Jobs and Careers
HE

Senior Director, Security Governance Risk and Identity

Healthmap Solutions
United States, United StatesRemotefull_timeVerifiedPosted 22 Jul 2026

About the role

Position Summary:
The Senior Director, Security Risk Governance and Identity will oversee and coordinate Healthmap’s governance, risk, and compliance (GRC) activities in relation to data protection, IT audit, and information security.  In addition will be accountable for the lifecycle, security, and governance of digital identities—both human (employees, contractors, customers) and non-human (bots, service accounts, IoT). This position will report directly to the Chief Information Security Officer while leading a team responsible for risk management, governance and data security and identity management. This role addresses all aspects of administration, enforcement, compliance, education, investigation, and contingency planning related to information security in alignment with stakeholders in IT, Privacy Legal, Sales and Clinical teams to ensure Healthmap Solutions rigorous data control standards are met. In this role, you will be expected to direct staff who will manage GRC and Identity security related activities. This role is a hands-on security leader role with the expectation that work will vary between strategic and operational.
 
Responsibilities: 
  • Serve as a bridge between technical teams (like IT and Security) and executive leadership, turning complex risk landscapes into clear business insights
  • Implement measures and governance frameworks to manage data use in compliance with laws and regulations
  • Develop, enhance, operationalize enterprise-level information security, IT security policies and procedures and controls to mitigate risk and comply with applicable laws and regulations
  • Lead use of and overall adoption of HITRUST Common Security Framework (CSF) to ensure and maintain continued certification and SOC2 Type II reporting
  • Identify, track, monitor and report on Information Security controls providing recommendations and remediation strategies to stakeholders when appropriate
  • Monitor the regulatory and statutory landscape on GRC and data security issues, keeping Healthmap personnel and senior leadership apprised of any relevant developments impacting the company’s business goals and objectives, and recommending appropriate courses of action as needed
  • Review projects, business critical systems and provide guidance and work with process owners to identify and remediate control weaknesses to ensure compliance with regulatory requirements and ensure client contractual commitments and industry best practices
  • Maintain IT/Security questionnaires and associated client required audit and assessment activities
  • Direct Disaster Recovery planning and testing to ensure recovery strategies meet or exceed business resiliency requirements and align with strategic objectives
  • Direct and manage our 3rd Party Risk Management program to ensure that vendors comply with all relevant security regulations, standards, and best practices
  • Monitor vendor security performance and identify areas for improvement. Work collaboratively with other functions, including Legal, Privacy, Finance and, IT and the business to ensure proper use of vendors to achieve strategic goals
  • Manage client inquiries regarding information security controls and curate and maintain approved documentation to demonstrate adherence to proper data security governance
  • Draft and manage content for the Information Security training of all employees and contractors
  • Direct and manage staff ensuring coach, development and performance management is in alignment with department goals, ensuring key performance metrics are attained and adjusting efforts to ensure target attainment
  • Define a multi-year roadmap for IAM, including transitioning to modern frameworks like Zero Trust and Passwordless Authentication
  • Oversee Identity Governance and Administration (IGA) processes—managing joiners, movers, and leavers to ensure least-privilege access across the entire enterprise
  • Manage Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Adaptive Access policies that determine how users log in and what context-aware security checks are applied
  • Secure high-risk "keys to the kingdom" for administrators and service accounts to prevent lateral movement during a breach
  • Oversee the security and user experience of customer-facing identity (e.g., social login, profile management, and secure registration flows)
  • Perform other duties as assigned

Requirements:

  • Bachelor’s degree in cyber security (or) related degree or equivalent work experience
  • 10-15 years’ experience in Information Security which includes 7 years’ experience managing and leading staff in an GRC discipline and Identity.  Or other areas of cyber security

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Healthmap Solutions

View company profile →