Title: Head of IT Governance, Risk, and Compliance (GRC)
Location: Remote - US, 2304 Silverdale Drive, Johnson City, Tennessee, United States of America
LabConnect is seeking a senior leader to establish and mature our IT Governance, Risk, and Compliance function — and to lead the organization in using AI itself as the engine of that compliance. This is a build role for a leader who believes that in a GxP environment, controls should be authored, tested, and enforced continuously by intelligent systems rather than rediscovered during an audit. You will own the strategy and operating model that advances compliance across SOC 2, HIPAA, GDPR, and FDA 21 CFR Part 11, while deploying AI and agentic tooling to draft and maintain SOPs, detect compliance gaps across our code and configuration, and enforce regulated-development standards at the point of work. In parallel, you will govern AI adoption responsibly across internal workflows and product development, setting the validation and oversight standards that make AI trustworthy in a healthcare context. Position Overview: In this role, you will work closely with teams across infrastructure, security, engineering, data, quality, and operations to make compliance a continuous, largely automated property of how LabConnect builds and operates — not a documentation exercise performed after the fact. You will define the target state for an AI-enabled GxP control environment and the roadmap to reach it: AI-assisted authoring and maintenance of SOPs and controlled documents, automated detection of compliance and validation gaps across code, configuration, and infrastructure, agentic development rules that encode regulated-engineering requirements directly into the tools engineers use every day, and continuous evidence collection that keeps the organization audit-ready by default. At the same time, you will govern the AI systems themselves — establishing the validation, human-oversight, transparency, and monitoring standards required for AI to be used safely in clinical research and healthcare — working in partnership with the Quality team that owns CSV and GxP validation. Key Areas of Responsibilities AI-Enabled Compliance Operations: You will lead LabConnect’s shift from periodic, manual compliance work to continuous, AI-assisted compliance. This includes deploying AI to draft, revise, and maintain SOPs, work instructions, and controlled documentation against current regulation and actual practice; keeping the SOP register, change history, and training impact current; and surfacing drift between what our procedures say and what our systems actually do. Automated Compliance Gap Detection: You will establish the capability to scan code, configuration, infrastructure-as-code, pipelines, and system documentation for compliance and validation gaps — Part 11 controls such as audit trails, electronic signature, access control, and record retention; privacy and PHI handling; and change-control evidence — surfacing findings continuously to engineering teams rather than at audit time. Agentic Development Rules and Policy-as-Code: You will define and enforce the guardrails that govern AI-assisted and agentic software development in a regulated environment: repository-level rule sets that encode regulated-engineering requirements into the coding agents themselves, mandatory human review and approval gates, traceability from requirement to code to test evidence, explicit boundaries on autonomous agent action in validated systems, and automated checks that block non-compliant changes before they merge. AI Governance and Healthcare AI Compliance: You will own the governance framework, review process, and risk controls for LabConnect’s AI-first internal workflows and AI-enabled product capabilities. This includes acceptable-use standards, model and vendor oversight, data handling, human-in-the-loop requirements, auditability, validation of AI outputs that carry regulatory or clinical weight, and ongoing monitoring for drift — aligned to HIPAA, the NIST AI Risk Management Framework, ISO/IEC 42001, EU AI Act considerations, and FDA expectations for AI in regulated healthcare settings. Regulatory Compliance and Continuous Audit Readiness: You will assess LabConnect’s current controls, documentation, and operating practices across frameworks such as SOC 2, HIPAA, GDPR, and FDA 21 CFR Part 11, then shape the strategy, roadmap, and governance processes needed to strengthen compliance maturity — with automated evidence collection and continuous control monitoring replacing manual audit preparation wherever it can be defended to an auditor. Security Governance and Architecture: You will help define and guide governance, risk, and compliance practices for modern access, endpoint, and virtual desktop environments, including secure approaches that support remote work and bring-your-own-device models. Data Protection and Loss Prevention: You will strengthen data protection practices, including classification, monitoring, and loss prevention controls, with particular attention to what data may enter prompts, model training, and agent context windows across collaboration, engineering, and operational platforms. Third-Party and Model Risk Management: You will evaluate and monitor the security and compliance posture of external partners, vendors, and service providers — including AI model providers, agentic development tooling, and AI features embedded in platforms we already run — that support important business and regulated processes. Cross-Functional Leadership: You will partner closely with technology and business leaders to embed compliance, validation, and risk management into delivery in a way that supports both operational rigor and speed. You will work alongside the Quality team, which owns CSV and GxP validation, to ensure that IT controls, automated evidence, and AI-assisted documentation are accepted as validation-grade and aligned with FDA 21 CFR Part 11 and risk-based computer software assurance expectations. Core Competencies & Skills Leadership Experience: You bring strong leadership experience in IT security, compliance, risk management, or GRC, ideally within a high-growth, cloud-enabled, or highly regulated environment, and you have led change in how compliance work itself gets done. AI-Enabled Compliance Delivery: You have put AI to work on compliance problems, not only governed it from the outside. Experience with AI-assisted authoring of controlled documents, automated control or code scanning, policy-as-code, or agentic development workflows is highly valued — along with the judgment to know which outputs require human review before they carry regulatory weight. Regulatory, Framework, and AI Governance Expertise: You have a strong working knowledge of major security and privacy frameworks such as SOC 2, ISO 27001, HIPAA, and GDPR, along with practical command of AI governance standards including the NIST AI Risk Management Framework and ISO/IEC 42001. Experience applying risk-based controls to AI use cases — privacy safeguards, vendor oversight, auditability, and model governance — is expected. Life Sciences and GxP Knowledge: You understand life sciences, healthcare, or other regulated industries, including GxP, FDA 21 CFR Part 11, computer system validation, and risk-based computer software assurance, and how validation expectations apply when software is written or reviewed with AI assistance. Technical Understanding: You bring a solid understanding of cloud platforms, data governance, identity and access management, endpoint and virtual desktop security, enterprise integration patterns, and modern engineering practice — source control, CI/CD, infrastructure-as-code, and AI coding agents — sufficient to set rules that engineers can follow and that hold up in an audit. Executive Communication: You are comfortable communicating complex risk, compliance, and security topics clearly and credibly to senior leaders, auditors, clients, and cross-functional stakeholders — including explaining and defending an AI-enabled approach to compliance to sponsors and regulators. Qualifications & Experience Bachelor’s degree in computer science, engineering, information systems, or a related field is required; an advanced degree is a plus. You bring 15+ years of progressive leadership experience across IT security, risk, compliance, or GRC, including accountability for a regulated control environment, along with a demonstrated track record of building strong teams and leading meaningful transformation. You have led successfully at a senior executive or enterprise leadership level, with accountability for compliance strategy, organizational capability, and audit outcomes in complex environments. You have introduced AI or intelligent automation into compliance, quality, or regulated documentation workflows and carried it through to adoption and auditor acceptance — not just to pilot. You have hands-on familiarity with modern engineering practice, including source control, CI/CD, infrastructure-as-code, AI-assisted development, and emerging agentic approaches, sufficient to define enforceable rules for how software is built in validated systems. You have a strong grasp of data architecture and data governance, including relational, unstructured, blob, and vector-based data models, and the control considerations that follow when that data feeds AI-enabled solutions. You have significant experience in Microsoft Azure environments, including platforms such as Purview, Entra ID, Defender, Azure Data Lake, and Azure AI services. You have a demonstrated record of audit and inspection success across frameworks such as SOC 2, HIPAA, GDPR, or FDA 21 CFR Part 11, and of partnering with engineering leaders to deliver resilient, compliant, and scalable solutions without stalling delivery. Experience in regulated industries such as healthcare, life sciences, clinical research, or similarly complex operational environments is strongly preferred. Compensation &
Benefits
Competitive base salary aligned to experience Annual incentive opportunity through the company’s bonus plan Comprehensive benefits package