As an IT Consultant V in Governance, Risk, and Compliance at Kaiser Permanente, you'll lead enterprise GRC initiatives in a highly regulated IT environment. You will design and refine governance frameworks, assess technology and vendor risks, and ensure ongoing compliance with standards such as HIPAA, SOC 2, and ISO 27001. Partnering with engineering, security, and operations teams, you'll implement scalable controls, conduct audits, and drive remediation. You'll mentor junior consultants, influence strategy, and help build secure, user-focused technology that supports clinicians and patients system-wide.
Responsibilities
- Lead enterprise IT governance, risk, and compliance programs
- Design and maintain GRC frameworks and policies
- Assess IT, security, and vendor risks and define mitigation plans
- Ensure compliance with HIPAA, SOC 2, ISO 27001 and internal standards
- Plan and support internal and external IT audits
- Implement and optimize GRC tools and workflows
- Partner with security, engineering, and operations on control design
- Report risk and compliance posture to leadership and stakeholders
- Drive remediation activities and continuous control improvement
- Mentor junior GRC consultants and contribute to strategic planning
Required Skills
- IT governance
- Risk management
- Regulatory compliance (HIPAA, SOC 2, ISO 27001)
- Security controls assessment
- Policy development
- IT audit
- GRC tools (e.g., Service
- Now, Archer)
- Vendor risk management
- Data privacy
- Stakeholder communication