Job DescriptionThis role will be responsible for managing security governance programs, SOX IT controls coordination, customer and vendor security reviews, client-facing security engagements, regulatory and compliance assessments, and cross-functional security initiatives.
The ideal candidate will act as the
single point of contact (SPOC) for security governance matters across Conifer, ensuring alignment with enterprise security requirements, client obligations, regulatory standards, and business objectives. This leader will work closely with Conifer executives, operational leaders, compliance teams, technology teams, customers, vendors, auditors, and Tenet Enterprise Security to drive a unified security and risk management program.
ESSENTIAL DUTIES AND RESPONSIBILITIESInclude the following. Others may be assigned.
Security Governance & Compliance- Lead Conifer's security governance activities, ensuring adherence to corporate security policies, regulatory requirements, and industry best practices.
- Coordinate and manage SOX IT General Controls (ITGC) activities, control testing, remediation efforts, evidence collection, and audit support.
- Support internal and external audits, including SOX, SOC, client audits, and regulatory assessments.
- Track compliance initiatives and monitor remediation activities through completion.
- Facilitate governance forums and provide regular updates to executive leadership.
Customer Security & Client Engagement- Serve as the primary security representative for client security inquiries, assessments, and due diligence activities.
- Lead customer security reviews, questionnaires, RFP/RFI responses, and security presentations.
- Build trusted relationships with client security, compliance, legal, and technology stakeholders.
- Partner with Sales, Client Services, and Operations teams to address customer security requirements during contract negotiations and ongoing service delivery.
Vendor Risk Management- Manage Conifer's third-party security risk management processes.
- Conduct security reviews and risk assessments for vendors, partners, and service providers.
- Coordinate remediation plans with vendors and internal stakeholders.
- Ensure compliance with vendor security requirements, contractual obligations, and client expectations.
- Maintain vendor security risk documentation and reporting.
Strategic Partnership with Tenet- Serve as Conifer's primary liaison to Tenet Enterprise Security, Risk, and Compliance organizations.
- Coordinate the adoption and implementation of enterprise security initiatives across Conifer.
- Ensure alignment between Conifer-specific requirements and Tenet cybersecurity standards.
- Represent Conifer in enterprise security governance, risk management, and strategic planning activities.
Risk Management & Security Programs- Identify, assess, and monitor information security, operational, and third-party risks.
- Support enterprise risk management activities, risk reporting, and mitigation planning.
- Track security findings and corrective actions through closure.
- Assist in the development and maintenance of security policies, standards, and procedures.
Executive Reporting & Stakeholder Management- Develop executive-level reporting, dashboards, and risk metrics.
- Present security program status, compliance updates, and risk assessments to senior leadership.
- Drive cross-functional collaboration among Security, Compliance, Legal, Operations, Technology, and Client Services teams.
REQUIRED QUALIFICATIONS- Bachelor's degree in Information Security, Computer Science, Information Technology, Business Administration, or related field/experience.
- 7+ years of experience in Information Security, Risk Management, Compliance, Audit, or Governance.
- 3+ years of leadership or program management experience.
- Strong knowledge of:
- SOX IT Controls (ITGC)
- Security Governance & Compliance
- Vendor Risk Management
- Client Security Reviews and Due Diligence
- Risk Assessment Methodologies
- SOC, NIST, ISO 27001, HIPAA, and healthcare security requirements
- Experience working directly with customers, auditors, and executive stakeholders.
- Exceptional communication and presentation skills.
Preferred Qualifications- Industry certifications such as:
- CISSP
- CISM
- CRISC
- CISA
- Security+
- Experience in healthcare, revenue cycle management, or regulated industries.
- Experience supporting large-scale enterprise security programs and governance frameworks.
- Familiarity with Tenet or complex multi-entity healthcare environments.
Compensation and Benefit InformationCompensation
- Pay: $120,016 - $191,568 annually. Compensation depends on location, qualifications, and experience.
- Position may be eligible for an Annual Incentive Plan bonus of 10%-40% depending on role level.
- Management level positions may be eligible for sign-on and relocation bonuses.
Benefits
Conifer offers the following benefits, subject to employment status:
- Medical, dental, vision, disability, AD&D and life insurance
- Manager Time Off - 20 days per year
- Discretionary 401k match
- 10 paid holidays per year
- Health savings accounts, healthcare & dependent flexible spending accounts
- Employee Assistance program, Employee discount program
- Voluntary benefits include pet insurance, legal insurance, accident and critical illness insurance, long term care, elder & childcare, auto & home insurance
- For Colorado employees, paid leave in accordance with Colorado's Healthy Families and Workplaces Act is available.
#LI-NO3
Qualifications