





Tier-1 employer, metro location, and mid-level 3–5 year role increase applicant competition.
Healthcare GxP, privacy, and pharma compliance context reduce cross-industry transferability of experience.
Explicit 3–5 years, mandatory IT risk/GRC experience, regulatory knowledge and GRC tool expectations make shortlisting stringent.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Review, interpret, and make final risk determinations based on automated IT risk assessment outputs, including Cyber Tier assignments and regulatory classifications.
Manage exception handling and escalate complex or ambiguous risk cases to relevant risk leads or subject matter experts.
Maintain auditor-ready risk documentation and collaborate with project teams and legal/privacy SMEs to ensure accurate risk communication and compliance.
3–5 years of experience in IT risk management, cybersecurity risk, IT audit, privacy compliance, or a directly related field.
Working knowledge of NIST Cyber Risk Management Framework and NIST 800-53 controls library.
Familiarity with major data privacy regulations such as GDPR, CCPA, EU AI Act, and GxP.
Experience with GRC platforms such as ServiceNow GRC or equivalent.
Strong analytical and independent risk judgment capabilities, comfortable forming defensible views from incomplete information.
Experience in automated or tool-assisted workflow environments with ability to challenge and override system-generated risk outputs.
Collaborative across IT, Legal, Privacy, and Business functions, comfortable translating technical risk assessments into clear guidance for varied stakeholders.