Jobs and Careers
ST

Lead - IT Risk Management & Compliance

St. Jude Children's Research Hospital
Remote - TN, United States, United StatesRemotefull_timeVerifiedPosted 25 Jul 2025
💰 $186,160/yr($104,000/yr$186,160/yr)

About the role

About St. Jude
There’s a reason St. Jude Children’s Research Hospital consistently earns a Glassdoor Employee Choice Award and is named to its "Best Place to Work" list. At our world-class pediatric research hospital, every one of our professionals shares our commitment to make a difference in the lives of the children we serve. There is a unique bond when you are part of a team that gives their all to advance the treatments and cures of pediatric catastrophic diseases. The result is a collaborative, positive environment where everyone, regardless of their role, receives the resources, support, and encouragement to advance and grow their careers.

Job Overview
The Lead of IT Risk Management & Compliance is responsible for leading St. Jude's IT governance, risk, and compliance (GRC) program. This role will oversee the identification, assessment, and mitigation of technology risks, help ensure and track compliance with regulatory and internal standards and drive the implementation of policies and controls across the enterprise. The position requires strong leadership skills, a solid understanding of cybersecurity frameworks, and the ability to collaborate across business and technical teams to foster a risk-aware culture.

This position may be eligible for the possibility of remote work.

Job Responsibilities:

  • Identify and assess technology risks across systems, projects, and third parties to support risk-informed decision making and maintain an accurate risk register.
  • Collaborate with control owners to implement and validate security and compliance controls based on frameworks and regulations such as NIST 800-171, HIPAA, and NIST CSF.
  • Participate in the security review of significant changes and projects, ensuring risks are identified and addressed throughout the lifecycle.
  • Monitor and track the effectiveness of risk mitigations and control activities, and support the timely remediation of open findings and exceptions.
  • Supervise and manage staff that support the IT Risk management program. Provide feedback, coaching, and counseling to staff. Monitor, document, and review team performance.
  • Serve as a liaison to internal and external auditors by coordinating evidence requests, supporting walkthroughs, and facilitating control owner responses.
  • Support vulnerability response efforts by helping to risk-rank remediation campaigns, direct remediation efforts and priorities and partner with remediation teams to ensure timely remediation of the most critical vulnerabilities.
  • Develop and maintain policies, standards, and procedures that support a consistent approach to security governance and align with existing St. Jude policies as well as industry best practices.
  • Work with awareness and training team to help improve awareness and training related to the IT risk management program and institutional policies.
  • Maintain and mature security metrics to evaluate the effectiveness of the risk remediation program, patching effectiveness, and other IT risk related efforts.
  • Stay up to date with the latest security trends, threats, best practices, and cybersecurity regulations to keep the program relevant, effective and continuously improve the program.
  • Perform other duties as assigned to meet the goals and objectives of the department and institution.
  • Maintain regular and predictable attendance.


Minimum Education and/or Training:

  • Bachelor's degree in business administration, computer science, data science, information science or related field required.
  • MBA or related Masters in technology field preferred.


Minimum Experience:

  • Minimum Experience: 5+ years of demonstrable work experience in Security, IT Risk Management and Compliance, preferably in healthcare research industry.
  • Prefer at least 5 additional years of work experience in a cybersecurity leadership role.
  • Significant experience with working with IT technology (e.g. cloud, SaaS, network/server management) with an insight into IT Risk, threat actors, and attack vectors.
  • Some experience with operational management, and budget planning & management within area.
  • Proven performance in earlier role/comparable role.
  • Experience managing cross-functional, complex IT security processes/ projects.
  • Experience providing technical guidance, mentorship, management within IT cybersecurity.


Licensure, Registration and/or Certification Required by SJCRH Only:

  • Professional certifications related to IT risk management or information security, such as CRISC, CISA, CISSP, or similar to be obtained one year.


Special Skills, Knowledge and Abilities:

  • Able to draw insights from different sets of data and quickly und

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

St. Jude Children's Research Hospital

View company profile →