Overview
Concentra is recognized as the nation’s leading occupational health care company.
With more than 40 years of experience, Concentra is dedicated to our mission to improve the health of America’s workforce, one patient at a time. With a wide range of services and proactive approaches to care, Concentra colleagues provide exceptional service to employers and exceptional care to their employees.
Â
The Director, Security - GRC (Governance, Risk Management, and Compliance) will lead the efforts in maintaining compliance with various regulatory and security frameworks. This role requires a deep understanding of security, compliance, regulatory frameworks, platform management, vendor security reviews, third party risk management and customer interactions. Requires a strong ability to collaborate across functions and provide valuable insights and leadership in enhancing our security and compliance environment (s).
Responsibilities
- Create and maintain Security Compliance policiesÂ
- Perform security risk assessments to identify gaps, develop recommendations and close the gaps to completion and resolutionÂ
- Lead and maintain and Third Party Risk Management (TPRM) programÂ
- Setup Internal audit processes for various security needsÂ
- Oversee platform security compliance audits for new regions to comply with legal regulationsÂ
- Project management that includes the knowledge to initiate and drive complex security projects requiring various stakeholdersÂ
- Develop metrics to track security program effectiveness and to report riskÂ
- Create a governance program for different security areas like Infrastructure, Application, SOC and othersÂ
- Identify critical security audit areas, establish the audit process and have completed audit of few areasÂ
- Create and update security risk metrics to measure the risk levels across systems and processesÂ
- Conduct security awareness and educational trainings for the company and specific teamsÂ
- Facilitate and participate in internal audits of critical processes and as required for PCI and SOXÂ
- Complete risk assessments of high-risk processes and come up with gaps and recommendationsÂ
- Rollout security awareness trainings for the company and GRC team
Qualifications
- Education Level: Bachelor’s Degree Major: Computer Science, Information SecurityÂ
- Minimum of 8-10 years of experience related to risk managementÂ
- Three to four years of project management experienceÂ
- Experience developing GRC programs in a cloud and SaaS environment.Â
- Concentra Core Competencies of Service Mentality, Attention to Detail, Sense of Urgency, Initiative and FlexibilityÂ
- Ability to make decisions or solve problems by using logic to identify key facts, explore alternatives, and propose quality solutionsÂ
- Outstanding customer service skills as well as the ability to deal with people in a manner which shows tact and professionalismÂ
- The ability to properly handle sensitive and confidential information (including HIPAA and PHI) in accordance with federal and state laws and company policiesÂ
- Experience with privacy frameworks, such as SOX, SOC2 Type 2, PCI, NIST and HIPAAÂ
- Experience with third party risk managementÂ
- Strong collaborator, with experience working on teams composed of both technical and non technical membersÂ
- Demonstrated ability to lead large projects, problem-solve, multitask, and have excellent organizational skills
- Excellent written and verbal communication skills, with experience presenting to key stakeholders and partnering with internal collaborators and external auditorsÂ
- Thrive in a data-driven, fast-paced and innovative environmentÂ
- Strong prioritization skills and the ability to handle multiple job duties in a fast-paced environmentÂ
- Exceptional communication skills and the ability to communicate appropriately at all levels of the organization, written and verbal
Additional Data
Employee Benefits
- 401(k) Retirement Plan with Employer Match
- Medical, Vision, Prescription, Telehealth, & Dental Plans
- Life & Disability Insurance
- Paid Time Off
- Colleague Referral Bonus Program
- Tuition Reimbursement
- Commuter Benefits
- Dependent Care Spending Account
- Employee Discounts
Â
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation, if required.
Â
*This job requires access to confidential and sensitive information, requiring ongoing discretion and secure information management*
Â
Concentra is an equal opportunity employer that prohibits discrimination, and will make decisions regarding employment opportunities, including hiring, promotion and advancement, without regard to the following characteristics: race, color, national origin, religious beliefs, sex (including pregnancy), age, disability, sexual orientation, gender identity, citizenship status, military status, marital status, genetic information, or any other basis protected by federal, state or local fair employment practice laws.
Learn more about this Employer on their Career Site
