Director, IT Security & Compliance - Remote
Job
Sharecare
Remote
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
79
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
Job Description:
- Sharecare is a digital healthcare company that delivers software and tech-enabled services to stakeholders across the healthcare ecosystem to help improve care quality, drive better outcomes, and lower costs.
Job Summary:
- The Director of IT Security Compliance is responsible for leading and managing enterprise-wide security compliance, IT audit, and third-party risk management initiatives.
Essential Job Functions:
- Certification & Audit Management
- + Lead and manage all external certification audit processes, including ISO 27001, HITRUST, and
SOC 1 / SOC 2.
+ Serve as the primary point of contact for external auditors, certification bodies, and IT audit firms. + Oversee IT audit readiness activities, including control design, documentation, and evidence management. + Coordinate internal stakeholders to ensure timely and successful audit execution. + Respond to client-driven audits and due diligence requests across all business lines.- IT Audit Oversight & Governance
- + Lead internal and external IT audit engagements, including planning, scoping, execution support, and reporting.
- Third-Party Risk Management (TPRM)
- + Define and lead the enterprise third-party risk management program. + Establish processes to assess and tier vendor risk based on data sensitivity, access, and business impact. + Evaluate vendor risk through: + Business owner-completed risk assessments + Vendor-provided certifications (e.g., SOC 2, HITRUST) + Independent vendor security scorecards + Leverage GRC tools to calculate and track
- inherent risk and residual risk
- for all vendors.
- Corrective Action & Findings Management
- + Define, implement, and manage the internal corrective action plan (CAP) process. + Track and drive remediation of findings from: + IT audits (internal and external) + Client audits + Penetration tests + Risk assessments + Vendor risk assessments + Ensure timely closure of identified gaps and maintain appropriate audit-ready documentation.
- Risk Assessment & Compliance Processes
- + Develop, implement, and oversee internal risk assessment processes aligned with certification and audit requirements. + Evaluate IT general controls (ITGCs), application controls, and security controls. + Identify control gaps and provide remediation strategies aligned with audit expectations.
- Continuous Improvement
- + Define and execute strategies for continuous improvement of compliance, audit, and third-party risk processes. + Enhance control frameworks, documentation quality, and audit efficiency. + Monitor evolving regulatory, audit, and industry requirements.
- Client & RFP Support
- + Respond to external audit requests, security questionnaires, and RFPs across all business units. + Translate audit and compliance posture into clear, client-facing responses. + Partner with sales, legal, and operational teams to support business growth.
- Access Management Oversight
- + Execute and oversee the quarterly user access review process. + Ensure compliance with ITGC access control requirements. + Validate adherence to least privilege and segregation of duties (SoD).
- KPI Development & Performance Management
- + Define, implement, and monitor KPIs for compliance, audit, and third-party risk processes. + Develop dashboards to track audit readiness, vendor risk posture, control effectiveness, and remediation progress. + Provide regular reporting to executive leadership and stakeholders.
Qualifications:
- + Bachelor's degree in Information Security, Information Technology, Accounting, or related field (or equivalent experience).
Preferred:
- + Professional certifications such as: + CISA (Certified Information Systems Auditor) + CISSP, CISM, or CRISC + Experience working with internal audit teams or public accounting firms.
Sharecare is an Equal Opportunity Employer and doesn't discriminate on the basis of race, color, sex, national origin, sexual orientation, gender identity, religion, age, disability, genetic information, protected veteran status,or other non-merit factor.
Similar remote jobs
International Foundation of Employee Benefit Plans
Brookfield, WI
Posted2 days ago
Updated1 day ago
Similar jobs in Augusta, ME
Similar jobs in Maine
CVS Health
Augusta, ME
Posted2 days ago
Updated1 day ago