AVP, IT Security & Compliance - Plano, TX
Welltower Inc.About the role
WELLTOWER – REIMAGINE REAL ESTATE WITH US
At Welltower, we’re transforming how the world thinks about senior living and wellness-focused real estate. As a global leader in residential wellness and healthcare infrastructure, we create vibrant, purpose-driven communities where housing, healthcare, and hospitality converge. Our culture is fast-paced, collaborative, and endlessly ambitious—guided by our mantra: The only easy day was yesterday.
We’re looking for bold, independent thinkers who thrive on challenge, embrace complexity, and are driven to deliver long-term value. Every team member is empowered to think like an owner, innovate fearlessly, and lead from where they stand. If you're passionate about outcomes and inspired by the opportunity to shape the future of healthcare infrastructure, we want you on our best-in-class team.
ABOUT THE ROLE
The AVP of IT Security and Compliance will be responsible for developing, implementing, and overseeing a comprehensive enterprise information security and compliance program across Welltower’s operations. This role will ensure the protection of corporate data, technology assets, and systems while maintaining compliance with public company requirements, including SOX and ITGC controls. The VP will lead the cybersecurity strategy, governance, risk, and compliance (GRC) initiatives, and ensure alignment with business objectives and regulatory standards.
KEY RESPONSIBILITIES
Cybersecurity Leadership
- Lead the company’s enterprise cybersecurity strategy and framework to protect critical information, infrastructure, and systems across all business units.
- Oversee the design and operation of security architecture, network defense, and endpoint protection programs.
- Implement proactive threat detection, incident response, and vulnerability management initiatives.
- Partner with business units and external partners to mitigate cybersecurity risks in vendor and third-party relationships.
Governance, Risk, and Compliance (GRC)
- Develop and manage the IT Governance, Risk, and Compliance (GRC) program, ensuring alignment with regulatory and internal control requirements.
- Oversee compliance with SOX ITGC (Information Technology General Controls), working closely with Internal Audit and Finance to maintain effective testing and documentation processes.
- Drive continuous improvement of IT policies, procedures, and controls in accordance with best practices and evolving standards.
- Ensure compliance with data privacy and information security regulations (e.g., HIPAA, GDPR, CCPA).
Strategic Leadership & Collaboration
- Serve as the company’s senior leader and subject matter expert on cybersecurity, IT risk, and compliance.
- Advise executive leadership and the Board of Directors on emerging cyber risks, regulatory changes, and strategic initiatives.
- Develop and lead security awareness programs for all employees to foster a strong culture of compliance and accountability.
- Manage relationships with external auditors, consultants, and regulators.
Team Leadership
- Build and lead a high-performing IT security and compliance team.
- Promote professional development and mentorship to ensure continuous capability enhancement.
- Partner with IT infrastructure and application teams to embed security and compliance into the technology lifecycle.
OTHER DUTIES
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of this employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
TRAVEL
Out-of-area and overnight travel should be expected as outlined in specific projects for which this role will engage.
MINIMUM REQUIREMENTS
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field; Master’s degree preferred.
- 10–15 years of progressive IT security and compliance experience, with at least 5 years in a senior leadership role.
- Deep knowledge of cybersecurity frameworks (NIST, ISO 27001, CIS), SOX 404, ITGC, and enterprise GRC platforms.
- Proven experience managing cybersecurity programs in a publicly traded environment.
- Strong understanding of cloud security, identity management, and third-party risk management.
- Professional certifications strongly preferred (CISSP, CISM, CISA, CRISC, or equivalent).
- Exceptional communication skills with the ability to influence executives and board members.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s