What are the responsibilities and job description for the EIT1009 - ENT DIRECTOR GRC - 1 position at Envision Healthcare?
Company Overview: Envision Healthcare is a leading national medical group focused on delivering high-quality care to patients when and where they need it most. You’ll find clinicians and clinical support professionals across the nation who are proud to call Envision home. We welcome teammates of every background and work in communities that reflect the racial, ethnic, gender, sexual orientation, and economic diversity of our country.
Benefits: At Envision Healthcare, we offer benefits at the speed of your life. Our wide range of health and welfare benefits allow you to choose the right ones for you and your family. Best of all, qualifying employees are eligible to enroll from day one, so you can rest easy knowing you and your loved ones are protected. Envision Healthcare offers a variety of health and welfare benefit options to help protect your health and promote your wellbeing. The benefits offered include but not limited to: Medical, Dental, Vision, Life, Disability, Healthcare FSA, Dependent Care FSA, Limited Healthcare FSA, FSAs for Transportation and Parking & HSAs.
Paid Time Off: Envision Healthcare offers paid time off, 9 observed holidays and paid family leave. You accrue Paid Time Off (PTO) each pay period and depending on your position and can earn a minimum of 20 days and up to 25 days per calendar year.
Summary
The Director, Governance, Risk and Compliance is responsible for leading and directing response efforts in support of audits and regulatory compliance assessments regarding Information Security requirements at Envision. The director will oversee the creation and implementation of policies, review current methodologies, and recommend appropriate strategies intended to mitigate Information Security risks for business systems and services Envision. The Director will provide oversight for the Security GRC team responsible for working with members of the various business lines to evaluate identified security risks to the company, whether acceptable internal controls and procedures are followed, and if risks are minimized to acceptable levels.
- Must be able to handle multiple, simultaneous tasks effectively and efficiently while maintaining a professional, courteous manner.
- Must be able to work well with others.
- Strong verbal and written communication skills required.
- Must be detail oriented and organized.
- High integrity, including maintenance of confidential information.
- Must be able to exercise good judgment and positively influence and lead others, including handling confrontations with poise and efficiency.
- Working knowledge and experience with MS office with proficiency in Excel
- Ability to work a flexible schedule, including some evenings and weekends as approved in advance.
- Ability to travel as needed (5-10%)
- Bachelor's degree or equivalent years of experience in the field of work required.
- Minimum of ten (10) years of experience working with security controls, frameworks, and regulatory requirements.
- Information Technology Audit experience required.
- Working experience and knowledge of HIPAA, NIST, SOX, PCI DSS and ISO principles, concepts, and practices. Active CISSP/CISM/CISA or equivalent security certification preferred.
If you are ready to join an exciting, progressive company and have a strong work ethic, join our team of experts! We offer a highly competitive salary and a comprehensive benefits package.
Envision Healthcare uses E-Verify to confirm the employment eligibility of all newly hired employees. To learn more about E-Verify, including your rights and responsibilities, please visit www.dhs.gov/E-Verify .
Envision Healthcare is an Equal Opportunity Employer.
- Directs employees by supporting, coaching, training, assisting with time management and performing evaluations; should conduct regular meetings with all direct reports.
- Provides strategic direction of the Security GRC program.
- Functions as the primary internal information security risk consultant to the organization, serving as an authoritative internal resource and advisor in all aspects related to security risks.
- Establishes relationships between internal teams and business line leadership.
- Sets security compliance policy, identifies events and issues with information systems and related processes, provides alternate recommendations for addressing identified risks, and supports the remediation of deficiencies.
- Communicates the status of security compliance through operational metrics, presentations, recommendations, and involvement in enterprise risk management activities and committees.
- Establishes, initiates, and oversees activities to improve security compliance with internal policies & standards and internal/external audits.
- Monitors, and advises on enterprise security compliance activities, ensuring desired results are achieved.
- Develops risk assessment programs and leads team to ensure risks to company data are identified and mitigated in a timely fashion.
- Drives and oversees the completion of vendor assessments involving company data or network, ensuring proper vetting, and understanding of security posture before contract execution.
- Assists in developing, reviewing, and implementing information security policies, standards, guidelines, procedures, and overall governance, security, risk management, and compliance strategies.