Assistant Vice President – Governance, Risk & Compliance

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of CVS Health

CVS Health

10,000+ employees

Founded 1963

🏥 Healthcare

⚕️ Healthcare Insurance

🛒 Retail

Healthcare • Healthcare Insurance • Retail

CVS Health is a leading American healthcare company dedicated to improving health access and affordability. The company focuses on a comprehensive approach that includes health services, health insurance, and pharmacy benefits management. Through its subsidiaries, such as Aetna and CVS Caremark, CVS Health offers a range of services that facilitate wellness, condition management, and affordable prescription drug coverage. CVS Health operates neighborhood pharmacies, provides mail-order pharmacy services, and manages specialty medication programs, aiming to make healthcare convenient and accessible for everyone. Driven by a mission to connect people with essential care services, CVS Health is committed to fostering healthier communities and supporting the wellbeing of all individuals.

📋 Description

• Lead CVS Health's enterprise information security governance, risk, technology compliance, and regulatory compliance strategy • Drive the cybersecurity risk assessment program, including identification, quantification, tracking, remediation, and executive reporting of risk • Modernize and automate GRC capabilities through evidence reuse, automated control testing, and AI-assisted risk quantification and reporting • Ensure compliance with healthcare cybersecurity regulations, industry requirements, and applicable control frameworks • Own enterprise technology compliance for cybersecurity controls, configurations, and platforms • Direct the lifecycle of enterprise information security policies, standards, and procedures • Serve as primary GRC liaison to Internal Audit, external auditors, and regulators • Oversee SOX cybersecurity and IT general control support • Lead SOC 1 and SOC 2 readiness and attestation support • Own the security exception and risk acceptance process • Establish and lead enterprise AI risk governance • Align the enterprise risk framework, control taxonomy, and reporting with the vendor risk program • Build partnerships with internal and external stakeholders to advance risk and compliance objectives • Prepare and deliver cybersecurity risk posture reporting to the Board Risk/Audit Committee and executive governance forums • Manage and mature GRC tooling and platforms • Lead and develop the GRC team, succession planning, continuous improvement, and organizational transformation

🎯 Requirements

• Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent professional experience • 10+ years of progressive experience in information security, IT risk management, or regulatory compliance • 5+ years in a leadership role • Deep knowledge of HITRUST CSF, SOX IT general controls, SOC 1/SOC 2, NIST CSF, ISO 27001, and related cybersecurity control frameworks • Experience building or scaling an enterprise GRC program, including risk assessment and policy management • Hands-on experience with GRC platforms and risk quantification/reporting tools, including automation and evidence reuse • Ability to communicate risk and compliance matters to executive leadership, Board committees, auditors, and regulators • Executive presence and ability to influence senior leaders • Experience partnering with Internal Audit and managing external regulatory examinations • Experience supporting SOX control testing, SOC readiness or attestation, audit evidence collection, control deficiency remediation, and executive-level compliance reporting • Experience in a matrixed, multi-business-unit enterprise • Ability to lead through influence and build trusted relationships across internal and external partner groups • Enterprise people leadership and talent management experience • Preferred: advanced degree (MBA or MS) or JD with cybersecurity and risk focus • Preferred: CISSP, CISM, CISA, CRISC, or CIPP certification • Preferred: experience in healthcare, pharmacy, health insurance, or retail • Preferred: experience with AI governance, model risk management, or emerging AI regulation • Preferred: familiarity with SEC cybersecurity disclosure requirements and materiality assessment processes

🏖️ Benefits

• CVS Health bonus, commission or short-term incentive program in addition to base pay • Award target in the company’s equity award program • Medical coverage • Dental coverage • Vision coverage • Paid time off • Retirement savings options • Wellness programs • Other resources supporting physical, emotional, and financial well-being

Apply Now

Similar Jobs

🔥 13 hours ago

LeonaBio

51 - 200

🧬 Biotechnology

💊 Pharmaceuticals

🏥 Healthcare

Regulatory strategy director advancing LeonaBio’s ALS and metastatic breast cancer therapeutics toward FDA and EU applications. Leading health authority interactions, submissions, and registration-enabling development strategies.

🇺🇸 United States – Remote

💵 $220k - $260k / year

💰 $103.5M Post IPO equity on 2021-02

⏰ Full Time

🔴 Lead

🚔 Compliance

🔥 16 hours ago

GE HealthCare

10,000+ employees

🏥 Healthcare

💊 Pharmaceuticals

Regulatory Affairs Manager guiding global labeling and US FDA submissions for GE HealthCare’s medical technologies. Coordinating CCDS, regional implementation, governance, and commercialization support.

🔥 18 hours ago

Gauntlet

11 - 50

💼 Consulting

📦 Logistics

₿ Crypto

Head of Compliance building scalable regulatory programs for Gauntlet’s onchain financial products. Leading policies, controls, monitoring, registrations, audits, and cross-functional compliance operations.

🔥 20 hours ago

IGS Energy

1001 - 5000

⚡ Energy

🛍️ eCommerce

Director leading legislative and regulatory strategy for IGS Energy, a U.S. and Canadian energy retailer. Advancing solar, storage, and distributed-energy policies supporting business growth.

🕒 Yesterday

Inframark

1001 - 5000

🤝 B2B

🏛️ Government

💼 Consulting

Environmental compliance manager overseeing regulatory programs for water and wastewater facilities. Conducting audits, corrective actions, inspections, reporting, and staff training.