Rochester Regional Health Logo

Rochester Regional Health

Manager, Governance, Risk & Compliance

Posted Yesterday
Be an Early Applicant
Remote
Hiring Remotely in USA
115K-140K Annually
Senior level
Remote
Hiring Remotely in USA
115K-140K Annually
Senior level
Lead and manage the GRC program and team across third-party risk, internal audit, compliance, and ISMS. Develop policies, run risk assessments (SOC2, ISO27001, PCI-DSS), maintain risk registers and CAPAs, manage client security questionnaires and business continuity planning, build security KPIs, and drive cross-functional compliance and improvement initiatives.
The summary above was generated by AI

Job Title: Governance Risk & Compliance Manager

Department: Information Security

Location: Remote, United States

Schedule: Days, Monday - Friday

SUMMARY

The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently.  

RESPONSIBILITIES

  • Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.

  • Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.

  • Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats. Manage CAPAs for non-compliance.

  • Define specific, assignable actions to mitigate the identified risks or exploit the opportunities. 

  • Evaluate how to embed the planned actions directly into daily operational processes.

  • Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.

  • Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.

  • Build and manage a security metrics (KPI’s) program.

  • Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.

  • Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.

  • Stay updated on applicable industry trends and regulations to ensure ISMS compliance.

  • Monitor and analyze GRC processes and systems, making recommendations for improvement.

  • Document risk reduction plan. Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).

  • Other duties as assigned.

REQUIRED QUALIFICATIONS

  • Minimum of 5 years of experience leading  Governance, Risk, and Compliance (GRC) programs.

  • Proficiency in ISO 27001

PREFERRED QUALIFICATIONS

  •  GRC certifications (e.g. CGRC, CRISC, etc)

  • A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.

  • Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.

  • Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.

  • Strong ability to analyze risk data and translate complex regulations into actionable controls.

  • Excellent communication skills to interact with stakeholders and lead team efforts.

  • Experience with 3rd party/vendor risk management processes.

  • Experience in working with sales teams to complete Requests for Proposals and security questionnaires.

  • Understanding of GRC processes such as policy management, risk assessment, and IT audits.

  • Exceptional verbal and written communication skills.

EDUCATION:

LICENSES / CERTIFICATIONS: 

PHYSICAL REQUIREMENTS:

L - Light Work - Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly; requires occasional walking, standing or squatting.

For disease specific care programs refer to the program specific requirements of the department for further specifications on experience and educational expectations, including continuing education requirements.

Any physical requirements reported by a prospective employee and/or employee’s physician or delegate will be considered for accommodations.

PAY RANGE:

$115,000.00 - $140,000.00

CITY:

Rochester

POSTAL CODE:

14624

The listed base pay range is a good faith representation of current potential base pay for a successful full time applicant. It may be modified in the future and eligible for additional pay components. Pay is determined by factors including experience, relevant qualifications, specialty, internal equity, location, and contracts.

Rochester Regional Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, predisposing genetic characteristics, marital or familial status, military or veteran status, citizenship or immigration status, or any other characteristic protected by federal, state, or local law.

Similar Jobs

Yesterday
Remote
USA
162K-209K Annually
Senior level
162K-209K Annually
Senior level
Healthtech • Social Impact
Lead Virta's Governance, Risk, and Compliance program by maturing policies, automating evidence collection with GRC platforms, managing HIPAA/HITRUST/SOC 2 compliance, supporting sales on security reviews and RFPs, conducting risk assessments, designing frictionless employee SaaS and access workflows, coordinating cross-functional security alignment including AI governance, and delivering security awareness training and executive reporting.
Top Skills: AIDrataHipaaHitrust CsfIso 42001JIRANist Ai RmfSaaSSoc 2VantaZendesk
5 Days Ago
In-Office or Remote
118K-223K Annually
Senior level
118K-223K Annually
Senior level
Healthtech • HR Tech • Insurance • Consulting
Manage and supervise the global Governance, Risk & Compliance team, oversee vendor risk management and security contract review, coordinate internal assessments and external audits across 60+ offices, support regulatory compliance (HIPAA, GDPR, CCPA), liaise with IT, Legal, Finance and executives, and drive GRC program planning, performance tracking, and targeted security training.
Top Skills: AIGrc ToolsSharepointVrm Tools
18 Days Ago
In-Office or Remote
150K-170K Annually
Senior level
150K-170K Annually
Senior level
Software
Lead security governance, risk, and compliance programs including policy and control management, audit readiness (SOC 2, ISO, GovRAMP, PCI, HIPAA, NIST), third-party risk, evidence collection, remediation tracking, metrics/dashboarding, and executive/auditor communications. Partner cross-functionally to operationalize controls, support customer security reviews, and improve GRC automation and processes.
Top Skills: CcpaControl Automation ToolsFedrampGdprGovrampGrc PlatformsHipaaIso 27001Nist 800-53Nist CsfPci DssPolicy Management PlatformsSoc 2Trust CenterVendor Risk Platforms

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account