All Together Better.
Director, IT Security & Compliance - Remote
Location
Georgia
Posted
70 days ago
Salary
0
Seniority
Lead
Job Description
Director, IT Security & Compliance - Remote
Sharecare
Job Description: Sharecare is a digital healthcare company that delivers software and tech-enabled services to stakeholders across the healthcare ecosystem to help improve care quality, drive better outcomes, and lower costs. Through its data-driven AI insights, evidence-based resources, and comprehensive platform – including benefits navigation, care management, home care resources, health information management, and more – Sharecare helps people easily and efficiently manage their healthcare and improve their well-being. Across its three business channels, Sharecare enables health plan sponsors, health systems and physician practices, and leading pharmaceutical brands to drive personalized and value-based care at scale. To learn more, visit Sharecare.com. Job Summary: The Director of IT Security Compliance is responsible for leading and managing enterprise-wide security compliance, IT audit, and third-party risk management initiatives. This role ensures alignment with industry standards and regulatory requirements while overseeing certification efforts, audit processes, vendor risk evaluations, and continuous improvement of compliance programs. The Director will work cross-functionally to support business objectives while maintaining a strong security, audit, and compliance posture. Essential Job Functions: Certification & Audit Management - Lead and manage all external certification audit processes, including ISO 27001, HITRUST, and SOC 1 / SOC 2. - Serve as the primary point of contact for external auditors, certification bodies, and IT audit firms. - Oversee IT audit readiness activities, including control design, documentation, and evidence management. - Coordinate internal stakeholders to ensure timely and successful audit execution. - Respond to client-driven audits and due diligence requests across all business lines. IT Audit Oversight & Governance - Lead internal and external IT audit engagements, including planning, scoping, execution support, and reporting. - Ensure alignment of IT controls with audit frameworks (e.g., SOC, ISO, HITRUST, NIST). - Partner with Internal Audit and external auditors to facilitate efficient audit cycles. - Review audit results, assess control effectiveness, and provide strategic recommendations. - Establish and maintain audit documentation standards, including policies, procedures, and control narratives. Third-Party Risk Management (TPRM) - Define and lead the enterprise third-party risk management program. - Establish processes to assess and tier vendor risk based on data sensitivity, access, and business impact. - Evaluate vendor risk through: - Business owner–completed risk assessments - Vendor-provided certifications (e.g., SOC 2, HITRUST) - Independent vendor security scorecards - Leverage GRC tools to calculate and track inherent risk and residual risk for all vendors. - Review vendor control environments and identify gaps against organizational and regulatory requirements. - Partner with business owners to ensure appropriate risk acceptance, mitigation, or remediation strategies are implemented. - Monitor vendor risk posture continuously and reassess critical vendors on a defined cadence. - Support procurement and legal teams in embedding security and compliance requirements into vendor contracts. Corrective Action & Findings Management - Define, implement, and manage the internal corrective action plan (CAP) process. - Track and drive remediation of findings from: - IT audits (internal and external) - Client audits - Penetration tests - Risk assessments - Vendor risk assessments - Ensure timely closure of identified gaps and maintain appropriate audit-ready documentation. Risk Assessment & Compliance Processes - Develop, implement, and oversee internal risk assessment processes aligned with certification and audit requirements. - Evaluate IT general controls (ITGCs), application controls, and security controls. - Identify control gaps and provide remediation strategies aligned with audit expectations. Continuous Improvement - Define and execute strategies for continuous improvement of compliance, audit, and third-party risk processes. - Enhance control frameworks, documentation quality, and audit efficiency. - Monitor evolving regulatory, audit, and industry requirements. Client & RFP Support - Respond to external audit requests, security questionnaires, and RFPs across all business units. - Translate audit and compliance posture into clear, client-facing responses. - Partner with sales, legal, and operational teams to support business growth. Access Management Oversight - Execute and oversee the quarterly user access review process. - Ensure compliance with ITGC access control requirements. - Validate adherence to least privilege and segregation of duties (SoD). KPI Development & Performance Management - Define, implement, and monitor KPIs for compliance, audit, and third-party risk processes. - Develop dashboards to track audit readiness, vendor risk posture, control effectiveness, and remediation progress. - Provide regular reporting to executive leadership and stakeholders. Qualifications: - Bachelor’s degree in Information Security, Information Technology, Accounting, or related field (or equivalent experience). - 10+ years of experience in IT security, compliance, IT audit, and/or third-party risk management. - Strong hands-on experience with: - SOC 1 / SOC 2 - ISO 27001 - HITRUST - IT General Controls (ITGCs) - Third-party/vendor risk management frameworks - Proven experience managing IT audits and vendor risk assessments. - Proven experience managing security compliance teams. - Experience with GRC platforms and risk scoring methodologies (inherent vs. residual risk). - Strong understanding of control environments and risk mitigation strategies. - Excellent communication and stakeholder management abilities - Ability to manage multiple priorities, audits, and vendor relationships simultaneously - Detail-oriented with strong documentation and evidence management discipline Preferred: - Professional certifications such as: - CISA (Certified Information Systems Auditor) - CISSP, CISM, or CRISC - Experience working with internal audit teams or public accounting firms. - Experience in healthcare or other regulated industries. - Familiarity with vendor risk tools and security rating platforms (e.g., BitSight, SecurityScorecard). - Familiarity with IT development and operations management tools (e.g. JIRA, WIZ, MEND, OneTrust, CrowdStrike) Sharecare and its subsidiaries are Equal Opportunity Employers and E-Verify users. Qualified applicants will receive consideration for employment without regard to race, color, sex, national origin, sexual orientation, gender identity, religion, age, equal pay, disability, genetic information, protected veteran status, or other status protected under applicable law.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Own and drive the end-to-end product strategy for a paid Platform Security offering. • Define vision, roadmap, and success metrics for capabilities including BYOK, HYOK, audit logging, and related security features. • Identify market opportunities and customer needs to shape a differentiated enterprise security product. • Lead product development from ideation through launch and scale, partnering closely with engineering to deliver secure, scalable, and performant solutions. • Make principled tradeoffs between speed, risk, and long-term platform integrity. • Act as a thought leader across the platform organization, driving improvements in authentication, authorization, multi-tenant architecture, and organization management. • Influence platform standards, patterns, and best practices. • Work directly with enterprise customers to understand security requirements and validate solutions. • Partner with internal solution/product teams to ensure platform capabilities meet downstream needs. • Partner with Sales and Marketing to define packaging, pricing, and positioning for the security offering. • Enable Sales through clear value propositions, messaging, and supporting materials. • Drive successful product launches and adoption strategies.
Information Systems Security Officer (Part-time, Remote)
Koniag Government Services, LLCKoniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies.
Arlluk Technology Solutions, LLC a Koniag Government Services company, is seeking an Information Systems Security Officer with a Secret security clearance to support ATS and our government customer. This position is remote and part-time. Koniag Government Services is seeking a Part-Time Information Systems Security Officer (ISSO) to support and maintain the security posture of critical Department of War (DOW) information systems. The ideal candidate will be a detail-oriented professional with extensive expertise in the DOD Risk Management Framework (RMF), DISA regulations, and STIG compliance. Initially supporting one primary program, this role requires flexibility to potentially expand support to additional programs as requirements evolve. The successful candidate will manage vulnerabilities via ACAS and HBSS, maintain Authority to Operate (ATO) accreditations, and possess the strong organizational skills necessary to ensure continuous cybersecurity compliance in a mission-critical, team-based environment. Essential Functions, Responsibilities & Duties may include, but are not limited to: The Information Systems Security Officer will be responsible for maintaining the security posture of multiple DOW information systems and ensuring compliance with all applicable cybersecurity frameworks and regulations. Principal responsibilities will include but are not limited to: - Develop and maintain System Administration Documentation that maps interdependencies and critical paths for successful system refreshes, working closely with government stakeholders to identify agency interdependencies - Create and update Configuration and Architecture Diagrams in relation to critical paths and system interdependencies - Provide comprehensive RMF documentation to the ISSM in accordance with DOD accreditation processes - Verify compliance with STIG, DISA Chief Technology Office (CTO), and INFOCON guidelines and requirements - Validate security postures and update findings for assigned databases based on Assured Compliance Assessment Solution (ACAS) and Host Based Security System (HBSS) reports and logs - Adhere to CYBERCOM Information Assurance Vulnerability Alerts (IAVAs) by applying required patches and maintaining Plan of Action and Milestones (POA&M) documentation - Conduct STIG Checklist reviews and provide detailed reports of all findings in accordance with RMF frequency requirements - Generate monthly Cybersecurity Reports containing patch schedules for all servers, accreditation status, POA&M status, IAVA status, ACAS scan remediation status, and DISA CTO compliance status - Develop system and cybersecurity policies and plans to identify and respond to threats in compliance with DOW and DISA regulations - Audit access controls and permissions for CSS, COPS, and FABS systems in accordance with DOW and DISA compliance requirements - Provide incident response and recovery support as necessary - Support obtaining and maintaining Authority to Operate (ATO) accreditations for CSS and COPS/FABS systems - Maintain security posture for CSS, COPS/FABS, and EDMS systems - Support DISA ISSO/ISSM with security information to respond to taskers and emerging cybersecurity requirements - Support development and maintenance of Incident Response Plans (IRPs) and Continuity of Operations Plans (COOPs) - Interpret, plan for, prioritize, and implement actions necessary to maintain compliance with DOD and DISA cybersecurity requirements Education and Experience: - Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field from an accredited college or university - 5+ years of experience as an ISSO supporting DOW information systems - Current DOD 8570.01-M IAT Level II or IAM Level II certification (CISSP, CISM, or CAP certification) - Experience working within the Risk Management Framework (RMF) Clearance Requirement: - Active Secret security clearance Required Skills and Competencies: - Comprehensive knowledge of DOD Risk Management Framework (RMF) and accreditation processes - Expertise in Security Technical Implementation Guides (STIGs) and STIG compliance verification - Proficiency with ACAS (Nessus) scanning tools and vulnerability management - Experience with Host Based Security System (HBSS) including ePO administration - Strong understanding of DISA CTO requirements and INFOCON procedures - Knowledge of CYBERCOM IAVAs and patch management processes - Ability to develop and maintain POA&Ms and track remediation efforts - Experience creating technical documentation including system architecture diagrams and security plans - Proficiency in conducting security assessments and audits - Knowledge of access control principles and implementation - Understanding of incident response procedures and recovery operations - Familiarity with ATO processes and requirements - Strong analytical and problem-solving abilities - Excellent written and verbal communication skills - Ability to work independently and as part of a team - Strong attention to detail and organizational skills - Ability to manage multiple priorities and meet strict deadlines Our Equal Employment Opportunity Policy The company is an equal opportunity employer. The company shall not discriminate against any employee or applicant because of race, color, religion, creed, ethnicity, sex, sexual orientation, gender or gender identity (except where gender is a bona fide occupational qualification), national origin or ancestry, age, disability, citizenship, military/veteran status, marital status, genetic information or any other characteristic protected by applicable federal, state, or local law. We are committed to equal employment opportunity in all decisions related to employment, promotion, wages, benefits, and all other privileges, terms, and conditions of employment. The company is dedicated to seeking all qualified applicants. If you require an accommodation to navigate or apply for a position on our website, please get in touch with Heaven Wood via e-mail at accommodations@koniag-gs.com or by calling 703-488-9377 to request accommodations. Koniag Government Services (KGS) is an Alaska Native Owned corporation supporting the values and traditions of our native communities through an agile employee and corporate culture that delivers Enterprise Solutions, Professional Services and Operational Management to Federal Government Agencies. As a wholly owned subsidiary of Koniag, we apply our proven commercial solutions to a deep knowledge of Defense and Civilian missions to provide forward leaning technical, professional, and operational solutions. KGS enables successful mission outcomes for our customers through solution-oriented business partnerships and a commitment to exceptional service delivery. We ensure long-term success with a continuous improvement approach while balancing the collective interests of our customers, employees, and native communities. For more information, please visit www.koniag-gs.com. Equal Opportunity Employer/Veterans/Disabled. Shareholder Preference in accordance with Public Law 88-352
School Summary North Carolina Connections Academy is a public remote charter academy serving students across the state. The school delivers a personalized learning experience through the Connections Academy model, emphasizing strong family partnerships, academic rigor, and equitable access to student support services. The virtual environment allows students to learn flexibly while receiving the guidance and support needed to succeed academically and personally. Position Summary Accepting applications for the 2026-2027 school year. Working from their home or from our Durham office, North Carolina licensed and certified teachers will support and motivate students through high-quality virtual instruction using Pearson Online Classroom. Through the use of the telephone, internet, and various curriculum and communication tools they will consult frequently with learning coaches and students to ensure that each child successfully completes their instructional program. The Art Teacher will be responsible for the successful completion of the following tasks: - Contribute to a culture of achievement by supporting the instructional program with asynchronous and synchronous instruction in whole group, small group and 1-1 settings; - Complete all grading, lesson preparation, student and learning coach communications within specified and required timeframes; - Review curriculum and assigned courses developing and maintaining a detailed knowledge of content as well as devising alternate approaches to present lessons to increase student understanding; - Support students and learning coaches with daily assignments and provide additional strategies and approaches to drive student course completion and success; - Adhere to and support Individualized Education Plans (IEP) and Section 504 Plans for students in assigned courses; - Engage in professional development and professional learning communities; - Develop methods & activities for fostering & maintaining a virtual “school community”; - Work collaboratively with school staff daily through online meeting and communication tools and school LMS (i.e. Pearson Online Classroom, Google Chat, Gmail, Google Meet, Zoom, etc.); - Communicate regularly with learning coaches and students through use of computer and telephone (i.e. Google Voice, POC Webmail, LiveLesson, Zoom, etc.); - Serve as a Homeroom teacher for a group of students, acting as their primary point of contact and support for all school related issues; - Keep student records and data up-to-date, including Data Views, cumulative files, online student and family information, attendance accounting, and logging all student and learning coach contacts; - Serve as a proctor and support state testing assignments as directed; - Attend field trips and other community activities implemented for students and families; - Other duties as assigned. Requirements: - Valid North Carolina Teaching License with certification in Art (appropriate to grade level and course responsibilities). - North Carolina residency preferred. - A valid driver’s license or state-issued identification card. - Availability to work full-time teacher shift from 8am - 4pm, Monday through Friday. - Strong interpersonal skills which include the ability to work effectively with students, parents, staff, and community members from diverse backgrounds. - Strong technology skills (especially in Google Suite). - Virtual experience preferred. - Demonstrated ability to create a positive, equitable, and student-centered environment. - Customer focused approach. - High degree of flexibility. - Demonstrated ability to work well in a fast paced environment. - Willingness and ability to travel for school-based meetings, training, graduation, field trips, and state testing events (may require overnight travel). - Ability to work some occasional evening hours, as needed to support some families. - Please note, if given a job offer, 2-step authentication is required to login to all systems. North Carolina Connections Academy is committed to providing an inclusive and supportive educational experience that reflects a diverse student body and fosters innovation through technology.
Principal AWS Cloud Security Consultant
GuidePoint SecurityFounded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security
• Provide oversight for delivery teams, ensuring quality, consistency, and alignment with client objectives while fostering knowledge transfer and consistent execution • Manage and resolve client escalations, balancing client satisfaction with project scope and delivery constraints • Present findings and recommendations to executive stakeholders, lead technical workshops, and facilitate security strategy sessions • As an individual contributor, provide consulting services on customer engagements and deliver security outcomes. Tasks may include: • Design secure cloud architectures and reference models for AWS and multi-cloud environments • Conduct in-depth cloud security assessments to identify security misconfigurations, architecture and cloud operational risks, and compliance gaps • Assist clients with continuous compliance and audit readiness in cloud environments • Conduct AWS security workshops, technical interviews, and stakeholder briefings • Prepare and present client deliverables including security roadmaps, process improvements, gap analyses, architecture diagrams, cloud security strategies, and custom deliverables based on client needs • Contribute to internal methodologies, templates, and reusable assessment frameworks • Mentor junior consultants and support knowledge sharing within the consultancy • Assist with scoping and pre-sales activities including proposals and statements of work (SOWs) • Collaborate with internal pre-sales teams to identify use-cases and opportunities for third-party security tooling (e.g., CNAPP, secrets management, data security, cloud detection and response, NHI [Non-Human Identity], etc.)



