Senior Lead Cyber Compliance
Listed on 2026-09-30
-
IT/Tech
-
Business
Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients.
With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives. Labcorp is a global leader in diagnostic testing and drug development solutions, helping healthcare providers, researchers, and patients make informed decisions that advance care.
Join us in our mission to improve health and improve lives.
This is a full-time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. in EDT time zone. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible.
RESPONSIBILITIES- Framework Strategy & Rationalization:
Enable strategic alignment and rationalization across SOC2 Type 2, ISO 27001, NIST SP 800-53, PCI DSS, SOX ITGCs, FedRAMP, and CMMC (and related customer/regulatory requirements) to avoid duplicative effort and an unsustainable annual workload. Support transitions between assurance approaches where appropriate (e.g., simplifying overlapping requirements) to meet expectations such as state and sector requirements (including TX-RAMP where applicable). Perform control mapping activities;
identifying overlaps, gaps, and efficiency opportunities across standards, internal policies, and contractual obligations. - Evidence Management, Customer Assurance, and Regulatory Support:
Preserve consistent, high-quality evidence production for assessments, customer RFIs, and regulatory requirements—reducing execution risk and downstream disruption. Build and maintain a well-governed evidence repository with clear traceability, version control, retention, and audit defensibility aligned to enterprise standards. Coordinate timely, accurate responses to customer security questionnaires and assurance requests in partnership with control owners. - Operational Risk Management & Issue Lifecycle:
Maintain effective operational risk management coverage, ensure monitoring, documentation, and issue lifecycle management continue without erosion as scope expands. Track findings, exceptions, risks, and remediation activities; coordinate validation and closure documentation aligned to governance expectations. Support risk reporting and governance cadence (e.g., risk forums, control owner check-ins) with clear status, trends, and escalation points. - Continuity, Capacity, and Compliance Operations Excellence:
Mitigate concentration and continuity risk within compliance/GRC by reducing reliance on a single overextended resource for critical audit and risk functions through documentation, process standardization, and repeatable operating routines. Develop scalable compliance artifacts (templates, checklists, playbooks) to improve consistency and reduce rework across cycles. Sustain audit readiness and customer confidence during increased compliance demands and post-acquisition integration complexity. - Stakeholder…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).