Director Information Security - Governance, Risk, and Compliance
The Rector & Visitors of the University of Virginia | |
$118,144.00 - $236,288.00 Annual
| |
vision insurance, paid time off
| |
United States, Virginia, Charlottesville | |
1215 Lee Street (Show on map) | |
Nov 10, 2025 | |
|
The Director Information Security - Governance, Risk, and Compliance (GRC) will lead the IT Governance, Risk, and Compliance teams and oversee the services and processes for establishing effective IT risk management in an academic provider healthcare environment. This role collaborates with executive leadership, clinical and operational teams, and external partners to proactively identify, assess, and manage cybersecurity risks, ensure regulatory compliance, and foster a culture of security awareness throughout the health system. This role will oversee and continuously mature the information security risk management program including assessment of cyber and IT risk management and exceptions, maintenance of a registry of significant IT risks, third-party risk management (TPRM), data governance, disaster recovery and business continuity (DR/BC), cyber insurance and other assessments, coordination of internal and external audits and completion of the associated corrective action plans, security metrics and dashboards, internal phishing simulations and tabletop exercises (TTX), and on-going security awareness education.
KEY RESPONSIBILITIES Strategic Planning and Financial Oversight
Leadership and Operations Management
Service Delivery and Stakeholder Management
Policy Development and Implementation
ADDITIONAL RESPONSIBILITIES
MINIMUM QUALIFICATIONS Education: Bachelor's degree in information security, computer science, or a related field required. Master's Degree is preferred. Experience: 10 years of experience in information technology within a related area, with at least five years of progressive responsibility in a technology leadership role managing information security teams, healthcare preferred. Academic healthcare security operations, risk management, or access management preferred. Strong understanding of information security concepts, protocols, industry best practices and regulatory requirements with knowledge of networking, enterprise applications, cloud computing, and information risk management and compliance frameworks preferred. Ability to communicate via written and verbal communication in both formal and casual situations. Demonstrated initiative and success in providing Information Security services, preferably in an academic healthcare setting. Strong analytical and problem-solving skills. Ability to work under pressure and handle multiple priorities. One or more of the following professional certifications or equivalent is required:
PHYSICAL DEMANDS This is primarily a sedentary job involving extensive use of desktop computers. The job does occasionally require traveling some distance to attend meetings, and programs. Position Compensation Range: $118,144.00 - $236,288.00 AnnualBenefits
UVA Health is a world-class Magnet Recognized academic medical center and health system with a level 1 trauma center. 2023-2024 U.S. News & World Report "Best Hospitals" guide rates UVA Health University Medical Center as "High Performing" in 5 adult specialties and 14 conditions/procedures. We are one of 70 National Cancer Institute designated cancer centers. UVA Health Children's is named by 2023-2024 U.S. News & World Report as the best children's hospital in Virginia with 9 specialties ranked among the best in the nation. Our footprint also encompasses 3 community hospitals and an integrated network of primary and specialty care clinics throughout Charlottesville, Culpeper, Northern Virginia, and beyond.
The University of Virginia is an equal opportunity employer. All interested persons are encouraged to apply, including veterans and individuals with disabilities. Click here to read more about UVA's commitment to non-discrimination and equal opportunity employment. | |
$118,144.00 - $236,288.00 Annual
vision insurance, paid time off
Nov 10, 2025