Point your AI agent at freehire and let it find you a job.

Get the CLI →

Henry Ford Health

NewBe an early applicant

Lead-GRC IT Audit & Readiness

Posted Updated
Discussion

Summary

Leads IT audit coordination and readiness within Henry Ford Health's cybersecurity GRC team, serving as the central liaison for SOC 1/SOC 2 and General IT Controls audits, managing evidence collection and GRC tools, and guiding GRC specialists and control owners.

About the Role:

The Lead-Governance, Risk, and Compliance (GRC) Information Technology (IT) Audit & Readiness reports to the IT Security Compliance Manager within the Cybersecurity Governance, Risk, and Compliance (CGRC) organization and collaborates with Information Privacy and Security Office (IPSO) and IT team members to facilitate IT audits. These audits include SOC 1, SOC 2, General IT Controls, and other compliance assessments.

Key Tasks and Duties:

  1. Able to develop work with minimal supervision, maintain and report against a work plan, give appropriate updates and status reports, and serve as a point of contact and liaison with internal and external auditors, assessors, vendors and clients and assist other staff members.
  2. Provide Governance Risk and Compliance (GRC) support for third-party audit requests and reporting requests from leadership.
  3. Lead coordination and facilitation of IT audits (internal and external), acting as the central point of contact between auditors and internal stakeholders
  4. Drive the collection, review, and organization of audit evidence to ensure accuracy, completeness, and timely delivery
  5. Advise and partner with control owners to support audit readiness, including guidance on documentation, control execution, and remediation efforts
  6. Serve as the primary project coordinator for audit, compliance, and risk management activities, ensuring milestones, deadlines, and objectives are achieved.
  7. Establish and manage integrated audit and compliance plans, coordinating resources, timelines, dependencies, and deliverables across multiple initiatives.
  8. Champion use of GRC tools to manage audit workflows, extract evidence, and monitor control performance and compliance status
  9. Lead communication of audit requirements, follow-ups, and status updates clearly to internal teams and external auditors
  10. Develop, maintain, and monitor operational and strategic metrics to measure audit performance, compliance effectiveness, control health, and program maturity.
  11. Build and maintain relationships with key stakeholders across IPSO, Information Technology and business teams
  12. Monitor emerging regulatory requirements, industry trends, security frameworks, and best practices, providing guidance and recommendations to strengthen the organization's compliance posture.
  13. Provide day-to-day leadership and guidance to GRC Specialists, prioritizing work, removing barriers, and ensuring consistent execution of program objectives.
  14. Act as a subject matter expert and trusted advisor on audit coordination, compliance processes, GRC tools, and control governance.
  15. Execute GRC tool system test plans as necessary (ex. For system upgrades, updates, enhancements, new reporting).
  16. Participate in continuous learning initiatives specifically related to the GRC system, IT governance, controls, insurance, healthcare, leading security frameworks, and information technology.
  17. Supports Henry Ford Health as well as its subsidiaries.

Education & Experience:

  • Bachelor’s degree in Accounting, Information Systems, Computer Science or related field preferred, relevant work experience/certification considered.
  • Four plus (4+) years of experience in IT risk, IT Controls or IT Audit.
  • Demonstrates strong and effective verbal, written, and interpersonal communication skills, with experience in all at the executive level.
  • Ability to prioritize and multi-task in a dynamic, fast-paced, and challenging environment.
  • Experience with federal and state healthcare information regulations and requirements (e.g. HIPAA) preferred.
  • Advanced knowledge of IT systems and functions, process development, change management, and service and implementation lifecycle.
  • Knowledge of information security best practices, NIST Cybersecurity Framework , and common risk frameworks.
  • Can conform to shifting priorities, demands and timelines through analytical and problem-solving capabilities.

Certifications:

  • CISSP, CISA, CISM preferred.

Skills

What Lead Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available