Senior Director, Security Governance Risk and Identity
Description
Company Background
Healthmap Solutions is the future of specialty health management that focuses on progressive diseases, with a particular expertise in kidney health populations. Healthmap Solutions uses clinical big data resources and high-powered analytics to power complex specialty health management programs. Healthmap Solutions is a diverse, growing company committed to our clients and our employees. We are champions for better health, for those who need us most.
Position Summary:
The Senior Director, Security Risk Governance and Identity will oversee and coordinate Healthmap’s governance, risk, and compliance (GRC) activities in relation to data protection, IT audit, and information security. In addition will be accountable for the lifecycle, security, and governance of digital identities—both human (employees, contractors, customers) and non-human (bots, service accounts, IoT). This position will report directly to the Chief Information Security Officer while leading a team responsible for risk management, governance and data security and identity management. This role addresses all aspects of administration, enforcement, compliance, education, investigation, and contingency planning related to information security in alignment with stakeholders in IT, Privacy Legal, Sales and Clinical teams to ensure Healthmap Solutions rigorous data control standards are met. In this role, you will be expected to direct staff who will manage GRC and Identity security related activities. This role is a hands-on security leader role with the expectation that work will vary between strategic and operational.
Responsibilities:
- Serve as a bridge between technical teams (like IT and Security) and executive leadership, turning complex risk landscapes into clear business insights
- Implement measures and governance frameworks to manage data use in compliance with laws and regulations
- Develop, enhance, operationalize enterprise-level information security, IT security policies and procedures and controls to mitigate risk and comply with applicable laws and regulations
- Lead use of and overall adoption of HITRUST Common Security Framework (CSF) to ensure and maintain continued certification and SOC2 Type II reporting
- Identify, track, monitor and report on Information Security controls providing recommendations and remediation strategies to stakeholders when appropriate
- Monitor the regulatory and statutory landscape on GRC and data security issues, keeping Healthmap personnel and senior leadership apprised of any relevant developments impacting the company’s business goals and objectives, and recommending appropriate courses of action as needed
- Review projects, business critical systems and provide guidance and work with process owners to identify and remediate control weaknesses to ensure compliance with regulatory requirements and ensure client contractual commitments and industry best practices
- Maintain IT/Security questionnaires and associated client required audit and assessment activities
- Direct Disaster Recovery planning and testing to ensure recovery strategies meet or exceed business resiliency requirements and align with strategic objectives
- Direct and manage our 3rd Party Risk Management program to ensure that vendors comply with all relevant security regulations, standards, and best practices
- Monitor vendor security performance and identify areas for improvement. Work collaboratively with other functions, including Legal, Privacy, Finance and, IT and the business to ensure proper use of vendors to achieve strategic goals
- Manage client inquiries regarding information security controls and curate and maintain approved documentation to demonstrate adherence to proper data security governance
- Draft and manage content for the Information Security training of all employees and contractors
- Direct and manage staff ensuring coach, development and performance management is in alignment with department goals, ensuring key performance metrics are attained and adjusting efforts to ensure target attainment
- Define a multi-year roadmap for IAM, including transitioning to modern frameworks like Zero Trust and Passwordless Authentication
- Oversee Identity Governance and Administration (IGA) processes—managing joiners, movers, and leavers to ensure least-privilege access across the entire enterprise
- Manage Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Adaptive Access policies that determine how users log in and what context-aware security checks are applied
- Secure high-risk "keys to the kingdom" for administrators and service accounts to prevent lateral movement during a breach
- Oversee the security and user experience of customer-facing identity (e.g., social login, profile management, and secure registration flows)
- Perform other duties as assigned
Requirements:
- Bachelor’s degree in cyber security (or) related degree or equivalent work experience
- 10-15 years’ experience in Information Security which includes 7 years’ experience managing and leading staff in an GRC discipline and Identity. Or other areas of cyber security
- Certified Information Security Systems Professional (CISSP), Certified Information Security Manager (CISM) or Global Information Assurance Certifications (GIAC) certifications are preferred
- Managing risk scoring methodologies to establish risk scores against risk appetite
- Experience managing non-IT and outside vendor partner staff to achieve GRC goals and objectives
- Experience reviewing contracts and managing audit activities both as assessor and assessed. Healthcare and HITRUST v11 experience
- Performing Information Security/Information Technology risk assessments experience
- Ability to align security and compliance objectives with the broader business goals and growth strategy
- Proven track record of scaling GRC programs, often using tools like ServiceNow GRC, Archer, or OneTrust
- Deep knowledge of frameworks such as NIST, ISO 27001, and various regional/industry-specific regulations
- Effectively partnering with Legal, HR, Finance, and IT to embed risk management into day-to-day operations
- Leading teams to automate access request workflows to reduce manual overhead and human error
- Experience with enterprise platforms like MS Azure, Sailpoint, Ping etc.
- Hands on experience with Access Management workflows for all identity transactions (Moves, Adds, Tranfers, and Changes)
Skills:
- Excellent program team building, leadership, and people management skills
- Strong executive presence to translate technical risk into "business language" for non-technical stakeholders
- Ability to influence cross-functional teams (HR, IT, Engineering) to adopt new processes without disrupting business velocity
- Ability to effectively prioritize and execute tasks in a high-pressure environment
- Excellent Customer service skills
- Calm and confident under pressure
- Collaboration and Conflict management
Travel:
Limited Travel, scheduled per needs of the business
Working Conditions:
All roles require:
• Sitting
- Ability to sit for extended periods stationary or while driving
• Dexterity/Effort
- Repetitive motion for typing and/or texting
- Good manual dexterity for handling packages, paperwork, operation of motor vehicles and/or electronic devices
• Sense Acuity
- Ability to see/read computer monitors or other electronic devices
Additionally, on-site or at location positions (ex. Mailroom, IT or Admin) may require:
• Lift/Carry/Push/Pull
- Occasional movement of equipment, or materials up to 50/75 Pounds
• Bend/Twist
- Occasional bending, twisting, and stooping
- Occasional need to kneel or crouch
Additionally Traveling positions (ex. Field Care Navigators or Quality Practice Advisors) may require:
• Sense Acuity
- Ability to see/read road signs, maps, and electronic devices
- Good visual acuity for driving, including peripheral vision and depth perception
• Environmental
- Possible exposure to travel, traffic and/or other outdoor hazards
- Possible exposure to various weather conditions, including extreme heat, cold, rain, and snow
#LI-REMOTE
Americans with Disability Specifications
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
As an Equal Opportunity Employer, we will not discriminate against any job candidate or employee due to age, race, religion, ethnicity, national origin, gender, gender identity/expression, sexual orientation, disability, familial status, veteran status, marital status, parental status, or pregnancy. In our innovative and inclusive workplace, we prohibit discrimination and harassment of any kind.
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
As an Equal Opportunity Employer, we will not discriminate against any job candidate or employee due to age, race, religion, ethnicity, national origin, gender, gender identity/expression, sexual orientation, disability, familial status, veteran status, marital status, parental status, or pregnancy. In our innovative and inclusive workplace, we prohibit discrimination and harassment of any kind.