Governance, Risk & Compliance Director
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, Information Security
Overview
Since our founding in 1924, we've cut cardiovascular disease deaths in half, but there is still so much more to do. To overcome today’s biggest health challenges and accelerate this progress, we need passionate individuals like you. Join our movement, be part of the progress, and help ensure a healthier future for all. You matter, and so does the impact you can make with us.
The American Heart Association has an excellent opportunity for a Governance, Risk & Compliance Director
.
The Governance, Risk & Compliance Director will serve as the subject matter expert responsible for developing and implementing the organization's cybersecurity operations, enterprise governance, risk, and compliance (GRC) initiatives. This role will work closely with leaders within and outside of Business Technology, Legal, Compliance, and Privacy. This role provides leadership in GRC activities and will work closely with the BT Cybersecurity team, understanding both GRC requirements and business requirements, and can tie technical concepts to enterprise and business risk.
The Association offers many resources to help you maintain work‑life harmonization through your changing needs and কোনো life situations. To help you be successful, you will have access to Heart U, our award‑winning corporate university, as well as additional training and support, locally.
#TheAHALife is more than a company culture; it is our way of life. It embodies our commitment to work‑life harmonization and is guided by our core values where our employees can thrive both personally and professionally. Europea why you will be Seen. Beulay. Be Heard. Be Valued at the American Heart Association by following us on Linked In, Instagram, Facebook, X, and atheart.jobs.
Responsibilities- Develops, maintains, and executes the BT GRC strategy and roadmap in alignment with organizational information security and business objectives, including setting strategic другое direction, policies, and standards
- Develops and maintains policies, processes, procedures, and standards to support GRC and Cybersecurity requirements based on selected industry and regulatory frameworks. Collaborates with business units, legal, and HR to ensure consistent policy application, awareness, and alignment with organizational goals
- Manages the BT risk management program, including identification, assessment, mitigation, and reporting of cyber and technology risks, and maintains the risk register for leadership visibility.
- Ensures GRC strategy covers security and privacy frameworks, adapting to changes in legislation and regulation. Stays current with evolving national, state, and local privacy laws and framework impacting security and data governance
- Translates GRC requirements into actionable guidance for stakeholders, ensuring compliance or identifying compensating controls as needed. Maintains a compliance calendar and ensures timely execution of required activities such as policy reviews, annual training, risk assessments, and gathering compliance artifacts
- Drives remediation plans and risk treatment strategies in collaboration with technology and business leaders, ensuring adherence to internal and external requirements
- Lead and support internal and external audits, including readiness assessments, remediation activities, and serve as the primary contact for third‑party auditors and assessors
- Performs other duties as required or assigned, which are reasonably within the scope and responsibility of the job level and family.
- Requires a degree or equivalent
- Requires 8 years of minimum prior relevant experience
- Required Skills:
Strategic Planning, Cybersecurity, Governance, Risk and Compliance (GRC), Risk Assessment, Regulatory Compliance, Project Management, Cloud Security, Metrics Management, Team Management and Team Building, Risk Management
The American Heart Association invests in its people. Here are the main components of our total rewards package. Visit Rewards & Benefits to see more details.
- Compensation – Our goal is to ensure you have a competitive base salary. That’s why we regularly review the market value of jobs and make adjustments, as…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).