Director of InfoSec Governance, Risk & Compliance leading enterprise-wide information security programs at Option Care Health, a leading home infusion provider.
Responsibilities
Lead the enterprise information security and IT risk management program, including identification, assessment, classification, and measurement of risks impacting healthcare operations and ePHI.
Lead the enterprise information security governance program, including development and maintenance of policies, standards, procedures, and control narratives
Lead a scalable third‑party risk management program covering security and privacy assessments, risk tiering, remediation tracking, and continuous monitoring
Lead enterprise‑wide security education and awareness programs for employees, contractors, and vendors
Develop executive‑level metrics and dashboards translating technical risk into business‑relevant insights
Present security risk, compliance posture, and investment needs to leadership
Provide governance oversight for incident response and lead enterprise tabletop exercises
Expand Data Governance program in alignment with privacy and compliance
Support the AI Governance Committee with effective implementation of governance controls around enterprise AI use
Maintain and govern the InfoSec and IT risk register, including risk ownership, treatment plans, exception handling, and align with Enterprise Risk Management.
Develop and maintain key risk and performance metrics (KRIs/KPIs), dashboards, and trend analyses demonstrating risk posture and maturity improvements
Lead control maturity and compliance programs aligned to NIST‑CSF, SOC 2, SOX IT General Controls (ITGC), and other applicable regulatory or assurance frameworks
Coordinate external audits and assessments, serving as the primary liaison for auditors and assessors
Identify and research potential performance improvement opportunities in leveraging security benchmarks and best practices.
Lead, mentor, and develop a high‑performing GRC team.
Requirements
Bachelor’s degree required; Master’s degree preferred in relevant field.
10+ years of progressively responsible experience in information security, IT and InfoSec risk, governance, compliance, metrics, business continuity, and training.
5+ years direct management experience leading InfoSec and/or IT GRC Teams
Experience managing third‑party risk, business continuity programs, and security training initiatives
Demonstrated experience managing enterprise information security risk, NIST‑aligned programs, SOC 2, and SOX ITGC environments
Proven success implementing metrics‑driven GRC programs at scale
Experience with GRC tooling, continuous control monitoring, M&A security due diligence, and AI governance programs
Demonstrated experience with HIPAA Security Rule implementation and HITRUST CSF alignment.
Business acumen with an ability to explain to business leaders security initiatives, programming and impact
Exceptional written, verbal, and public speaking skills.
Benefits
Medical, Dental, & Vision Insurance
Paid Time off
Bonding Time Off
401K Retirement Savings Plan with Company Match
HSA Company Match
Flexible Spending Accounts
Tuition Reimbursement
myFlexPay
Family Support
Mental Health Services
Company Paid Life Insurance
Award/Recognition Programs
Job title
Director – InfoSec Governance, Risk and Compliance
Director or Sr. Director, FCM Compliance responsible for compliance program oversight and regulatory engagement at NinjaTrader. Position requires strong background in futures compliance and CFTC regulations.
Trade Compliance Specialist responsible for export compliance activities and collaboration with internal and external partners. Join Entegris' team in Billerica or Chaska, promoting growth and compliance integrity.
Labour Compliance Manager ensuring organization complies with employment legislation across the UK and Europe. Overseeing audits and maintaining high ethical standards in labour practices throughout data centre construction projects.
Compliance and Risk Consultant providing flexible support across Support Desk and Quality Control functions at PG&E. Engaging in data analysis, quality checks, and process improvement initiatives.
Managing Director overseeing strategic development of technology solutions for Fixed Income, Equities and Compliance at TIAA. Ensuring technological infrastructure supports trading operations and regulatory compliance.
Business Compliance Officer supporting Front Office on regulatory compliance at innovative Blockchain Banking firm. Involve in transaction monitoring and onboarding processes with dynamic team.
Chemical Compliance Lead at BD managing a team and overseeing compliance regulations. Collaborating with stakeholders to ensure regulations are met while driving improvements in compliance processes.
Facilities Coordinator providing administrative and compliance support for healthcare management operations. Ensuring documentation accuracy and regulatory readiness for healthcare accreditation and compliance standards.
Regulatory Affairs Specialist completing customer product and plant questionnaires for food and feed products. Ensuring accurate regulatory information and collaborating with internal stakeholders at Corbion.
Senior Compliance Manager at ControlExpert, leading compliance across the company and ensuring adherence to regulations in the automotive claims sector.