





Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Tier-1 brand plus metro location but specialized GRC focus limits applicant pool.
Healthcare and medical-device regulatory and GRC expertise make cross-industry transferability limited.
Explicit 7+ years requirement plus mandatory certifications (CISSP/CRISC/CISA) and domain-specific GRC experience.
Lead and manage end-to-end internal cybersecurity risk assessments including intake, analysis, treatment, escalation, and closure.
Develop and maintain audit-ready risk documentation, reports and metrics ensuring compliance with healthcare regulations like HIPAA and GDPR.
Collaborate cross-functionally to evaluate and improve cybersecurity posture across products and operational processes using frameworks like NIST CSF and FAIR.
7+ years of IT experience with a Bachelor's Degree in Engineering, MCA, or MSc.
7+ years of cybersecurity GRC or audit experience, preferably in healthcare or medical device industry.
Minimum 5 years of hands-on risk management experience including conducting risk assessments using quantitative and qualitative methods such as FAIR.
Experience evaluating technical design documents and maintaining risk registers with remediation and treatment plans.
Experienced in designing and executing comprehensive risk management programs within large, complex organizations.
Strong technical understanding of cybersecurity frameworks, regulatory standards, and risk quantification models (e.g., NIST CSF, ISO 27001, FAIR).
Comfortable working with GRC tools (ServiceNow, Archer, etc.) and capable of integrating risk management into operational workflows across cross-functional teams.