Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
HF
Henry Ford Health
Lead-GRC IT Audit & Readiness
Career Insights for IT Auditor
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Michigan data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An IT Auditor monitors IT systems to ensure they follow policies and practices. Must evaluate technology, manage staff, identify controls, and keep records.
$125,231 / year median in Michigan
-7% projected decline
Job Description
Lead-GRC IT Audit & Readiness Henry Ford Health - 3.8 Troy, MI Job Details Full-time 1 day ago Benefits Health insurance Qualifications Project reporting Certified Information Systems Auditor Computer science Staff supervision Internal controls Computer Science Team supervision Information security audit implementation Tooling Program development CISSP Governance, risk, and compliance (GRC) software
SOC 2 HIPAA
Performance Reporting Information Systems Metrics Reporting Project communication management State healthcare regulations CISM Policy & process development Bachelor's degree Change management for system development Task prioritization System validation Industry trends System testing Healthcare privacy protection IT control testing Security Governance (information security management) Full Job Description Company Description Henry Ford Health partners with millions of people on their health journey, across Michigan and around the world. We offer a full continuum of services from primary and preventative care to complex and specialty care, health insurance, a full suite of home health offerings, virtual care, pharmacy, eye care and other health care retail. With former Ascension southeast Michigan and Flint region locations now part of our team, Henry Ford's care is available in 13 hospitals and hundreds of ambulatory care locations. Based in Detroit, Henry Ford is one of the nation's most respected academic medical centers and is leading theFuture of Health:
Detroit, a $3 billion investment anchored by a reimagined Henry Ford academic healthcare campus. Job Description About theRole:
The Lead-Governance, Risk, and Compliance (GRC) Information Technology (IT) Audit & Readiness reports to the IT Security Compliance Manager within the Cybersecurity Governance, Risk, and Compliance (CGRC) organization and collaborates with Information Privacy and Security Office (IPSO) and IT team members to facilitate IT audits. These audits includeSOC 1, SOC
2, General IT Controls, and other compliance assessments.Key Tasks and Duties:
Able to develop work with minimal supervision, maintain and report against a work plan, give appropriate updates and status reports, and serve as a point of contact and liaison with internal and external auditors, assessors, vendors and clients and assist other staff members. Provide Governance Risk and Compliance (GRC) support for third-party audit requests and reporting requests from leadership. Lead coordination and facilitation of IT audits (internal and external), acting as the central point of contact between auditors and internal stakeholders Drive the collection, review, and organization of audit evidence to ensure accuracy, completeness, and timely delivery Advise and partner with control owners to support audit readiness, including guidance on documentation, control execution, and remediation efforts Serve as the primary project coordinator for audit, compliance, and risk management activities, ensuring milestones, deadlines, and objectives are achieved. Establish and manage integrated audit and compliance plans, coordinating resources, timelines, dependencies, and deliverables across multiple initiatives. Champion use of GRC tools to manage audit workflows, extract evidence, and monitor control performance and compliance status Lead communication of audit requirements, follow-ups, and status updates clearly to internal teams and external auditors Develop, maintain, and monitor operational and strategic metrics to measure audit performance, compliance effectiveness, control health, and program maturity. Build and maintain relationships with key stakeholders across IPSO, Information Technology and business teams Monitor emerging regulatory requirements, industry trends, security frameworks, and best practices, providing guidance and recommendations to strengthen the organization's compliance posture. Provide day-to-day leadership and guidance to GRC Specialists, prioritizing work, removing barriers, and ensuring consistent execution of program objectives. Act as a subject matter expert and trusted advisor on audit coordination, compliance processes, GRC tools, and control governance. Execute GRC tool system test plans as necessary (ex. For system upgrades, updates, enhancements, new reporting). Participate in continuous learning initiatives specifically related to the GRC system, IT governance, controls, insurance, healthcare, leading security frameworks, and information technology. Supports Henry Ford Health as well as its subsidiaries.Qualifications Education & Experience:
Bachelor's degree in Accounting, Information Systems, Computer Science or related field preferred, relevant work experience/certification considered. Four plus (4+) years of experience in IT risk, IT Controls or IT Audit. Demonstrates strong and effective verbal, written, and interpersonal communication skills, with experience in all at the executive level. Ability to prioritize and multi-task in a dynamic, fast-paced, and challenging environment. Experience with federal and state healthcare information regulations and requirements (e.g. HIPAA) preferred. Advanced knowledge of IT systems and functions, process development, change management, and service and implementation lifecycle. Knowledge of information security best practices, NIST Cybersecurity Framework , and common risk frameworks. Can conform to shifting priorities, demands and timelines through analytical and problem-solving capabilities.Certifications:
CISSP, CISA, CISM
preferred.Benefits
- Health Insurance
- Dental Insurance