Director of InfoSec Governance, Risk & Compliance leading enterprise-wide information security programs at Option Care Health, a leading home infusion provider.
Responsibilities
Lead the enterprise information security and IT risk management program, including identification, assessment, classification, and measurement of risks impacting healthcare operations and ePHI.
Lead the enterprise information security governance program, including development and maintenance of policies, standards, procedures, and control narratives
Lead a scalable third‑party risk management program covering security and privacy assessments, risk tiering, remediation tracking, and continuous monitoring
Lead enterprise‑wide security education and awareness programs for employees, contractors, and vendors
Develop executive‑level metrics and dashboards translating technical risk into business‑relevant insights
Present security risk, compliance posture, and investment needs to leadership
Provide governance oversight for incident response and lead enterprise tabletop exercises
Expand Data Governance program in alignment with privacy and compliance
Support the AI Governance Committee with effective implementation of governance controls around enterprise AI use
Maintain and govern the InfoSec and IT risk register, including risk ownership, treatment plans, exception handling, and align with Enterprise Risk Management.
Develop and maintain key risk and performance metrics (KRIs/KPIs), dashboards, and trend analyses demonstrating risk posture and maturity improvements
Lead control maturity and compliance programs aligned to NIST‑CSF, SOC 2, SOX IT General Controls (ITGC), and other applicable regulatory or assurance frameworks
Coordinate external audits and assessments, serving as the primary liaison for auditors and assessors
Identify and research potential performance improvement opportunities in leveraging security benchmarks and best practices.
Lead, mentor, and develop a high‑performing GRC team.
Requirements
Bachelor’s degree required; Master’s degree preferred in relevant field.
10+ years of progressively responsible experience in information security, IT and InfoSec risk, governance, compliance, metrics, business continuity, and training.
5+ years direct management experience leading InfoSec and/or IT GRC Teams
Experience managing third‑party risk, business continuity programs, and security training initiatives
Demonstrated experience managing enterprise information security risk, NIST‑aligned programs, SOC 2, and SOX ITGC environments
Proven success implementing metrics‑driven GRC programs at scale
Experience with GRC tooling, continuous control monitoring, M&A security due diligence, and AI governance programs
Demonstrated experience with HIPAA Security Rule implementation and HITRUST CSF alignment.
Business acumen with an ability to explain to business leaders security initiatives, programming and impact
Exceptional written, verbal, and public speaking skills.
Benefits
Medical, Dental, & Vision Insurance
Paid Time off
Bonding Time Off
401K Retirement Savings Plan with Company Match
HSA Company Match
Flexible Spending Accounts
Tuition Reimbursement
myFlexPay
Family Support
Mental Health Services
Company Paid Life Insurance
Award/Recognition Programs
Job title
Director – InfoSec Governance, Risk and Compliance
Chef Formation Conformité supervisant activités de formation conformité dans l’industrie pharmaceutique. Gestion du programme de formation et conformité aux exigences réglementaires.
Responsable de la conformité et des systèmes qualité au sein de Pharmascience sur le site de Candiac. Participation à la gestion des audits internes et des systèmes qualité pour assurer la conformité.
Lead regulatory affairs strategies ensuring compliance for pharmaceutical submissions. Collaborate with cross - functional teams and regulatory authorities for product development success.
Spécialiste en conformité et systèmes qualité gérant les systèmes qualité pour Pharmascience. Gestion des audits, déviations, et spécifications sur le site de Candiac.
Compliance & Risk Consultant involved in supporting regulatory projects within financial sector. Collaborating with experienced consultants to improve compliance processes and risk management.
Airworthiness Directive Compliance Specialist responsible for managing compliance with FAA Airworthiness Directives at Frontier Airlines. Overseeing the Airworthiness Directive management system with maintenance organization activities.
QMS & Compliance Officer at Pharmathen Pharmaceuticals, overseeing Quality Management System and ensuring compliance. Engaging in audits, training, document control, and cross - functional collaboration.
Compliance LOB Senior Advisor assessing regulatory risk for AUB Lines of Business. Advising on compliance risks and consulting with business units for effective controls in Richmond, VA.
Consultant supporting infrastructure funding and compliance for North American clients. Involves analytical tasks, project delivery, and client collaboration in capital planning.
Compliance Nurse reviewing Medicaid case management activities to ensure policy adherence. Analyzing data and conducting audits for compliance while supporting operational metrics and team success.