





Strong employer brand and metro location increase applicant density but role is specialized, so medium competition.
Requires medical-device and regulatory GRC expertise, making cross-industry transfers difficult and background-sensitive.
Explicit 7+ years requirement plus mandatory CISSP/CRISC/CISA and regulatory experience makes shortlisting highly strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead identification, assessment, and mitigation of cybersecurity risks across the organization, focusing on healthcare and medical device regulatory environments.
Drive design and implementation of risk management programs and governance, risk, and compliance (GRC) initiatives, ensuring security integration throughout product lifecycle and operations.
Collaborate cross-functionally to enhance cybersecurity posture, maintain compliance with HIPAA, GDPR, FDA, NIST, and automate risk management processes.
Minimum 7 years of IT experience with at least 7 years in cybersecurity GRC or internal/external audit, preferably in healthcare or medical devices.
Bachelor's Degree in Engineering, MCA, or MSc required.
Minimum 5 years in risk management activities with experience in quantitative and qualitative risk assessments, including FAIR model.
Certifications required: CISSP, CRISC, or CISA.
Experienced in designing and implementing comprehensive risk management programs within large, complex organizations.
Proficient with leading GRC tools (e.g., ServiceNow, LogicGate, OneTrust) and able to leverage automation for process improvement.
Strong knowledge of healthcare cybersecurity regulatory landscape and risk assessment frameworks (NIST, HIPAA, GDPR) with demonstrated ability to communicate complex risk concepts to leadership.