Gathering your results ...
3 days
Not Specified
Not Specified
Not Specified
<p>Posting Date</p> <p>04/03/2026</p> <p>2000 16th Street, Denver, Colorado, 80202, United States of America</p> <p>Overview</p> <p>The Program Manager, IT Risk & Audit, is an individual contributor responsible for driving enterprise-level governance, regulatory compliance, and risk management programs across DaVita's IT and Security landscape. This role ensures consistent execution of IT risk processes, supports internal and external audits, leads partner-facing due diligence activities, advances governance programs, and manages the operational cadence of key security initiatives.</p> <p>This role is program-oriented - focused on the lifecycle of risk, from contracting to decommissioning, ensuring governance, compliance, and risk processes flow predictably across the enterprise.</p> <p>Key Responsibilities</p> <p>Governance & Program Management</p> <ul> <li> <p>Own and manage core governance programs including policy lifecycle management, standards updates, cross-functional alignment, and coordination with Security, Privacy, Compliance, Legal, and IT.</p> </li><li> <p>Facilitate governance working groups and steering committees, ensuring agendas, documentation, decisions, and follow-up actions are executed consistently.</p> </li><li> <p>Track and report on program-level OKRs, compliance posture, and audit activity for leadership and committee reporting cycles.</p> </li></ul> <p>Lifecycle Risk Management</p> <ul> <li> <p>Oversee end-to-end IT risk lifecycle management, ensuring risks are appropriately evaluated and managed from:</p> </li><li> <p>Contracting and procurement (BAA reviews, contract language alignment, partner due diligence)</p> </li><li> <p>Solution onboarding and implementation</p> </li><li> <p>Operational monitoring and oversight</p> </li><li> <p>System changes, exceptions, and remediation activities</p> </li><li> <p>System retirement/decommissioning</p> </li><li> <p>Maintain governance controls across each lifecycle stage to ensure consistency, documentation quality, and regulatory alignment.</p> </li></ul> <p>Exception Management</p> <ul> <li> <p>Coordinate the intake, evaluation, documentation, approval routing, and tracking of security and compliance exceptions.</p> </li><li> <p>Maintain an enterprise-wide exception repository, ensuring exceptions have defined compensating controls, expiration dates, and remediation plans.</p> </li><li> <p>Partner with control owners, IT teams, and leadership to ensure exception backlogs are prioritized and resolved within expected timelines.</p> </li></ul> <p>Regulatory, Audit & Compliance Support</p> <ul> <li> <p>Coordinate SOX, HIPAA, internal audit, external audit, and regulatory assessment activities across Security, IT Overwatch, ERS, Privacy, Legal, and Finance.</p> </li><li> <p>Manage audit readiness activities, evidence collection, documentation updates, and remediation follow-through (MAPs/CAPs).</p> </li><li> <p>Track audit findings, ensuring gaps are formally logged, assigned, monitored, and closed according to internal SLAs and regulatory expectations.</p> </li></ul> <p>Enterprise Risk Assessment Support</p> <ul> <li> <p>Support the enterprise risk assessment process, including review of IT and cybersecurity risk assessments, validation of risk scoring, and confirmation of mitigation strategies.</p> </li><li> <p>Track risk-based findings and gaps across the enterprise, ensuring they remain visible, actionable, and progress toward closure is monitored.</p> </li><li> <p>Provide program-level reporting on enterprise risk themes, recurring control gaps, and opportunities for systemic improvements.</p> </li></ul> <p>Third-Party & Partner Assessments</p> <ul> <li> <p>Lead completion of partner questionnaires, payor and regulatory due diligence forms, RFP/RFI security sections, and vendor assessments.</p> </li><li> <p>Review BAAs and data-flow related documentation to ensure alignment with DaVita's privacy and security requirements.</p> </li><li> <p>Maintain reusable artifacts (response libraries, program overviews, diagrams, certifications) to streamline intake and partner interactions.</p> </li></ul> <p>Training, Awareness & Communications</p> <ul> <li> <p>Partner with Training & Awareness to design, deliver, and update annual and targeted security/compliance training modules.</p> </li><li> <p>Develop internal communications for governance updates, policy changes, audit cycles, and enterprise compliance initiatives.</p> </li><li> <p>Contribute to phishing simulations, education campaigns, and security culture efforts across the Village.</p> </li></ul> <p>Cross-Functional Program Execution</p> <ul> <li> <p>Support enterprise initiatives such as:</p> </li><li> <p>AI governance and intake workflows</p> </li><li> <p>Security maturity assessments and roadmap development</p> </li><li> <p>Risk register program operations</p> </li><li> <p>Metrics dashboards and executive-ready reporting</p> </li><li> <p>Help operationalize repeatable workflows, templates, intake processes, documentation standards, and program controls.</p> </li></ul> <p>Stakeholder Engagement & Communication</p> <ul> <li> <p>Act as a primary liaison among IT, Security, Privacy, Internal Audit, Legal, Compliance, Procurement, and business partners.</p> </li><li> <p>Translate complex regulatory, security, and risk concepts into clear, actionable guidance for diverse audiences.</p> </li><li> <p>Prepare concise, executive-ready materials that support leadership decision-making.</p> </li></ul> <p>Qualifications</p> <p>Required</p> <ul> <li> <p>5+ years of IT risk, audit, compliance, or security governance experience.</p> </li><li> <p>Strong knowledge of SOX, HIPAA, NIST, ISO, and typical IT control frameworks.</p> </li><li> <p>Excellent writing skills for audit responses, security questionnaires, governance documentation, and leadership reporting.</p> </li><li> <p>Proven program management, cross-functional coordination, and organizational skills.</p> </li><li> <p>Ability to manage multiple complex workstreams with high accountability.</p> </li></ul> <p>Preferred</p> <ul> <li> <p>Healthcare, regulated-industry, or enterprise-scale experience.</p> </li><li> <p>BAAs, RFP/RFI processes, partner assessments, or vendor governance experience.</p> </li><li> <p>Certifications (CISA, CRISC, CISM, CISSP, PMP).</p> </li></ul> <p>Success Factors</p> <ul> <li> <p>Highly dependable operator with strong ownership.</p> </li><li> <p>Builds trust and rapport across IT, Security, Audit, Legal, and business stakeholders.</p> </li><li> <p>Communicates directly, clearly, and professionally - especially with senior leaders.</p> </li><li> <p>Embodies DaVita's values and Leading the DaVita Way behaviors.</p> </li></ul> <p>What We'll Provide:</p> <p>More than just pay, our DaVita Rewards package connects teammates to what matters most. Teammates are eligible to begin receiving benefits on the first day of the month following or coinciding with one month of continuous employment. Below are some of our benefit offerings.</p> <ul> <li> <p>Comprehensive benefits: Medical, dental, vision, 401(k) match, paid time off, PTO cash out</p> </li><li> <p>Support for you and your family: Family resources, EAP counseling sessions, access Headspace, backup child and elder care, maternity/paternity leave and more</p> </li><li> <p>Professional development programs: DaVita offers a variety of programs to help strong performers grow within their career and also offers on-demand virtual leadership and development courses through DaVita's online training platform StarLearning.</p> </li></ul> <p>#LI-SM5</p> <p>At DaVita, we strive to be a community first and a company second. We want all teammates to experience DaVita as "a place where I belong." Our goal is to embed belonging into everything we do in our Village, so that it becomes part of who we are. We are proud to be an equal opportunity workplace and comply with state and federal affirmative action requirements. Individuals are recruited, hired, assigned and promoted without regard to race, national origin, religion, age, color, sex, sexual orientation, gender identity, disability, protected veteran status, or any other protected characteristic.</p> <p>This position will be open for a minimum of three days.</p> <p>The Salary Range for the role is $91,000.00 - $133,700.00 per year.</p> <p>For location-specific minimum wage details, see the following link: DaVita.jobs/WageRates</p> <p>Compensation for the role will depend on a number of factors, including a candidate's qualifications, skills, competencies and experience. DaVita offers a competitive total rewards package, which includes a 401k match, healthcare coverage and a broad range of other benefits. Learn more at https://careers.davita.com/benefits</p> <p>Colorado Residents: Please do not respond to any questions in this initial application that may seek age-identifying information such as age, date of birth, or dates of school attendance or graduation. You may also redact this information from any materials you submit during the application process. You will not be penalized for redacting or removing this information.</p>
POST A JOB
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!
It's completely FREE to post your jobs on ZiNG! There's no catch, no credit card needed, and no limits to number of job posts.
The first step is to SIGN UP so that you can manage all your job postings under your profile.
If you already have an account, you can LOGIN to post a job or manage your other postings.
Thank you for helping us get Americans back to work!