Senior Lead Cyber Compliance

Labcorp Durham NC Updated 24 September 2026
PharmaMedTechRegulatory AffairsQuality Assuranceheoremacroraveinform

Job description

Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients. With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives. Labcorp is a global leader in diagnostic testing and drug development solutions, helping healthcare providers, researchers, and patients make informed decisions that advance care. Join us in our mission to improve health and improve lives. Work Schedule This is a full‑time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. in EDT time zone. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible. RESPONSIBILITIES Framework Strategy & Rationalization Enable strategic alignment and rationalization across SOC2 Type 2, ISO 27001, NIST SP 800-53, PCI DSS, SOX ITGCs, FedRAMP, and CMMC (and related customer/regulatory requirements) to avoid duplicative effort and an unsustainable annual workload. Support transitions between assurance approaches where appropriate (e.g., simplifying overlapping requirements) to meet expectations such as state and sector requirements (including TX-RAMP where applicable). Perform control mapping activities; identifying overlaps, gaps, and efficiency opportunities across standards, internal policies, and contractual obligations. Evidence Management, Customer Assurance, and Regulatory Support Preserve consistent, high-quality evidence production for assessments, customer RFIs, and regulatory requirements—reducing execution risk and downstream disruption. Build and maintain a well-governed evidence repository with clear traceability, version control, retention, and audit defensibility aligned to enterprise standards. Coordinate timely, accurate responses to customer security questionnaires and assurance requests in partnership with control owners. Operational Risk Management & Issue Lifecycle Maintain effective operational risk management coverage, ensure monitoring, documentation, and issue lifecycle management continue without erosion as scope expands. Track findings, exceptions, risks, and remediation activities; coordinate validation and closure documentation aligned to governance expectations. Support risk reporting and governance cadence (e.g., risk forums, control owner check-ins) with clear status, trends, and escalation points. Continuity, Capacity, and Compliance Operations Excellence Mitigate concentration and continuity risk within compliance/GRC by reducing reliance on a single overextended resource for critical audit and risk functions through documentation, process standardization, and repeatable operating routines. Develop scalable compliance artifacts (templates, checklists, playbooks) to improve consistency and reduce rework across cycles. Sustain audit readiness and customer confidence during increased compliance demands and post-acquisition integration complexity. Stakeholder Partnership & Enterprise Governance Serve as a primary compliance partner to control owners across Security, Engineering, IT, Legal, and Operations to drive timely evidence production and remediation outcomes. Communicate status, risks, and blockers with precision; independently manage stakeholder follow-ups and escalate issues appropriately to protect timelines and quality. Promote a strong culture of compliance through clear guidance, practical enablement, and consistent expectations for evidence quality. MINIMUM QUALIFICATIONS Bachelor’s Degree. 5 or more years of experience supporting cybersecurity compliance assessments and audits aligned to one or more of the following: SOC Type 2, ISO 27001, NIST SP 800-53, FedRAMP, PCI DSS, SOX ITGCs, and CMMC. 5 or more years of experience coordinating audit evidence and testing with multiple control-owner teams (e.g. security, Engineering, IT, Product, Finance). PREFERRED QUALIFICATIONS 5 or more years with operating in post-acquisition or high-change environments with complex stakeholder landscapes. 5 or more years of experience supporting CMMC readiness and/or working with defense-sector security requirements (e.g. SSP/POA&M development, control implementation tracking). ADDITIONAL JOB STANDARDS Independent execution and ownership mindset; proactive identification and removal of blockers. Compliance tooling (GRC platforms, ticketing systems, evidence repositories, workflow automation tools). Risk-based prioritization and sound judgment. Experience using AI-enabled tools to improve efficiency and quality in compliance workflows (e.g., drafting policies/procedures, summarizing evidence sets, accelerating RFI responses, mapping controls, identifying gaps). Ability to apply AI responsibly in accordance with confidentiality, data handling, and audit defensibility requirements. Process discipline and attention to detail; strong documentation rigor. Stakeholder management and clear, concise communication across multiple organizational levels. Should be open to travel up to 15% on occasion to assist with on-site audits if needed. Comfortable working within formal governance, change control, and fixed assessment/audit timelines. This role is responsible for leading and coordinating cybersecurity compliance assessments and audit readiness activities across multiple regulatory and industry frameworks, including SOC 2 Type II, ISO 27001, NIST 800-53, PCI DSS, SOX ITGC, FedRAMP, and CMMC. The position ensures the successful execution of external audits and assessments by managing workplans, milestones, dependencies, and stakeholder engagement while maintaining audit-ready documentation, and evidence repositories. Working closely with control owners and business partners, the role validates control effectiveness, supports assessment preparedness, and drives timely remediation of identified gaps. As a highly independent contributor, this position plays a critical role in helping Labcorp meet compliance obligations, strengthen its security governance posture, and maintain confidence with customers, regulators, and external assessors. Benefits: Employees regularly scheduled to work 20 or more hours per week are eligible for comprehensive benefits including: Medical, Dental, Vision, Life, STD/LTD, 401(k), Paid Time Off (PTO) or Flexible Time Off (FTO), Tuition Reimbursement and Employee Stock Purchase Plan. Employees regularly scheduled to work less than 20 hours, Casual, Intern, and Temporary employees are only eligible to participate in the 401(k) Plan. Employees who are regularly scheduled

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try