Haystack
← Back to Jobs
Full time
Technology
KP

IT Consultant V, Governance Risk and Compliance

Kaiser PermanenteGreensboro, North Carolina🇺🇸United StatesPosted 9 Sept 2026

Why This Role Stands Out

This hybrid IT Consultant V role at Kaiser Permanente offers a significant opportunity to shape enterprise-level Governance, Risk, and Compliance initiatives within a leading healthcare organization, allowing you to develop expertise in critical regulatory standards and influence secure technology strategies. You'll thrive here if you possess strong experience in IT governance, risk management, and compliance frameworks, and are eager to mentor others while driving impactful solutions. Apply now to contribute to a mission-driven team and advance your career in a dynamic environment.

Quick Overview

Seniority
Mid Senior
Employment type
Full Time
Work mode
Hybrid
Location
Greensboro, North Carolina, United States
SOC 2HIPAA

Job Description

As an IT Consultant V in Governance, Risk, and Compliance at Kaiser Permanente, you'll lead enterprise GRC initiatives in a highly regulated IT environment. You will design and refine governance frameworks, assess technology and vendor risks, and ensure ongoing compliance with standards such as HIPAA, SOC 2, and ISO 27001. Partnering with engineering, security, and operations teams, you'll implement scalable controls, conduct audits, and drive remediation. You'll mentor junior consultants, influence strategy, and help build secure, user-focused technology that supports clinicians and patients system-wide.

Responsibilities

  • Lead enterprise IT governance, risk, and compliance programs
  • Design and maintain GRC frameworks and policies
  • Assess IT, security, and vendor risks and define mitigation plans
  • Ensure compliance with HIPAA, SOC 2, ISO 27001 and internal standards
  • Plan and support internal and external IT audits
  • Implement and optimize GRC tools and workflows
  • Partner with security, engineering, and operations on control design
  • Report risk and compliance posture to leadership and stakeholders
  • Drive remediation activities and continuous control improvement
  • Mentor junior GRC consultants and contribute to strategic planning

Required Skills

  • IT governance
  • Risk management
  • Regulatory compliance (HIPAA, SOC 2, ISO 27001)
  • Security controls assessment
  • Policy development
  • IT audit
  • GRC tools (e.g., Service
  • Now, Archer)
  • Vendor risk management
  • Data privacy
  • Stakeholder communication

Similar jobs