2

Remote Governance Risk Compliance Jobs (NOW HIRING)

This role executes governance, risk, and compliance activities aligned with regulatory frameworks ... remote with occasional in-person sessions. Additional qualifications required for Level II: * 3 ...

Governance, Risk and Compliance tools. Knowledge, Skills & Abilities: * Knowledge of:GRC, information security, and cybersecurity principles, phishing campaigns, cybersecurity awareness and training ...

The Senior Manager also develops and mentors colleagues, shapes operating routines, and drives continuous improvement in governance, risk management, and compliance practices for Health Engagement ...

Showing results 21-40

Remote Governance Risk Compliance information

See salary details

$99K

$191.8K

$384K

How much do remote governance risk compliance jobs pay per year?

As of Aug 27, 2026, the average yearly pay for remote governance risk compliance in the United States is $191,763.00, according to ZipRecruiter salary data. Most workers in this role earn between $168,500.00 and $190,500.00 per year, depending on experience, location, and employer.

What is a remote Governance Risk Compliance (GRC) professional?

A Remote Governance Risk Compliance (GRC) professional is responsible for ensuring that an organization adheres to legal, regulatory, and internal policies related to risk management and corporate governance, all while working from a remote location. They assess risks, implement compliance programs, and develop policies that help prevent violations and mitigate risks. These professionals use digital tools to monitor compliance, conduct audits, and report findings to management or regulatory bodies, ensuring that the organization operates ethically and within the law, regardless of where they are physically located.

What are the key skills and qualifications needed to thrive as a remote Governance Risk Compliance (GRC) professional?

To succeed as a Remote Governance Risk Compliance professional, you need a strong understanding of regulatory frameworks, risk management principles, and compliance standards, often backed by a relevant degree and certifications such as CISA, CISSP, or CRISC. Familiarity with GRC platforms (like RSA Archer or LogicGate), data analytics tools, and documentation systems is crucial for effective monitoring and reporting. Outstanding analytical thinking, attention to detail, and clear communication set top candidates apart in remote environments. These competencies ensure regulatory adherence, minimize organizational risks, and maintain a robust compliance posture even from a distance.

What are some common challenges faced by professionals in remote Governance Risk Compliance (GRC) roles, and how can they be effectively managed?

One common challenge in remote GRC roles is maintaining clear communication and coordination with cross-functional teams, as GRC professionals often work with IT, legal, and operations departments. Staying updated on regulatory changes and ensuring timely compliance across distributed teams can also be complex. To manage these challenges, it's important to leverage collaboration tools, establish regular check-ins, and use centralized documentation systems. Building strong virtual relationships and setting clear expectations with stakeholders can further support effective risk management and compliance.

Can remote governance risk compliance jobs be remote?

Remote governance risk compliance jobs are commonly available, especially as many organizations adopt flexible work arrangements. These roles often require skills in risk management, compliance frameworks, and familiarity with remote collaboration tools, making remote work feasible for qualified candidates.

How to get into remote governance risk compliance?

To enter remote governance risk compliance roles, candidates typically need a bachelor's degree in fields like business, law, or cybersecurity, along with knowledge of regulatory frameworks and risk management practices. Gaining certifications such as Certified in Risk and Information Systems Control (CRISC) or Governance, Risk, and Compliance (GRC) certifications can enhance prospects. Strong analytical skills, familiarity with compliance tools, and experience working remotely are also valuable for success in this field.

Is remote governance risk compliance a good career?

Remote governance risk compliance is a growing field that involves ensuring organizations adhere to regulations and manage risks effectively, often requiring knowledge of compliance frameworks and risk management tools. It offers opportunities for remote work, career advancement, and specialization in areas like cybersecurity and data privacy. The role typically requires relevant certifications and strong analytical skills.
More about Remote Governance Risk Compliance jobs

What cities are hiring for Remote Governance Risk Compliance jobs?

Cities with the most Remote Governance Risk Compliance job openings:

What are the most commonly searched types of Governance Risk Compliance jobs?

The most popular types of Governance Risk Compliance jobs are:

What states have the most Remote Governance Risk Compliance jobs?

States with the most job openings for Remote Governance Risk Compliance jobs include:

Infographic showing various Remote Governance Risk Compliance job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $191,763 per year, or $92.2 per hour.

Assistant Vice President (AVP) Governance, Risk & Compliance (GRC)

CVS Health

Remote

$129K - $173K/yr

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 14 days ago


CVS Health rating

5.8

Company rating: 5.8 out of 10

Based on 4,351 frontline employees who took The Breakroom Quiz

90th of 113 rated pharmacies


Job description

We're building a world of health around every individual - shaping a more connected, convenient and compassionate health experience. At CVS Health, you'll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselvesaccountable and prioritize safety and quality in everything we do. Join us and be part of something bigger - helping to simplify health care one person, one family and one community at a time.

Position Summary

The AVP Governance, Risk & Compliance (GRC) leads the strategy, design, and execution of CVS Health's enterprise information security governance, risk management, technology compliance, and regulatory compliance program, including the modernization of GRC through automation, evidence reuse, and AI-assisted risk quantification and reporting.

Reporting to the Deputy CISOandpartneringclosely withthe CISO, this leadermanagescybersecurity risk posture,controls, technology compliance, and regulatory obligationswhile driving continuous improvement.The AVP builds trustedrelationships acrossSecurity,Third-Party Risk,Audit, Legal, Finance,regulators,vendors,and businessleaders to translate risk into clear,actionable priorities.

Key Responsibilities

  • Lead the development and execution of CVS Health's enterprise information security governance, risk, technology compliance, and regulatory compliance strategy, aligned to businessobjectivesand enterprise risk appetite, working in close partnership with both the CISO and Deputy CISO.

  • Drive the cybersecurity risk assessment program - identification, quantification, tracking, and remediation of risk - and report risk posture and trends to the Deputy CISO, CISO, and leadership committees.

  • Lead the modernization and automation of GRC capabilities, includingevidencereuse, automated control testing, and AI-assisted risk quantification and reporting, to improve speed, accuracy, and scalability of the program.

  • Ensure the security program's continued compliance with the full range of regulatory and industry requirements applicable to cybersecurity in healthcare - including HIPAA, HITECH, 42 CFR Part 2, CMS security and privacy requirements, FDA requirements where applicable, state insurance and privacy laws, PCI DSS,SOX, SOC 1/SOC 2,and SEC cybersecurity disclosure requirements - as well as other frameworks relevant to CVS Health's retail, pharmacy, and health services lines of business.

  • Own enterprise technology compliance for cybersecurity, ensuring technology controls, configurations, and platforms across the enterprise meet applicable regulatory, contractual, and internal policy requirements.

  • Direct the lifecycle of enterprise information security policies, standards, and procedures, ensuring theyremaincurrent, enforceable, and aligned to NIST CSF, ISO 27001, HITRUST CSF, and other adopted control frameworks.

  • Serve as the primary GRC liaison to Internal Audit, external auditors, and regulators; coordinate audit and examination responses and drivetimelyremediation of findings.

  • Oversee SOX cybersecurity and IT general control support, including coordination with Finance, Internal Audit, control owners, and external auditors to define control scope,validateevidence, track deficiencies, and supporttimelyremediation.

  • Lead SOC 1 and SOC 2 readiness and attestation support for applicable services and platforms, including control mapping, evidence management, audit coordination, exception handling, and continuous improvement of trust services control coverage.

  • Own the security exception and risk acceptance process, ensuringappropriate executivevisibility and accountability for accepted risk.

  • Establish and lead enterprise AI risk governance, including oversight of AI-related security, privacy, and regulatory risk across internally developed and third-party AI capabilities.

  • PartnerwithSecurityRisk Management leadership to ensure the enterprise risk framework, control taxonomy, and reporting are aligned with the vendor risk program, without duplicating ownership.

  • Buildstrongpartnerships with internalandexternalstakeholdersto strengthen alignment, resolve issues, and advance enterprise risk and complianceobjectives.

  • Prepare and deliver regular cybersecurity risk posture reporting to the Board Risk/Audit Committee and other executive governance forums.

  • Manage and mature GRC tooling and platforms to support risk quantification, control testing, and reporting automation.

  • Lead and develop the GRC team,buildingsuccession bench strength, andfosteringa culture of accountability, continuous improvement, business partnership, and effective change leadership through organizational transformation.

Required Qualifications

  • Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field, or equivalent professional experience.

  • 10+ years of progressive experience in information security, IT risk management, or regulatory compliance, including 5+ years in a leadership role.

  • Deep working knowledge of regulatory and control frameworks applicable to a large, regulated enterprise, including HITRUST CSF, SOX IT general controls, SOC 1/SOC 2, NIST CSF, ISO 27001, and related cybersecurity control frameworks.

  • Demonstrated experience building or scaling an enterprise GRC program, including risk assessment and policy management.

  • Hands-on experience with GRC platforms and risk quantification/reporting tools, including automation andevidencereuse capabilities.

  • Proven ability to communicate risk and compliance matters clearly to executive leadership, Board committees, auditors, and regulators.

  • Demonstrated executive presence, with the ability to influence senior leaders, represent the GRC function in executive forums, and communicate complex risk and compliance matters with clarity, credibility, and sound judgment.

  • Experience partnering with Internal Audit and managing external regulatory examinations.

  • Experience supporting SOX control testing, SOC readiness or attestation activities, audit evidence collection, control deficiency remediation, and executive-level reporting on compliance posture.

  • Experienceoperatingwithin a matrixed, multi-business-unit enterprise (e.g., retail, pharmacy, health services, or similarly complex organizational structures).

  • Proven ability to lead through influence and build trusted relationships across internal and external partner groups, including senior business leaders, technology teams, Legal, Finance, Internal Audit, regulators, external auditors, consultants, and third-party service providers.

  • Proven enterprisepeopleleadership and talent management experience, including building, developing, coaching, andretaininghigh-performing teams; cultivating succession bench strength; and leading leaders through organizational change.

Preferred Qualifications

  • Advanced degree (MBA or MS) in a related discipline, or JD withcybersecurity and risk focus.

  • Relevant certifications such as CISSP, CISM, CISA, CRISC, or CIPP.

  • Experience in healthcare, pharmacy, health insurance, or retail industries.

  • Experience with AI governance, model risk management, or emerging AIregulation.

  • Familiarity with SEC cybersecurity disclosure requirements and materiality assessment processes.

This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.


Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.


Great benefits for great people


We take pride in offering a comprehensive and competitive mix of pay and benefits that reflects our commitment to our colleagues and their families.

This fulltime position is eligible for a comprehensive benefits package designed to support the physical, emotional, and financial wellbeing of colleagues and their families. The benefits for this position include medical, dental, and vision coverage, paid time off, retirement savings options, wellness programs, and other resources, based on eligibility.


Additional details about available benefits are provided during the application process and on Benefits Moments.

We anticipate the application window for this opening will close on: 09/02/2026

Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.


What CVS Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom