Director GRC & Security Architecture



Pay Grade: 33S


Context of Job:

The Director of GRC and Security Architecture is a senior leadership role responsible for governing the organization’s information security risk, compliance, and architectural security posture. This role provides enterprise-wide leadership across governance, risk management, regulatory compliance (including HIPAA), and security architecture to ensure security controls are designed, implemented, and operating effectively in support of business, academic, and clinical objectives.



Serving as the designated HIPAA Security Officer, this role partners closely with Legal, Privacy, Compliance, IT, Cloud, Application, and Security Operations teams to ensure regulatory readiness, risk-informed decision-making, and secure-by-design technology architecture across on-premises, cloud, and SaaS environments.

This position reports to the Chief Information Security Officer of the University.



Major Responsibilities:

Governance, Risk & Compliance (GRC)


  • Lead the enterprise Information Security Governance, Risk, and Compliance (GRC) program.
  • Establish and maintain security policies, standards, procedures, and control frameworks aligned with NIST, HITRUST, ISO 27001, and other applicable frameworks.
  • Oversee enterprise risk assessments, third-party risk management, and control effectiveness evaluations.
  • Translate regulatory, legal, and contractual requirements into actionable security controls and architectural standards.
  • Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS, FERPA, SOC 2, and FIPS-140, as applicable

HIPAA Security Officer Responsibilities

  • Serve as the organization’s designated HIPAA Security Officer.
  • Oversee administrative, technical, and physical safeguards required under the HIPAA Security Rule.
  • Partner with Privacy, Legal, Compliance, and Health IT leadership on risk analyses, remediation plans, and regulatory inquiries.
  • Support audits, investigations, and compliance reviews related to protected health information (PHI).
  • Ensure appropriate security awareness and HIPAA training programs are developed and delivered across the organization.
    Security Architecture & Secure Design
  • Own and lead the security architecture function, defining enterprise security architecture principles, reference architectures, and design standards.
  • Review and approve security architecture for new systems, applications, cloud services, and major technology initiatives.
  • Ensure security is embedded early in system lifecycle activities through secure-by-design and defense-in-depth principles.
  • Partner with infrastructure, cloud, application, and DevOps teams to integrate security requirements into platforms and solutions.
  • Guide architectural decisions related to identity, network segmentation, encryption, key management, logging, and data protection.

Strategic Planning & Program Leadership


  • Contribute to and lead multi-year security strategy and roadmap development in alignment with organizational objectives.
  • Actively participate in enterprise security and risk governance forums, advising executive leadership on risk posture and architectural trade-offs.
  • Balance risk reduction with operational efficiency, usability, and institutional mission requirements.
  • Serve as a trusted advisor to schools, departments, and business units on risk and architectural security decisions.

Oversight of Security Technologies & Controls

  • Provide governance and oversight for security technologies supporting risk management, compliance, and architectural controls.
  • Ensure alignment between security architecture standards and operational security tooling.
  • Evaluate new security technologies and frameworks to address evolving regulatory and threat landscapes.

Metrics, Reporting & Communication


  • Develop and report meaningful risk and compliance metrics to senior leadership and governance committees.
  • Communicate complex security and compliance topics clearly to technical and non-technical stakeholders.
  • Provide executive-level reporting on risk trends, compliance posture, and architectural maturity.

Leadership & Talent Development

  • Lead and develop GRC and security architecture professionals.
  • Establish clear role definitions, performance expectations, and professional development pathways.
  • Foster a culture of accountability, continuous improvement, and collaboration across security and IT teams.

Budget, Vendor & Resource Management


  • Manage budgets associated with GRC, compliance, and security architecture programs.
  • Oversee vendor relationships related to risk management, compliance tooling, and architectural services.
  • Ensure responsible financial stewardship and alignment with strategic priorities.



Qualifications:

  • Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field (Master’s preferred).
  • Seven years of progressive experience in information security, risk management, or IT, including leadership roles.
  • Demonstrated experience leading GRC programs, regulatory compliance efforts, and enterprise risk management.
  • Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory frameworks.
  • Proven experience defining and governing security architecture across enterprise and cloud environments.
  • Excellent written and verbal communication skills, including executive-level presentations.
  • Experience supporting healthcare, higher education, or regulated enterprise environments preferred.
  • Hands-on experience with NIST, HITRUST CSF, ISO 27001, SOC 2, and third-party risk frameworks preferred.
  • Professional certifications such as CISSP, CISM, CRISC, or equivalent preferred.
  • Experience partnering closely with SOC, IR, Privacy, and Legal teams preferred.
  • Demonstrated success leading organizational change and maturing security governance programs preferred.

Source

To apply, please visit the following URL:

Advert 2 *
1
Latest Article
2

Table of Contents

Sponsor
Youtube
3
Youtube
4
Keep Reading

Related Article

map

9 / 100 Powered by Rank Math SEO SEO Score

Construction Accident Lawyer Near Me Tochigi

Construction Accident Lawyer Near Me Tochigi

78 / 100 Powered by Rank Math SEO SEO Score Search The Site looking up for more resources Search Bar Advert 1 * Construction Accidents in Tochigi: Industrial Hubs, Rural Sites, and Winter Conditions Require Expert Legal Support Tochigi Prefecture, located in Japan’s northern Kantō region and home to over 1.9 million people, sustains a varied construction industry shaped by its industrial base, agricultural heritage, and tourism attractions. Major activities include factory and warehouse builds in Utsunomiya and Oyama industrial zones, high-tech and automotive-related facilities, rural agricultural infrastructure (greenhouses, livestock barns, rice warehouses), tourism developments (hot-spring ryokans and resort upgrades in Nikko National Park), seismic retrofitting across the prefecture (due to earthquake risk), and transportation/infrastructure projects (highways, rail extensions). The sector employs tens of thousands, including skilled trades, laborers, and many foreign technical intern and specified skilled workers. Despite national regulations under the Industrial Safety and Health Act and Construction Occupational Safety and Health Regulations, construction ranks among Tochigi’s most hazardous industries. Ministry of Health, Labour and Welfare (MHLW) and Tochigi Labor Bureau data show construction contributing significantly to workplace fatalities and injuries in the prefecture, with falls from height, struck-by incidents, heavy machinery accidents, trench collapses, and cold-weather incidents prominent. Winter snow and ice in northern/mountainous areas (Nikko, Nasu), combined with industrial density in southern zones (Utsunomiya, Oyama) and rural isolation, heighten risks. Foreign workers face elevated exposure, consistent with national trends of rising foreign-worker cases in construction. When employer negligence—poor scaffolding/fall protection, inadequate risk assessments for industrial machinery or winter conditions, insufficient training, faulty equipment, or rushed schedules—causes harm, victims or families can claim Workers’ Accident Compensation Insurance (rōsai hoken) benefits and pursue civil damages against employers/contractors for safety duty breaches (安全配慮義務違反). A specialized **construction accident lawyer in Tochigi** is essential to navigate Tochigi Labor Standards Inspection Offices (Utsunomiya, Oyama, Ashikaga, etc.), address industrial/rural differences, and secure maximum compensation. Photo caption: Industrial construction site in Utsunomiya or Oyama area, Tochigi—dense heavy machinery and factory work create high-risk environments. (Conceptual stock image) Advert 2 * Typical Construction Accidents and Life-Changing Injuries Across Tochigi Prefecture Tochigi construction accidents often reflect industrial, rural, and seasonal conditions: Falls from height (scaffolds, roofs, unguarded edges in Utsunomiya high-rises or Nikko tourism builds) Struck-by incidents (falling materials, swinging crane loads, vehicles in busy industrial zones) Heavy machinery accidents (cranes, excavators, forklifts) in factories, warehouses, or rural projects Trench/excavation collapses during urban redevelopment or agricultural infrastructure work Slips/trips on icy, snowy, or uneven surfaces (winter in Nikko/Nasu, rural sites) Electrocution or contact with live wires/chemicals during industrial retrofitting Vehicle/plant incidents on highways or construction zones near traffic Overexertion and chronic strain from manual handling in large-scale projects Injuries range from minor to catastrophic: traumatic brain injuries (TBIs), spinal cord damage causing paralysis, amputations, multiple fractures, severe lacerations, internal trauma, and long-term musculoskeletal disorders. Fatalities frequently involve falls, crushing, or machinery incidents. Psychological trauma like PTSD is common after serious events. Medical costs—treatment at Jichi Medical University Hospital (Shimotsuke), Dokkyo Medical University Hospital (Mibu), Tochigi Medical Center, or regional facilities—plus rehabilitation, surgeries, and adaptive equipment can reach millions of yen, compounded by lost wages and varying employment opportunities across urban/rural areas. Rōsai hoken covers medical expenses, temporary disability benefits (60-80% wage replacement), disability pensions, and survivor payments for certified cases, but often excludes full pain/suffering (慰謝料) or complete lost earnings. A **construction accident lawyer near me in Tochigi** evaluates combined rōsai + civil claims to achieve comprehensive recovery. Advert 3 * Japan’s Workers’ Compensation and Why Tochigi Specialists Are Essential Workers’ Accident Compensation Insurance (rōsai hoken), governed by the Industrial Accident Compensation Insurance Act, covers all employees (including foreign workers) for work-related injuries, illnesses, and commuting accidents. Benefits include full medical costs, temporary compensation, disability/survivor pensions, and lump sums. Applications are filed at Tochigi Labor Standards Inspection Offices (Utsunomiya, Oyama, Ashikaga, Sano, Nikko-area service points, etc.), with appeals possible to examination committees. Rōsai provides statutory minimums—excluding full慰謝料 or excess lost earnings. Victims can file separate civil suits against employers/contractors for safety duty violations, seeking additional damages. These require proving negligence, especially in industrial or winter-related cases, and collecting evidence (photos, witnesses, records). Tochigi-based rōsai attorneys deliver: Free initial consultations (phone, LINE, Zoom, or in-person) Rōsai application/appeal support for higher disability grades Civil claim preparation against employers or third parties Evidence gathering and expert coordination (medical, engineering, safety specialists) Interim payments and long-term financial planning Reputable firms include Utsunomiya-based practices (e.g., lawyers from local labor/accident specialists or firms like Tochigi Labor Law Office), Oyama Sōgō Law Office, Ashikaga-area attorneys, Nikko tourism-related law offices, and national chains like Bright Law Firm or VeryBest Law Offices with Tochigi outreach—many offering multilingual support for foreign workers and free advice across the prefecture. Advert 4 * Critical Actions After a Construction Injury in Tochigi Prefecture If injured on a Tochigi site: Seek immediate medical attention — Use site first aid, then hospital/A&E; retain all records—early documentation supports rōsai certification. Report the incident — Notify supervisor/contractor; ensure accident log entry and reporting if serious (Labor Standards Office may investigate). Document thoroughly — Photograph injuries, scene, equipment faults, PPE issues, industrial/winter conditions; collect witness contacts. Avoid premature statements — Decline recorded insurer/employer interviews without counsel—early admissions can reduce claims. Contact a lawyer promptly — Three-year civil claim limitation (from awareness); rōsai deadlines apply. Many Tochigi firms offer free consultations via phone/LINE and home/hospital visits, even in rural/industrial areas. Limit social media — Posts can harm credibility with insurers or courts. Act fast—evidence (photos, logs) can disappear quickly on active industrial or rural sites. A **construction accident lawyer near me in Tochigi** launches investigations immediately, often improving disability outcomes and securing additional employer compensation. Advert 5 * Compensation Outlook and Selecting a Specialist Construction Accident Lawyer in Tochigi Rōsai-certified benefits cover medical costs, wage replacement, disability/survivor pensions, and lump sums. Civil suits add慰謝料 (often ¥1-10 million+ for severe cases), full lost earnings, and future care—potentially millions of yen for catastrophic injuries, especially in industrial zones with high living costs. Foreign workers qualify fully,