About this role
The team is seeking a Director of GRC Cybersecurity to lead their cybersecurity risk governance initiatives. This role is pivotal in managing third-party cybersecurity risks, with a strong emphasis on protecting PHI/PII, ensuring HIPAA compliance, and overseeing critical vendors.
Key responsibilities include:
- Leading the third-party cybersecurity risk management program.
- Driving assessments aligned with NIST CSF and ISO frameworks to evaluate and enhance the cybersecurity program.
- Establishing and maintaining exception management, approval management, and periodic monitoring processes.
- Collaborating with global cybersecurity and IT teams to implement automation through GRC tools.
- Overseeing the development and execution of risk mitigation strategies.
Required skills and qualifications:
- Extensive experience in cybersecurity risk management, particularly in healthcare or related fields.
- Strong knowledge of HIPAA regulations and compliance requirements.
- Familiarity with NIST CSF and ISO frameworks.
- Experience with GRC tools and automation processes.
- Excellent leadership and communication skills.
Experience required: 8-10 years in cybersecurity risk management or a related field, with a proven track record in governance, risk, and compliance.
What we offer: The team provides a dynamic work environment, opportunities for professional growth, and the chance to make a significant impact in the cybersecurity landscape.
Applications are read by our talent team, usually within two working days.
If you look like a fit we will call you, and you will hear from us either way.