Back to jobs

IT Risk Manager

Dublin, Ireland

LetsGetChecked is a global healthcare solutions company that provides the tools to manage health from home through health testing, virtual care, genetic sequencing, and medication delivery for a wide range of health and wellness conditions. LetsGetChecked's end-to-end model includes manufacturing, logistics, lab analysis, physician support, and prescription fulfillment. Founded in 2015 and co-headquartered in Dublin and Atlanta, LetsGetChecked empowers people to take control of their health and live longer, happier lives.

 

This is an excellent opportunity for an IT Risk Manager to join our rapidly growing team, and to support our company in driving the continuous improvement of its privacy, security, engineering and AI programs and related control frameworks. The IT Risk Manager reports to the SVP of Data Compliance and Privacy , and is expected to work across multiple business functional teams such as Information Security, Data Privacy, Software Engineering, Legal, Compliance and HR to ensure our company is effectively adhering to industry standard frameworks and best practices, legal and contractual requirements, and in-house policies.

Job Summary:

The role ensures successful and consistent assessment and delivery of security, privacy and IT risk-related compliance program activities, policies, and procedures, and serves to advise and give guidance to the business on how to align with the compliance requirements we are subject to. Particular focus areas will include developing policies and procedures to reflect evolving industry standards, and being involved in day-to-day management and maintenance of privacy and security certifications (HITRUST, NIST, ISO27001, etc.) while ensuring related processes are as lightweight and streamlined as possible, minimizing red tape and simplifying where possible. The role will also have responsibility for performing third party risk management (due diligence of prospective service providers), responding to client requests for information (RFIs) regarding our own privacy and security posture, and supporting the SVP of Information Security and the SVP of Data Compliance and Privacy in the performance of audits to identify and mitigate privacy and security risks as they emerge.

In addition to this, the role may be expected to perform ad-hoc audits or reviews of business processes as requested by senior leadership, and help set the direction across a broad spectrum of emerging technology risks (e.g. AI governance, open source software licensing, deployment of Governance, Risk and Compliance tools, etc.).

To be successful in this role, you will have proven ability in internal and/or external IT risk or audit functions related to information security and privacy, as well as a track record of promoting awareness, understanding, and practical application of privacy and security policies and principles across organizational boundaries, performing audits and assessments, and providing guidance to enable operational alignment with the requirements of security and privacy frameworks and regulations. Any prior knowledge or experience in performing AI governance audits or risk assessments, software development lifecycle audits, or experience performing contract reviews for vendors, clients or open source software licenses would also be a plus.

You will have an in-depth knowledge of one or more security and privacy industry standards and compliance-related frameworks (for example HITRUST, ISO27001, NIST, SOX, GDPR, HIPAA, FedRamp, etc.). Familiarity with the healthcare or medical device industries and the nature of their data processing activities would be a significant plus, as would experience with implementing or managing audit programs or key domains within them. Proven experience in third party risk management or client-facing roles supporting client due diligence efforts would also be advantageous.

This is a hybrid working role.

 Duties and Responsibilities

  • Support the SVP Data Compliance and Privacy and SVP of Information Security in continual assessment and enhancement of the company's security and privacy control framework and policies, identifying areas of risk or non-compliance and supporting in mitigation and/or remediation.
  • Conduct formally documented audits of Information Security and Data Protection related domains, summarizing findings and risks, and working with leadership to communicate and implement remediation plans in areas such as Access Control, Change Management, Incident Response, Software Development, Third Party Risk Management, Business Continuity, AI Governance, etc.
  • Support Legal, Compliance, Information Security, and the wider business in performing due diligence and contracting with new third parties. This will involve assessing third party vendors’ privacy and security controls and standards, and coordinating across the business to communicate and remediate risks associated with new third party relationships.
  • Support in other compliance audit activities, for example responding to customer requests regarding our security program, or working closely with the DPO to document personal data processing activities as part of our GDPR and HIPAA compliance programs, or our AI governance program.
  • Act as a point of contact with internal teams to promote awareness and understanding of privacy and security regulatory and control requirements, as well as related company policies and procedures.
  • Other duties as assigned by Legal, Privacy, Compliance, Information Security or related leadership.

 Requirements

  • Minimum 3 years of experience in performing privacy and security audits against established control frameworks.
  • Minimum 3 years of experience in creating or enhancing privacy and security control frameworks, policies, and procedures.
  • Strong familiarity with computer security systems/critical security controls and related industry standards for privacy and security, such as HITRUST, ISO27 series, NIST, SOX or SOC2 requirements and their implementation.
  • Some familiarity with data privacy and AI laws such as GDPR, HIPAA, US state privacy laws, or the EU AI Act would be a plus.
  • Experience in third party risk management or client-facing security, privacy, or audit advisory roles.
  • Ability to handle confidential information.
  • Ethical, with the ability to remain tactful, impartial and escalate all instances of noncompliance through established reporting channels.
  • Organizational skills with attention to detail.

 Additional Skills/Certifications (preferred)

  • Security or IT Audit certifications such as CISSP, CIPM, CISA, or CRISC.
  • Privacy certifications such as CIPP/US, CIPP/E, CIPM, CIPT, or AIGP.
  • Educational or professional background in Information Management, Security, Computer Science, IT Audit, or similar.

 The base salary range for this role is €70.000 - €85.000.

Benefits: 

Alongside base salary we offer a range of benefits including: 

  • Health insurance and an Employee Assistance Programme 
  • Pension
  • LetsGetChecked has a flexible annual leave policy
  • Annual Compensation Reviews
  • 3 paid volunteer days per year
  • Free monthly LetsGetChecked tests as we are not only focused on the well being of our patients but also the well being of our teams
  • A referral bonus programme to reward you for helping us hire the best talent
  • Internal Opportunities and Careers Clinics to help you progress your career within the company
  • Maternity, Paternity, Parental and Wedding leave

Why LetsGetChecked

At LetsGetChecked, we are revolutionizing healthcare by making it more accessible, convenient, and personalized. Our mission is to empower individuals with the knowledge and tools they need to manage their health proactively, so they can live longer, happier lives.

By joining our team, you will be part of a dynamic and innovative company that is dedicated to improving lives through cutting-edge technology and compassionate care. We value our employees and invest in their growth, offering opportunities for professional development and career advancement. Together, we can make a meaningful impact on the future of healthcare and help people take control of their health journey. Join us in our commitment to transforming healthcare for the better.

Our Commitment to Diversity, Equity, and Inclusion

At LetsGetChecked, we are committed to fostering an inclusive environment that celebrates diversity in all its forms. We believe that the diversity of thought, background, and experience strengthens our teams and drives innovation. We are an equal-opportunity employer and do not discriminate on the basis of race, ethnicity, religion, color, place of birth, sex, gender identity or expression, sexual orientation, age, marital status, military service status, or disability status. Our goal is to ensure that everyone feels valued and empowered to thrive.

To learn more about LetsGetChecked and our mission to help people live longer, healthier lives please visit https://www.letsgetchecked.com/careers/

Create a Job Alert

Interested in building your career at LetsGetChecked? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

By submitting your application, you agree that LetsGetChecked may collect your personal data for recruiting, and related purposes. LetsGetChecked's Privacy Notice explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over LetsGetChecked's use of your personal information.

You can view the appropriate privacy policy below:

United States

Europe 

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in LetsGetChecked’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.