> Markdown version of [/jobs/ext/564540-head-of-it-governance-risk-and-compliance-grc](https://www.wearedevelopers.com/jobs/ext/564540-head-of-it-governance-risk-and-compliance-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of IT Governance, Risk, and Compliance (GRC) - **Company:** LabConnect, LLC - **Location:** Johnson City, TN, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Audit Trail, Cyber Security, Information Systems, IT Management, Virtual Desktops, Data Processing, Data Classification, IT General Controls (ITGC), Information Technology - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=82ae50f37e4380f3 ## About the Role Do you have experience in Senior leadership?, * Bachelor's degree in computer science, engineering, information systems, or a related field required; advanced degree preferred. * 10+ years of progressive experience in IT security, compliance, risk management, or GRC leadership roles, ideally within a high-growth, cloud-enabled, or highly regulated environment. * Demonstrated expertise in major security and privacy frameworks and standards, such as SOC 2, ISO 27001, HIPAA, and GDPR, along with practical knowledge of AI governance and healthcare AI compliance considerations. * Experience applying risk-based controls to AI use cases, including privacy safeguards, vendor oversight, auditability, and model governance, is strongly preferred. * Strong executive presence and the ability to influence stakeholders across technical, operational, and business functions. Skills and Ability * Ability to communicate complex risk, compliance, and security matters clearly to senior leadership, auditors, clients, and cross-functional stakeholders. * Demonstrated success building credibility and leading in environments where technology, operations, and business processes are tightly interconnected. * Experience establishing or enhancing governance models that improve decision quality, accountability, prioritization, and cross-functional alignment. * Strong executive presence and the ability to build credibility with senior leaders as well as frontline operators and functional partners. * Excellent communication skills, including the ability to translate complexity into clear, concise messages tailored to technical, operational, and executive audiences. * Sound judgment and high initiative in ambiguous environments, with the capacity to create structure, momentum, and alignment quickly. * A track record of influencing outcomes through collaboration, credibility, and thoughtful organizational leadership. * The ability to balance strategic leadership with selective hands-on engagement in high-priority initiatives. ## Description We are an independent, global, one-stop-shop focused on delivering Central Laboratory Services that are tailor-made, timely and flexible to meet the evolving study demands of traditional to increasingly complex trials. Additionally, we provide Functional Service Provider (FSP) Solutions, supporting our clients with scientific and technical expertise, acting as an extension of their team, coordinating all laboratory related needs, advising on strategies for lab data collection and providing end-to-end analytical and logistical solutions., The Senior Director, IT Governance, Risk, and Compliance (GRC) is responsible for developing and leading the company's IT risk, compliance, and control strategy. The Senior Director will assess LabConnect's current maturity, identify gaps, and establish the roadmap, governance processes, and cross-functional operating discipline needed to strengthen and evolve the control environment over time. The Senior Director will help build a sustainable foundation for audit readiness and ongoing alignment across key regulatory, privacy, and quality frameworks, including SOC 2, HIPAA, GDPR, and FDA 21 CFR Part 11, while also establishing governance for the company's increasing use of AI in internal operations and healthcare-related product capabilities. This includes creating policies, review processes, and risk controls for AI adoption with attention to privacy, security, transparency, validation, and applicable healthcare regulatory expectations., * Define and oversee governance, risk, and compliance policies for modern access, endpoint, and virtual desktop environments, including secure approaches that support bring-your-own-device and remote work models. * Assess the organization's current-state controls, documentation, and operating practices across relevant frameworks, including SOC 2, HIPAA, GDPR, and FDA 21 CFR Part 11. Develop the strategy, roadmap, and governance processes needed to close gaps, strengthen compliance maturity, and support ongoing audit readiness and sustained regulatory alignment. * Develop the governance framework, risk controls, and review processes needed to support LabConnect's transition to AI-enabled internal workflows and product capabilities. Establish practical standards for acceptable AI use, model and vendor oversight, data handling, human review, auditability, and ongoing monitoring, with particular attention to HIPAA requirements for protected health information, the NIST AI Risk Management Framework, and FDA considerations where AI functionality may affect regulated healthcare use cases. * Establish and enhance data protection controls, including data classification, monitoring, and loss prevention practices, to reduce risk and protect sensitive information across collaboration and operational platforms. * Evaluate and monitor the compliance and security posture of external partners, vendors, and service providers that support business-critical and regulated processes. * Partner with technology, quality, legal, privacy, and business leaders to embed compliance, validation, and risk management into operating processes in a manner that supports both operational rigor and organizational agility. Align IT controls, risk management, and audit readiness with validation requirements to ensure coordinated compliance with regulations such as FDA 21 CFR Part 11., * Prolonged periods of sitting at a desk and working on a computer. * Prolonged use of computer and headphones for conference calls. * Communicate effectively via phone, video, and email. * Use hands and fingers to operate a computer and other office equipment. * Occasional travel may be required for meetings, audits, or company events. ## Related Videos - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) - [AI in Leadership: How Technology is Reshaping Executive Roles](https://www.wearedevelopers.com/videos/1705-ai-in-leadership-how-technology-is-reshaping-executive-roles) ## Related Articles - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)