FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Assistant Vice President – Governance, Risk & Compliance
CVS HealthCVS Health AVP leading enterprise cybersecurity governance, risk, and compliance across healthcare operations. Modernizing GRC through automation, control testing, AI risk governance, and executive reporting.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in enterprise information security governance, risk management, and regulatory compliance, with a strong focus on healthcare cybersecurity regulations and frameworks. Proven ability to lead GRC initiatives, manage risk assessment programs, and communicate effectively with executive leadership and regulatory bodies.
Highest-signal resume keywords
Enterprise Information Security GovernanceCybersecurity Risk AssessmentGRC Program DevelopmentHITRUST CSF KnowledgeSOX Compliance Support
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Information SecurityRisk ManagementRegulatory CompliancePolicy ManagementControl FrameworksRisk QuantificationAutomated Control TestingGRC PlatformsCybersecurity ControlsExecutive Reporting
Soft Skills
LeadershipCommunicationInfluenceRelationship BuildingTeam Development
Tools & Technologies
GRC ToolingRisk Reporting ToolsAutomation ToolsEvidence Reuse Systems
Certifications & Qualifications
CISSPCISMCISACRISCCIPP
Industry Keywords
Healthcare CybersecuritySOX IT General ControlsSOC 1SOC 2NIST CSFISO 27001AI GovernanceSEC Cybersecurity Disclosure
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Lead CVS Health's enterprise information security governance, risk, technology compliance, and regulatory compliance strategy
- Drive the cybersecurity risk assessment program, including identification, quantification, tracking, remediation, and executive reporting of risk
- Modernize and automate GRC capabilities through evidence reuse, automated control testing, and AI-assisted risk quantification and reporting
- Ensure compliance with healthcare cybersecurity regulations, industry requirements, and applicable control frameworks
- Own enterprise technology compliance for cybersecurity controls, configurations, and platforms
- Direct the lifecycle of enterprise information security policies, standards, and procedures
- Serve as primary GRC liaison to Internal Audit, external auditors, and regulators
- Oversee SOX cybersecurity and IT general control support
- Lead SOC 1 and SOC 2 readiness and attestation support
- Own the security exception and risk acceptance process
- Establish and lead enterprise AI risk governance
- Align the enterprise risk framework, control taxonomy, and reporting with the vendor risk program
- Build partnerships with internal and external stakeholders to advance risk and compliance objectives
- Prepare and deliver cybersecurity risk posture reporting to the Board Risk/Audit Committee and executive governance forums
- Manage and mature GRC tooling and platforms
- Lead and develop the GRC team, succession planning, continuous improvement, and organizational transformation
Requirements
What you’ll need- Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent professional experience
- 10+ years of progressive experience in information security, IT risk management, or regulatory compliance
- 5+ years in a leadership role
- Deep knowledge of HITRUST CSF, SOX IT general controls, SOC 1/SOC 2, NIST CSF, ISO 27001, and related cybersecurity control frameworks
- Experience building or scaling an enterprise GRC program, including risk assessment and policy management
- Hands-on experience with GRC platforms and risk quantification/reporting tools, including automation and evidence reuse
- Ability to communicate risk and compliance matters to executive leadership, Board committees, auditors, and regulators
- Executive presence and ability to influence senior leaders
- Experience partnering with Internal Audit and managing external regulatory examinations
- Experience supporting SOX control testing, SOC readiness or attestation, audit evidence collection, control deficiency remediation, and executive-level compliance reporting
- Experience in a matrixed, multi-business-unit enterprise
- Ability to lead through influence and build trusted relationships across internal and external partner groups
- Enterprise people leadership and talent management experience
- Preferred: advanced degree (MBA or MS) or JD with cybersecurity and risk focus
- Preferred: CISSP, CISM, CISA, CRISC, or CIPP certification
- Preferred: experience in healthcare, pharmacy, health insurance, or retail
- Preferred: experience with AI governance, model risk management, or emerging AI regulation
- Preferred: familiarity with SEC cybersecurity disclosure requirements and materiality assessment processes
Benefits
Comp & perks- CVS Health bonus, commission or short-term incentive program in addition to base pay
- Award target in the company’s equity award program
- Medical coverage
- Dental coverage
- Vision coverage
- Paid time off
- Retirement savings options
- Wellness programs
- Other resources supporting physical, emotional, and financial well-being