Program Manager, Security
DaVitaAbout the role
Posting Date
04/03/20262000 16th Street, Denver, Colorado, 80202, United States of AmericaOverview
The Program Manager, IT Risk & Audit, is an individual contributor responsible for driving enterprise‑level governance, regulatory compliance, and risk management programs across DaVita’s IT and Security landscape. This role ensures consistent execution of IT risk processes, supports internal and external audits, leads partner‑facing due diligence activities, advances governance programs, and manages the operational cadence of key security initiatives.
This role is program‑oriented — focused on the lifecycle of risk, from contracting to decommissioning, ensuring governance, compliance, and risk processes flow predictably across the enterprise.
Key Responsibilities
Governance & Program Management
Own and manage core governance programs including policy lifecycle management, standards updates, cross‑functional alignment, and coordination with Security, Privacy, Compliance, Legal, and IT.
Facilitate governance working groups and steering committees, ensuring agendas, documentation, decisions, and follow‑up actions are executed consistently.
Track and report on program‑level OKRs, compliance posture, and audit activity for leadership and committee reporting cycles.
Lifecycle Risk Management
Oversee end‑to‑end IT risk lifecycle management, ensuring risks are appropriately evaluated and managed from:
Contracting and procurement (BAA reviews, contract language alignment, partner due diligence)
Solution onboarding and implementation
Operational monitoring and oversight
System changes, exceptions, and remediation activities
System retirement/decommissioning
Maintain governance controls across each lifecycle stage to ensure consistency, documentation quality, and regulatory alignment.
Exception Management
Coordinate the intake, evaluation, documentation, approval routing, and tracking of security and compliance exceptions.
Maintain an enterprise‑wide exception repository, ensuring exceptions have defined compensating controls, expiration dates, and remediation plans.
Partner with control owners, IT teams, and leadership to ensure exception backlogs are prioritized and resolved within expected timelines.
Regulatory, Audit & Compliance Support
Coordinate SOX, HIPAA, internal audit, external audit, and regulatory assessment activities across Security, IT Overwatch, ERS, Privacy, Legal, and Finance.
Manage audit readiness activities, evidence collection, documentation updates, and remediation follow‑through (MAPs/CAPs).
Track audit findings, ensuring gaps are formally logged, assigned, monitored, and closed according to internal SLAs and regulatory expectations.
Enterprise Risk Assessment Support
Support the enterprise risk assessment process, including review of IT and cybersecurity risk assessments, validation of risk scoring, and confirmation of mitigation strategies.
Track risk‑based findings and gaps across the enterprise, ensuring they remain visible, actionable, and progress toward closure is monitored.
Provide program‑level reporting on enterprise risk themes, recurring control gaps, and opportunities for systemic improvements.
Third‑Party & Partner Assessments
Lead completion of partner questionnaires, payor and regulatory due diligence forms, RFP/RFI security sections, and vendor assessments.
Review BAAs and data‑flow related documentation to ensure alignment with DaVita’s privacy and security requirements.
Maintain reusable artifacts (response libraries, program overviews, diagrams, certifications) to streamline intake and partner interactions.
Training, Awareness & Communications
Partner with Training & Awareness to design, deliver, and update annual and targeted security/compliance training modules.
Develop internal communications for governance updates, policy changes, audit cycles, and enterprise compliance initiatives.
Contribute to phishing simulations, education campaigns, and security culture efforts across the Village.
Cross‑Functional Program Execution
Support enterprise initiatives such as:
AI governance and intake workflows
Security maturity assessments and roadmap development
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s