- Own the IT evidence program across ISO 27001:2022, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately thirteen sites.
- Act as the primary point of contact for external auditors, preparing evidence and owning remediation of findings.
- Manage IT third-party and vendor risk assessments, including maintaining a vendor register and performing periodic reviews.
- Handle customer-facing security due diligence, questionnaires, and audits.
- Maintain the IT risk register and drive remediation efforts to closure.
- Lead vulnerability management including scanning coverage, triage, and remediation escalation.
- Oversee incident response, including containment, investigation, and post-incident reporting.
- Run the security awareness program, including phishing simulations and analysis.
- Manage identity governance, access reviews, and privileged access controls across hybrid environments.
ComplianceRisk ManagementHIPAA