Job Requirements
Position Summary
The Senior IT GRC Coordinator, reporting to the Chief Information Security Officer (CISO), leads the Information Technology Governance, Risk, and Compliance program within Information Technology. This role is responsible for IT documentation lifecycle governance, disaster recovery documentation readiness, policy and procedure management, and continuous improvement of the organization's GRC documentation posture. The Senior IT GRC Coordinator serves as the primary documentation lead during cybersecurity incidents and disaster recovery exercises, drives maturity of IT standards, ensures compliance with HIPAA, NIST CSF, CIS Controls, and PCI DSS, and leads after-action review processes. This position plays a critical role in strengthening the organization's governance maturity, compliance posture, and operational resilience by ensuring that all IT documentation is accurate, current, retrievable, and audit-ready.
Minimum Requirements
Education
• Bachelor's degree in Information Technology, Information Security, Technical Communications, Healthcare Administration, or a related field.
Experience
• 5-7 years of experience in IT governance, risk, compliance, documentation management, or a related field, preferably in a healthcare environment.
• Demonstrated experience developing and maintaining IT policies, procedures, runbooks, and playbooks.
• Experience with disaster recovery planning and documentation.
• Experience with document lifecycle management tools and version control.
License/Registration/Certifications
• N/A
Other Knowledge, Skills, and Abilities
• Strong knowledge of healthcare regulatory frameworks including HIPAA, NIST CSF, and CIS Controls.
• Proven ability to manage projects, coordinate cross-functional teams, and meet deadlines.
• Excellent written and verbal communication skills with the ability to translate technical concepts into clear, actionable documentation.
Preferred Requirements
Preferred Education
• Master's degree in Information Security, Healthcare Informatics, or a related field.
Preferred Experience
• Experience in a healthcare system with 5,000+ associates.
• Familiarity with Joint Commission, CMS, or DNV accreditation requirements.
• Experience with documentation management systems.
Preferred License/Registration/Certifications
• ITIL 4 Foundation or higher.
• Project Management Professional (PMP) or Certified Associate in Project Management (CAPM).
• Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or Certified in the Governance of Enterprise IT (CGEIT).
• Certified Document Imaging Architect (CDIA+) or equivalent.
Core Job Responsibilities
Documentation Governance & Standards
• Own the IT documentation lifecycle including templates, version control, review cycles, quality assurance, and recertification.
• Develop and maintain standardized templates for policies, procedures, runbooks, playbooks, guidelines, and standards.
• Manage the centralized IT documentation repository, ensuring all documents are current, accessible, and properly classified.
• Lead annual documentation quality audits and maintain a documentation maturity scorecard.
• Establish and enforce documentation naming conventions, metadata standards, and retention schedules.
Disaster Recovery & Incident Response Documentation
• Lead the development and maintenance of all DR runbooks and operational recovery playbooks in accordance with the SRHS Operational Recovery Runbook Template and Protiviti audit recommendations.
• Ensure all runbooks include purpose, scope, assumptions, RACI, failover strategy, critical dependencies, communications plan, and step-by-step recovery procedures executable by non-key personnel.
• Serve as primary documentation lead during cybersecurity incidents, maintaining action logs, timelines, and evidence chains.
• Facilitate After Action Reports (AARs) following DR tests and real incidents, documenting lessons learned and tracking remediation actions to closure.
Policy & Compliance Management
• Manage the annual IT policy and procedure review cycle in accordance with internal review policy.
• Coordinate with IT directors and system directors to ensure all policies are reviewed, updated, and approved on schedule.
• Maintain a master inventory of all IT policies, procedures, and guidelines with assigned owners, review dates, and framework mappings (HIPAA, NIST CSF, CIS, PCI DSS).
• Support audit readiness by maintaining organized, retrievable evidence of documentation governance for internal audits, Protiviti engagements, and regulatory assessments.
Program Leadership & Continuous Improvement
• Serve as program lead for the IT Governance program, defining the roadmap, KPIs, and maturity targets.
• Report to the CISO on program progress, documentation health metrics, and compliance posture.
• Lead continuous improvement initiatives including lessons-learned processes, peer reviews, and documentation readability assessments.
• Mentor and guide junior team members, fostering a culture of documentation excellence.
• Collaborate with IT leadership to align the IT Governance program with the SRHS strategic plan and regulatory requirements.