Director, IT Security Risk

R1 RCM Inc.
Salt Lake City, UT, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$122,366.0 - $178,767.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Workflow Management Systems

Job description

As Director, IT Security Risk , you will lead cybersecurity governance, risk, and compliance capabilities that protect R1 and customer information assets and technology infrastructure. Reporting to the Deputy CISO, you will lead a US- and India-based team and own key programs spanning third-party cyber risk, customer cybersecurity inquiries and assessments, risk exceptions, and the cyber risk register.

This is a hands-on leadership opportunity to mature and automate critical cyber risk processes in a dynamic, global healthcare organization. You will partner with customers, business leaders, Procurement, Compliance, IT, Product Development, and Security teams to address risk, support business needs, and strengthen the organization’s overall security posture.

Responsibilities:

· Develop and execute the strategy and operating program for assessing, monitoring, and mitigating cybersecurity risk from third parties and suppliers.

· Lead, mentor, and develop a US- and India-based team, including approximately two to three direct reports and a broader team of approximately five employees.

· Oversee responses to customer cybersecurity questionnaires, customer cyber risk assessments, risk-exception processing, and maintenance of the cyber risk register.

· Build and mature scalable governance and third-party risk capabilities, including clear procedures, documentation, controls, reporting, and stakeholder accountability.

· Continuously review and optimize processes for efficiency and effectiveness in a changing threat environment, leveraging automation wherever appropriate.

· Partner with customers and internal relationship leaders to respond to cybersecurity inquiries and support time-sensitive business needs.

· Collaborate with IT, Product Development, Procurement, Compliance, business leaders, and other Security teams to reduce risk and address customer, contractual, regulatory, and operational requirements.

· Ensure alignment with applicable regulatory requirements, industry standards, company policies, and cybersecurity best practices.

· Develop and maintain program procedures, standards, and supporting documentation.

· Define and communicate program performance, risk trends, priorities, and recommendations to senior management and other stakeholders.

· Stay current on industry trends, emerging threats, and evolving cybersecurity governance and third-party risk practices.

· Foster a culture of security awareness, accountability, collaboration, and continuous improvement.

· Manage relationships with external partners, including security vendors and consultants.

Requirements

· Bachelor’s degree or an equivalent combination of education and relevant experience.

· 10+ years of cybersecurity, technology risk, governance, risk and compliance, or related experience, including at least five years in a people-management role.

· Demonstrated experience leading cybersecurity governance, risk, and compliance programs, with significant responsibility for third-party cyber risk management.

· Experience building a new cyber GRC or third-party risk capability from the ground up, or materially rebuilding and maturing an existing program.

· Experience managing customer cybersecurity questionnaires, risk assessments, exceptions, and risk-register processes.

· Experience leading and developing teams across geographies, ideally including US- and India-based employees.

· Strong customer-facing and stakeholder-management skills, with the ability to work effectively with senior leaders, business partners, Procurement, Compliance, IT, Product Development, and Security teams.

· Ability to translate cybersecurity risk into clear business impact, recommendations, metrics, and executive-level reporting.

· Experience improving processes through standardization, workflow design, and automation.

· Strong judgment, organization, responsiveness, and the ability to manage multiple priorities and rapid-turnaround requests.

Preferred Qualifications:

· Cybersecurity risk experience within healthcare, banking, financial services, or another highly regulated industry.

· CISM certification required; CISSP or another relevant cybersecurity or risk certification is strongly preferred.

· Experience operating in a global, acquisition-oriented, or rapidly changing organization.

Benefits & conditions

For this US-based position, the base pay range is $122,366.00 - $178,767.22 per year . Individual pay is determined by role, level, location, job-related skills, experience, and relevant education or training.

This job is eligible to participate in our annual bonus plan at a target of 20.00%

The healthcare system is always evolving - and it’s up to us to use our shared expertise to find new solutions that can keep up. On our growing team you’ll find the opportunity to constantly learn, collaborate across groups and explore new paths for your career.

Our associates are given the chance to contribute, think boldly and create meaningful work that makes a difference in the communities we serve around the world. We go beyond expectations in everything we do. Not only does that drive customer success and improve patient care, but that same enthusiasm is applied to giving back to the community and taking care of our team - including offering a competitive benefits package. (http://go.r1rcm.com/benefits)

About the company

R1 is the leading provider of technology-driven solutions that transform the patient experience and financial performance of hospitals, health systems, and medical groups. We combine deep revenue cycle expertise, a global workforce, and advanced technology across analytics, AI, intelligent automation, and workflow orchestration to help healthcare organizations improve performance at scale., R1 is the leader in healthcare revenue management, helping providers achieve new levels of performance through smart orchestration. A pioneer in the industry, R1 created the first Healthcare Revenue Operating System: a modular, intelligent platform that integrates automation, AI, and human expertise to strengthen the entire revenue cycle. With more than 20 years of experience, R1 partners with 1,000 providers, including 95 of the top 100 U.S. health systems, and handles over 270 million payer transactions annually. This scale provides unmatched operational insight to help healthcare organizations unlock greater long-term value. To learn more, visit: https://www.r1rcm.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:30 min

Enabling GitOps using custom resource definitions and Kubernetes operators

Zan Markan Zan Markan · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

5:51 min

Audience questions on shared infrastructure and remote teams

Robert Hoffmann Robert Hoffmann +1 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all