





Niche senior GRC role in medical devices reduces applicant density despite strong employer brand.
Requires medical-device regulatory and GRC expertise, making background fit industry-specific and less transferable.
Explicit 8+ years, required certifications, and regulated medical-device GRC increase shortlisting strictness.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead identification, assessment, and mitigation of cybersecurity risks across the organization, emphasizing healthcare regulatory compliance (e.g., HIPAA, GDPR).
Drive the design, implementation, and enhancement of Governance, Risk & Compliance (GRC) processes and platforms to improve operational efficiency and risk management.
Collaborate cross-functionally with IT, legal, compliance, and product security teams to integrate security throughout product lifecycles and operations.
Minimum 8+ years relevant work experience in cybersecurity, with at least 7+ years in cybersecurity GRC or audit preferred.
Detailed knowledge of cybersecurity frameworks and regulatory standards relevant to healthcare/medical device industry (e.g., HIPAA, FDA, NIST, GDPR).
At least 5 years of risk management experience including risk assessments using methodologies like FAIR; 3 years in designing and implementing risk management programs within complex organizations.
Certifications such as CISSP, CRISC, or CISA are required or highly preferred.
Experienced in managing cybersecurity GRC within healthcare or medical device sectors, familiar with regulatory compliance and risk frameworks.
Proven ability to lead risk assessments, process design, and continuous improvement of risk and compliance programs at scale.
Technical savvy with GRC tools (e.g., ServiceNow, LogicGate), integration via automation/APIs, and strong communication skills for translating risks to senior leadership.