Assistant Vice President (AVP) Governance, Risk & Compliance (GRC)
CVS Health
- Location
- CA - Work from home
- Work model
- Remote
- Level
- Staff
- Posted
- Aug 12, 2026
Skills
About this role
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time.
Position
Summary The AVP Governance, Risk & Compliance (GRC) leads the strategy, design, and execution of CVS Health's enterprise information security governance, risk management, technology compliance, and regulatory compliance program, including the modernization of GRC through automation, evidence reuse, and AI-assisted risk quantification and reporting. Reporting to the Deputy CISO and partnering closely with the CISO , this leader manages cybersecurity risk posture, controls , technology compliance , and regulatory obligations while driving continuous improvement. The AVP builds trusted relationships across Security , Third - Party Risk , Audit, Legal, Finance, regulators, vendors, and business leaders to translate risk into clear , actionable priorities.
Key Responsibilities
Lead the development and execution of CVS Health's enterprise information security governance, risk, technology compliance, and regulatory compliance strategy, aligned to business objectives and enterprise risk appetite, working in close partnership with both the CISO and Deputy CISO . Drive the cybersecurity risk assessment program — identification, quantification, tracking, and remediation of risk — and report risk posture and trends to the Deputy CISO, CISO, and leadership committees. Lead the modernization and automation of GRC capabilities, including evidence reuse, automated control testing, and AI-assisted risk quantification and reporting, to improve speed, accuracy, and scalability of the program. Ensure the security program's continued compliance with the full range of regulatory and industry requirements applicable to cybersecurity in healthcare — including HIPAA, HITECH, 42 CFR Part 2, CMS security and privacy requirements, FDA requirements where applicable, state insurance and privacy laws, PCI DSS, SOX, SOC 1/SOC 2, and SEC cybersecurity disclosure requirements — as well as other frameworks relevant to CVS Health's retail, pharmacy, and health services lines of business. Own enterprise technology compliance for cybersecurity, ensuring technology controls, configurations, and platforms across the enterprise meet applicable regulatory, contractual, and internal policy requirements. Direct the lifecycle of enterprise information security policies, standards, and procedures, ensuring they remain current, enforceable, and aligned to NIST CSF, ISO 27001, HITRUST CSF, and other adopted control frameworks. Serve as the primary GRC liaison to Internal Audit, external auditors, and regulators; coordinate audit and examination responses and drive timely remediation of findings. Oversee SOX cybersecurity and IT general control support, including coordination with Finance, Internal Audit, control owners, and external auditors to define control scope, validate evidence, track deficiencies, and support timely remediation. Lead SOC 1 and SOC 2 readiness and attestation support for applicable services and platforms, including control mapping, evidence management, audit coordination, exception handling, and continuous improvement of trust services control coverage. Own the security exception and risk acceptance process, ensuring appropriate executive visibility and accountability for accepted risk. Establish and lead enterprise AI risk governance, including oversight of AI-related security, privacy, and regulatory risk across internally developed and third-party AI capabilities. Partner