drjobs Cybersecurity Governance Manager

Cybersecurity Governance Manager

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Knoxville, TN - USA

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

Job Functions Duties Responsibilities and Position Qualifications:

Were not just a workplace were a Great Place to Work certified employer!

Proudly certified as a Great Place to Work we are dedicated to creating a supportive and inclusive environment. At Sonic Healthcare USA we emphasize teamwork and innovation. Check out our job openings and advance your career with a company that values its team members!

JOB SUMMARY

TheCyber Governance & Risk Manager (GRC Manager)is a key member of the Cyber Security Team responsible for establishing and managing a robust governance framework overseeing risk management processes conducting internal audits and ensuring compliance with industry and healthcarespecific regulatory standards. This role also chairs theInformation Security Management Committeeand collaborates crossfunctionally to implement ethical and secure practices throughout the organization.

The role includes:

  • Providing advice and interpretation on the companys code of conduct security compliance policies relevant health industry regulations and industry codes
  • Recommending changes to corporate security compliance policies and practices to ensure consistency with laws regulations and industry standards
  • Maintaining uptodate knowledge of relevant healthcare and other related compliance rules regulations enforcement trends and industry standards
  • Providing strategic and tactical advice to stakeholders to ensure compliance and security.
  • Proactively identifying mitigating and managing incidents and vulnerabilities.
  • Ensuring ethical business conduct through the effective implementation of industry and company standards.

DUTIES AND RESPONSIBILITIES

  • Lead the development and implementation of a GRC program aligned withISO 27001SOC 2 andNISTcybersecurity frameworks.
  • Conduct internal audits and risk assessments across IT systems clinical operations and thirdparty vendors; maintain audit schedules and reports.
  • Implement and maintain anInformation Security Management System (ISMS)in accordance with ISO 27001 standards.
  • Evaluate and strengthen internal controls protecting PHI PII and financial data in alignment with HIPAA PCI DSS and CLIA/CAP requirements.
  • Maintain a risk register and document risk treatment plans audit results findings and remediation actions.
  • Provide strategic advice to stakeholders on compliance governance and information security best practices.
  • Align policies and procedures with global standards recommending updates in response to new laws technologies and risks.
  • Act as a liaison with regulatory bodies and certification auditors; prepare audit documentation and coordinate responses.
  • Develop training and awareness programs across the organization on security compliance and ethical conduct.
  • Ensure effective incident detection investigation response and prevention strategies.

WORK ENVIRONMENT AND PHYSICAL REQUIREMENTS

  • Office and clinical laboratory environments; occasional weekend or offhours work may be required.
  • May require lifting equipment 3050 pounds) standing or walking for extended periods and travel between sites.
  • Use of standard and specialized cybersecurity tools and IT systems.

MINIMUM QUALIFICATIONS

  • Minimum5 yearsof applied experience in cybersecurity governance audits risk remediation or compliance.
  • Minimum of 2 years managing a GRC ProgramTeam
  • Experience conducting and leadinginternal audits.
  • Indepth knowledge ofISO 27001SOC 2 andNIST frameworks.
  • Familiarity with HIPAA CLIA CAP and healthcare industry regulations.
  • Strong understanding of GRC tools and methodologies.
  • Ability to travel occasionally and work flexible hours during highimpact events or audits.

KNOWLEDGE SKILLS AND ABILITIES

  • Strong analytical and problemsolving skills.
  • Exceptional written and verbal communication skills with the ability to explain technical topics to nontechnical audiences.
  • Proficiency with risk management GRC platforms security control frameworks and incident response.
  • Ability to develop security strategy manage audits and report on compliance to executives and committees.
  • High ethical standards and a proactive serviceoriented approach to stakeholder engagement.
  • Ability to work independently handle sensitive information and maintain confidentiality under pressure.

Scheduled Weekly Hours:

40

Work Shift:

Job Category:

Information Technology

Company:

Sonic Healthcare USA Inc

Sonic Healthcare USA is an equal opportunity employer that celebrates diversity and is committed to an inclusive workplace for all employees. We prohibit discrimination and harassment of any kind based on race color sex religion age national origin disability genetics veteran status sexual orientation gender identity or expression or any other characteristic protected by federal state or local laws.


Required Experience:

Manager

Employment Type

Full-Time

Company Industry

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.