Director, Information Security (Governance Risk & Compliance)
Versant HealthAbout the role
Director, Information Security (Governance, Risk & Compliance)
Director, Information Security (Governance, Risk & Compliance)
Who are we?
Versant Health is one of the nation’s leading administrators of managed vision care, serving millions of our clients’ members nationwide. We are driven by our mission to help members enjoy the wonders of sight through healthy eyes and vision.
As a Versant Health associate, you can enjoy a comprehensive Total Rewards package, which includes health and dental insurance, tuition reimbursement, 401(k) with company match, pet insurance, no-cost-to-you vision insurance for you and your qualified dependents. We are also invested in your success. There are many opportunities for advancement and development throughout all stages of your career with us.
See how you can make a difference with the support of strong leadership and a team environment.
See Everything, Be Anything™.
What are we looking for?
Versant Health has a great opportunity for an experienced Governance, Risk and Compliance leader! We are seeking to hire a full-time Director, Information Security to manage our cybersecurity risk program, streamline our security policies, ensure alignment to information security frameworks and various regulatory certification requirements (including but not limited to HIPAA, HITRUST, SOC2 Type 2, etc.) and oversee security training, awareness, and development of the Versant Health workforce.
This role will report to the Sr. Vice President, Chief Information Security Officer and play a major role in shaping the future of the Versant Health Information Security program. We are looking for an experienced leader who understands security frameworks and certification requirements as well as the common controls (both technical and non-technical) needed to comply with said requirements.
The successful candidate will have demonstrated experience successfully leading Governance, Risk and Compliance team members in providing best-in-class awareness training, manage all aspects of our information security policies, and identify and track security risks through to completion.
Where you will have an impact:
• Create and maintain information security policies
• Work closely with various key stakeholders throughout the organization to prioritize initiatives and projects to mitigate risks and ensure control and policy alignment with HITRUST, SOC 2 Type 2, HIPAA, and other regulatory requirements
• Evaluate risks, understand controls and develop governance processes to support the company and articulate issues, develop consensus, raise awareness, and provide and implement solutions
• Serve as subject matter expert in supporting, leading, and providing guidance on the development, implementation, and monitoring of the enterprise Information Security controls
• Respond to customer requirements, providing relevant security responses, post discussion with internal stakeholders
• Translate business needs and regulatory requirements into risk appropriate controls to successfully implement security policies, standards, and guidelines
• Perform security risk assessments to identify gaps, come up with recommendations and drive the gaps to completion
• Establish security audit processes for various oversight/assurance needs
• Develop, maintain, assign, and oversee the controls necessary to remain HITRUST, HIPAA compliant and obtain a SOC2 type 2 certification
• Provide relevant metrics to demonstrate compliance levels with various requirements, effectiveness of awareness and training and progression of security risk mitigation overall
• Conduct proactive planning and communication to ensure the readiness and success related program audit and assessments
• Required occasional business travel (approximately 5% of travel)
• Other duties as assigned
What’s necessary to do the job?
• Must possess a minimum of 7+ years of experience in the field of Information Security, Governance Risk and Compliance, with exceptional knowledge of cyber risk best practice, models, and frameworks
• Solid competency in processes related to Information Security Governance, Risk and Compliance domains including Security Policy Management, Security Compliance Management, Risk Management, Vendor Security Risk, Business Continuity, and regulatory disclosures.
• Demonstrable interpersonal, facilitation and presentation skills to help clients/ business stakeholders navigate through complex cybersecurity and GRC challenges
• Demonstrated ability to lead, collaborate and work in a team environment enabling others to trust and grow their skills and competencies
• Experience in managing effective training and awareness programs, with demonstrable measurements and outcomes to show positive impacts of the training p
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s