





Strong employer brand but niche healthcare cybersecurity GRC reduces broad applicant pool.
Healthcare and medical-device regulatory GRC expertise makes cross-industry transfers difficult.
Explicit 7+ years, mandatory GRC experience, and certifications create strict screening filters.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Lead internal cybersecurity risk assessments end-to-end including risk identification, analysis, treatment, monitoring, and closure.
Evaluate security controls across various domains (IAM, vulnerability management, encryption, cloud security, etc.) and maintain audit-ready risk records.
Develop risk metrics, reporting, and improve GRC processes ensuring compliance with regulations like HIPAA, GDPR, and cybersecurity frameworks (NIST, ISO).
7+ years of IT experience with Bachelor's in Engineering, MCA, or MSc.
7+ years in cybersecurity GRC or audit, preferably healthcare or medical device industry.
At least 5 years executing risk management activities including FAIR risk assessments.
Experience conducting NIST risk assessments and knowledge of HIPAA, GDPR, ISO 27001, and other regulatory frameworks.
Experienced in large, complex organizations with hands-on design and implementation of risk management programs.
Strong expertise in technical risk evaluation including architecture and system design review.
Skilled in using GRC tools (e.g., ServiceNow, Archer) and translating complex cyber risks into business language for executive audiences.