- Location
- USA - NC - Durham - 10 Moore Drive, United States of America
- Type
- Full-time
- Department
- Legal
- Seniority
- Senior
- Source
- Workday
Description
Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data, technology and laboratory network, we advance diagnostics, accelerate innovation and help address some of the world’s most important health challenges. As we shape the future of healthcare, we are leveraging advanced technologies, intelligent digital solutions and data-driven innovation across our operations to enhance how work gets done and deliver greater value to customers and patients. With our global scale and deep expertise, you’ll have the opportunity to do meaningful work, grow your career and make a real impact on people’s health around the world. Together, we’re improving health and improving lives.
Labcorp is a global leader in diagnostic testing and drug development solutions, helping healthcare providers, researchers, and patients make informed decisions that advance care. Join us in our mission to improve health and improve lives.
Work Schedule
This is a full‑time, exempt (salaried) position assigned to a First Shift schedule, with standard business hours of Monday through Friday, 8:00 a.m. to 5:00 p.m. in EDT time zone. Business needs may occasionally require flexibility in work hours, including earlier, later, or additional hours, with reasonable notice provided when possible.
RESPONSIBILITIES
Framework Strategy & Rationalization
- Enable strategic alignment and rationalization across SOC2 Type 2, ISO 27001, NIST SP 800-53, PCI DSS, SOX ITGCs, FedRAMP, and CMMC (and related customer/regulatory requirements) to avoid duplicative effort and an unsustainable annual workload.
- Support transitions between assurance approaches where appropriate (e.g., simplifying overlapping requirements) to meet expectations such as state and sector requirements (including TX-RAMP where applicable).
- Perform control mapping activities; identifying overlaps, gaps, and efficiency opportunities across standards, internal policies, and contractual obligations.
Evidence Management, Customer Assurance, and Regulatory Support
- Preserve consistent, high-quality evidence production for assessments, customer RFIs, and regulatory requirements—reducing execution risk and downstream disruption.
- Build and maintain a well-governed evidence repository with clear traceability, version control, retention, and audit defensibility aligned to enterprise standards.
- Coordinate timely, accurate responses to customer security questionnaires and assurance requests in partnership with control owners.
Operational Risk Management & Issue Lifecycle
- Maintain effective operational risk management coverage, ensure monitoring, documentation, and issue lifecycle management continue without erosion as scope expands.
- Track findings, exceptions, risks, and remediation activities; coordinate validation and closure documentation aligned to governance expectations.
- Support risk reporting and governance cadence (e.g., risk forums, control owner check-ins) with clear status, trends, and escalation points.
Continuity, Capacity, and Compliance Operations Excellence
- Mitigate concentration and continuity risk within compliance/GRC by reducing reliance on a single overextended resource for critical audit and risk functions through documentation, process standardization, and repeatable operating routines.
- Develop scalable compliance artifacts (templates, checklists, playbooks) to improve consistency and reduce rework across cycles.
- Sustain audit readiness and customer confidence during increased compliance demands and post-acquisition integration complexity.
Stakeholder Partnership & Enterprise Governance
- Serve as a primary compliance partner to control owners across Security, Engineering, IT, Legal, and Operations to drive timely evidence production and remediation outcomes.
- Communicate status, risks, and blockers with precision; independently manage stakeholder follow-ups and escalate issues appropriately to protect timelines and quality.
- Promote a strong culture of compliance through clear guidance, practical enablement, and consistent expectations for evidence quality.
MINIMUM QUALIFICATIONS
- Bachelor’s Degree.
- 5 or more years of experience supporting cybersecurity compliance assessments and audits aligned to one or more of the following: SOC Type 2, ISO 27001, NIST SP 800-53, FedRAMP, PCI DSS, SOX ITGCs, and CMMC.
- 5 or more years of experience coordinating audit evidence and testing with multiple control-owner teams (e.g. security, Engineering, IT, Product, Finance).
PREFERRED QUALIFICATIONS
- 5 or more years with operating in post-acquisition or high-change environments with complex stakeholder landscapes.
- 5 or more years of experience supporting CMMC readiness and/or working with defense-sector security requirements (e.g. SSP/POA&M development, control implementation tracking).
ADDITIONAL JOB STANDARDS
- Independent execution and ownership mindset; proactive identification and removal of blockers.
- Compliance tooling (GRC platforms, ticketing systems, evidence repositories, workflow automation tools).
- Risk-based prioritization and sound judgment.
- Experience using AI-enabled tools to improve efficiency and quality in compliance workflows (e.g., drafting policies/procedures, summarizing evidence sets, accelerating RFI responses, mapping controls, identifying gaps).
- Ability to apply AI responsibly in accordance with confidentiality, data handling, and audit defensibility requirements.
- Process discipline and attention to detail; strong documentation rigor.
- Stakeholder management and clear, concise communication across multiple organizational levels.
- Should be open to travel up to 15% on occasion to assist with on-site audits if needed.
- Comfortable working within formal governance, change control, and fixed assessment/audit timelines.
This role is responsible for leading and coordinating cybersecurity compliance assessments and audit readiness activities across multiple regulatory and industry frameworks, including SOC 2 Type II, ISO 27001, NIST 800-53, PCI DSS, SOX ITGC, FedRAMP, and CMMC.
The position ensures the successful execution of external audits and assessments by managing workplans, milestones, dependencies, and stakeholder engagement while maintaining audit-ready documentation, and evidence repositories.
Working closely with control owners and business partners, the role validates control effectiveness, supports assessment preparedness, and drives timely remediation of identified gaps. As a highly independent contributor, this position plays a critical role in helping Labcorp meet compliance obligations, strengthen its security governance posture, and maintain confidence with customers, regulators, and external assessors.
Benefits: Employees regularly scheduled to work 20 or more hours per week are eligible for comprehensive benefits including: Medical, Dental, Vision, Life, STD/LTD, 401(k), Paid Time Off (PTO) or Flexible Time Off (FTO), Tuition Reimbursement and Employee Stock Purchase Plan. Employees regularly scheduled to work less than 20 hours, Casual, Intern, and Temporary employees are only eligible to participate in the 401(k) Plan. Employees who are regularly scheduled to work a 7 on 7 off schedule are eligible to receive all the foregoing benefits except PTO or FTO. For more detailed information, please click here.
Labcorp is proud to be an Equal Opportunity Employer:
Labcorp strives for inclusion and belonging in the workforce and does not tolerate harassment or discrimination of any kind. We make employment decisions based on the needs of our business and the qualifications and merit of the individual. Qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), family or parental status, marital, civil union or domestic partnership status, sexual orientation, gender identity, gender expression, personal appearance, age, veteran status, disability, genetic information, or any other legally protected characteristic. Additionally, all qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law.
We encourage all to apply
If you are an individual with a disability who needs assistance using our online tools to search and apply for jobs, or needs an accommodation, please visit our accessibility site or contact us at Labcorp Accessibility. For more information about how we collect and store your personal data, please see our Privacy Statement.