Signify Health

Signify Health

Lead Director - Third Party Security, Assessment Operations

Work at Home, Colorado, United States · Director · Full-time

Sponsorship not specified$144k-$288kDetected 31 days ago
CybersecurityComplianceProcurementHIPAALeadershipCommunication

About the role

  • The role also shapes enterprise-wide risk and control assurance efforts by bringing visibility, consistency, and accountability to third-party risk management.

Responsibilities

  • Third Party Security Leadership Own and continuously mature the enterprise Third Party Security program, including processes, and tooling.
  • Direct staff in the identification, development, implementation, and maintenance of security assessment practices for all third parties - including vendors, suppliers, and business partners.
  • Build, coach, and lead a high-performing team of security professionals spanning Individual Contributors, Managers, and Senior Managers.
  • Risk Assessment & Control Assurance Lead the evaluation and assessment of emerging cyber threats, vulnerabilities, and attack vectors relevant to third party ecosystems.
  • Develop and enforce risk-based remediation strategies derived from assessment findings and lessons learned.
  • Implement and enforce security controls within third parties supporting large, complex, and diverse enterprise environments.
  • Monitor evolving regulatory and industry landscapes and proactively adjust program requirements to maintain compliance.
  • This role leads the end-to-end lifecycle of third-party security assessments, ensuring that risks are identified early, understood clearly, and addressed effectively.
  • By building and advancing a scalable, risk-based assessment program, this position helps safeguard the enterprise while enabling the business to move forward with confidence in its external partnerships.
  • This leader partners closely with Procurement, Legal, Compliance, and business units to embed security into the full vendor lifecycle and translate complex cyber risks into clear, actionable guidance.

Requirements

  • 10+ years of progressive Information Security experience, with a strong foundation across risk management, architecture, and engineering domains.
  • 7+ years of direct leadership experience managing security professionals in both direct and matrixed reporting structures.
  • 5+ years of experience building and leading Third Party Security Risk or Vendor Risk Management programs at enterprise scale.
  • 5+ years of experience leading detailed control testing, regulatory audits, and compliance assessments.
  • 3+ years of experience implementing security controls within third party environments supporting large, complex enterprises.

Nice to have

  • Exceptional communication and executive presentation skills
  • ability to translate technical risk into business language for non-technical audiences.
  • Strong command of risk analysis frameworks and the ability to derive well-defined mitigation strategies from assessment findings.
  • Superior organizational and process management skills
  • Proficiency with Third Party Risk platforms (e.g., Archer, SecurityScorecard, ServiceNow, BlackKite) and GRC tooling.
  • Our people fuel our future.
  • Our employees are self-disciplined, hard working, curious, trustworthy, humble, and truthful.

Compensation

  • $144,200.00 - $288,400.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls.
  • The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors.
  • This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.
  • Our people fuel our future.
  • Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
  • Great benefits for great people We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

Benefits

  • We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience.
  • At CVS Health®, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do.
  • Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.
  • Provide authoritative security guidance to project teams, portfolio personnel, and business leaders to ensure alignment with CVS Health control standards.
  • This position also includes an award target in the company's equity award program.
  • The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.

Company info

  • our culture, our core values, our company meetings, our commitment to sustainability, our recognition programs, but most importantly, it's our people.
  • They make choices according to what is best for the team, they live for opportunities to collaborate and make a difference, and they make us the #1 Top Workplace in the area.

This listing is sourced directly from Signify Health's careers page and normalized into a canonical job model.