Director of Governance, Risk & Compliance jobs in United States
info-icon
This job has closed.
company-logo

Data Dimensions · 1 week ago

Director of Governance, Risk & Compliance

Data Dimensions is seeking a Director of Governance, Risk & Compliance who will report to the Chief Information Security Officer. This role is responsible for developing, implementing, and managing the organization’s governance, risk, and compliance programs, ensuring adherence to regulatory standards and overseeing the enterprise cyber risk management framework.

Information ServicesInformation TechnologySoftware
badNo H1BnoteSecurity Clearance Requirednote

Responsibilities

Lead and maintain SOC 2 and HITRUST certification programs, including readiness assessments, gap analysis, remediation planning, and audit coordination
Develop and maintain policies, procedures, and controls to meet compliance requirements
Serve as the primary liaison with external auditors and certification bodies
Design and implement a comprehensive cyber risk management program aligned with industry best practices and regulatory requirements
Conduct risk assessments, identify vulnerabilities, and recommend mitigation strategies
Maintain risk registers and provide regular reporting to executive leadership
Establish and enforce governance frameworks for information security and compliance
Ensure alignment of GRC activities with organizational objectives and regulatory obligations
Monitor emerging regulations and standards, advising leadership on potential impacts
Consult with the Chief Information Security Officer in support of senior management to ensure that security activities are taking place on an appropriate and ongoing basis
Collaborate with IT, Security, Legal, and Business teams to ensure compliance and risk management objectives are met
Provide training and awareness programs to promote compliance and risk-conscious behavior across the organization

Qualification

SOC 2 managementHITRUST managementCybersecurity frameworksRegulatory requirements knowledgeAudit processes knowledgeProject managementAnalytical skillsGRC platforms knowledgeMicrosoft Office SuiteVisio knowledgeProject knowledgeInfluencing skillsOrganizational skillsCommunication skillsTime managementIndependent work

Required

Must be at least 18 years of age
Able to read, write and speak English
Successfully pass and maintain acceptable background checks and security clearances
Bachelor's degree in Information Security, Risk Management, related field, or equivalent experience
8+ years in information security, compliance, or risk management roles
Proven experience managing SOC 2 and HITRUST programs
Strong understanding of cybersecurity frameworks (NIST, ISO 27001, etc.)
Excellent knowledge of regulatory requirements and audit processes
Strong analytical, organizational, and communication skills
Ability to work independently and influence cross-functional teams
Superior project management – must effectively develop and manage project plans
Expert time management skills

Preferred

One or more of: CISSP, CISA, CISM, CRISC certifications preferred
Knowledge of Microsoft Office Professional Suite, Project and Visio
Knowledge of GRC platforms, tooling, and automation are a plus

Company

Data Dimensions

twittertwittertwitter
company-logo
Data Dimensions provides technology-enabled services for the P&C insurance industry as well as other financial and government organizations.

Funding

Current Stage
Late Stage
Total Funding
unknown
Key Investors
HealthEdge Investment Partners
2019-12-13Acquired
2014-11-05Private Equity

Leadership Team

leader-logo
Bryan Doyle
President and CEO
linkedin
leader-logo
Cindi Benson
Chief Financial Officer
linkedin
Company data provided by crunchbase