy and procedure work, documentation, and audits. We also engineer and maintain our security products and tools. It’s not always a typical 9-to-5 gig, of course, but then again, you work in information security, so you already know that.

Why Wait? Apply Now

We’re a midsize company. This means you’re not just another employee ID number. Here, you can build real relationships and feel supported by truly awesome people with diverse backgrounds and talents in an innovative and collaborative work culture. We strive to create an environment where youcanbe yourself, share your ideas and work your way. We offer opportunities for employee development, as well as competitive compensation packages and extensive benefits.

At Surescripts, base pay is one part of our Total Rewards Package (which may also include bonus, benefits etc.) and is determined within a range. The base pay range for this position is $208,550 - $254,850 per year. Your base pay may vary within or outside of this range depending on a number of factors, including (but not limited to) your qualifications, skills, experience, and location.

Benefits include, but are not limited to, comprehensive healthcare (including infertility coverage), generous paid time off including paid childbirth and parental leave andmental health days, pet insurance, and 401(k) with company match and immediate vesting. To learn more, review the Keep You and Yours Healthy, Balancing Work and Life, and Where Talent Takes Shape links under the Better Benefits. Better Work. Better Life section of our careers site.

Physical and Mental Requirements

While performing duties of this job, an employee may be required to perform any, or all of the following: attend meetings in and out of the office, travel, communicate effectively (both orally and in writing), and be able to effectively use computers and other electronic and standard office equipment with, or without, a reasonable accommodation. Additionally, this job requires certain mental demands, including the ability to use judgement, withstand moderate amounts of stress and maintain attention to detail with, or without, a reasonable accommodation.

Work Environment

Surescripts embraces flexibility through its Flexible Hybrid Work model for most positions. This model allows employees to work virtually while still utilizing our offices as collaboration centers. With alignment and agreement from your leadership, you can come and go from the office as needed.

Surescripts is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate on the basis of race, color, religion, age, national origin, ancestry, disability, medical condition, marital status, pregnancy, genetic information, gender, sexual orientation, parental status, gender identity, gender expression, veteran status, or any other status protected under federal, state, or local law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
677,021 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Minneapolis
Remote/Hybrid • 5+ years exp • Bachelor's Degree
Python
PowerShell
AI/ML
AI Agents
DevOps
GCP
Azure
AWS
IAM
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Zero Trust
Microsoft Entra ID
Delinea
Analytics
Power BI
Apply
$80k – $100k per year • Remote/Hybrid • Contractor • 3+ years exp • San Francisco
AI/ML
Edge AI
Cybersecurity
ISO 27001
SOC 2
GDPR
HIPAA
Management
Linear
Apply
$110k – $156k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • Ann Arbor
JavaScript
TypeScript
SQL
C#
C#
ASP.NET Core
Databases
MS SQL
Frontend
React.js
DevOps
Datadog
Azure
CI/CD
AWS
Grafana
SRE
Platform Engineering
Configuration Management
Cybersecurity
ISO 27001
SOC 2
Apply
$160k – $220k per year • Equity 0–2% • In office • Full-Time • 6+ years exp • San Francisco
TypeScript
SQL
Node JS
Node JS
Nest.JS
AI/ML
vLLM
Embeddings
AI Agents
LLM
LLM Evaluation
Multi-Agent Systems
Frontend
Next.js
React.js
DevOps
Azure
Docker
Kubernetes
Cybersecurity
SOC 2
HIPAA
Management
Slack
Apply
$110k – $220k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Raleigh
Python
PowerShell
AI/ML
Red Teaming
Cybersecurity
Okta
ISO 27001
Cortex XDR
SOC 2
HIPAA
NIST 800-53
Threat Modeling
Management
Google Workspace
Apply
$93k – $114k per year • Remote/Hybrid • Full-Time • 2+ years exp • Bachelor's Degree • United States
SQL
AI/ML
Great Expectations
Synthetic Data
DevOps
Platform Engineering
Cybersecurity
HIPAA
Analytics
Collibra
Apply
$150k – $200k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • United States
Cybersecurity
HIPAA
Marketing
Salesforce
Apply
$150k – $200k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • United States
AI/ML
Copilot
Claude
Marketing
Salesforce
Apply
$82k – $100k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • United States
Cybersecurity
GDPR
HIPAA
Marketing
Salesforce
LinkedIn
Apply
$135k – $165k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • United States
DevOps
VMWare
Cybersecurity
HIPAA
Management
ServiceNow
Apply
$199k – $299k per year • Equity • In office • Full-Time • 8+ years exp • High School Diploma • Minneapolis • Irvine
Apply
$205k – $307k per year • Equity • In office • Full-Time • 15+ years exp • High School Diploma • Minneapolis
Apply
$70k – $111k per year • In office • Full-Time • 6+ years exp • Bachelor's Degree • Minneapolis • Seattle • San Francisco • Portland
Cybersecurity
Wireshark
Apply
AI Engagement Manager 6 hours ago
$129k – $193k per year • Equity • In office • Full-Time • 8+ years exp • Chicago • Reston • Seattle • Boulder • Denver
Apply
Sr Business Analyst 6 hours ago
$82k – $102k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Minneapolis
Databases
Snowflake
DevOps
AWS
Apply
See all jobs
This is one of many
677,021 more open roles from verified company boards, updated every day.