Cybersecurity Governance, Risk, & Compliance Manager
Erlanger Health System Chattanooga, Tennessee, United States
Hospitals and Health Care · 5,001-10,000 employees
About the role
The GRC Manager designs, implements, and maintains the cybersecurity policy framework and compliance programs to ensure alignment with NIST CSF 2.0 and healthcare regulations. This role manages risks associated with evolving technologies such as AI, quantum computing, and cloud infrastructures while ensuring organizational resilience.
What they look for
Requirements
Candidates must possess a bachelor's degree in information security or a related field and at least 7 years of experience in cybersecurity governance and compliance. Expert knowledge of NIST frameworks, HIPAA, and HITRUST is required, along with the ability to communicate complex risk concepts to diverse audiences.
Full description
Job Summary: This individual will report to the Chief Information Security Officer. The Cybersecurity Governance, Risk, & Compliance (GRC) Manager designs, implements, and maintains Erlanger Health System's cybersecurity policy framework, compliance programs, and governance processes to ensure alignment with NIST CSF 2.0 Govern function and healthcare regulations including HIPAA Security Rule, as well as emerging standards for AI security (e.g., NIST AI RMF), post-quantum cryptography, and cloud security frameworks (e.g., CSA CCM). This role addresses risks from evolving technologies such as AI-integrated systems, quantum computing, and cloud-based infrastructures while prioritizing regulatory compliance and organizational resilience. Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, plus familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (e.g., NIST PQC), and cloud security frameworks (e.g., AWS Well-Architected Security, Azure Security Center, or CSA STAR). Demonstrated ability to communicate complex compliance and risk concepts, including those from AI, quantum, and cloud domains, to both technical and non-technical audiences. Ability to work in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.
Days and hours worked may be variable. (Hybrid/On-site as required)
Minimum Qualifications or Competencies: Basic competencies include, but are not limited to education, experience, or certification requirements.
Education: - Required: Bachelor's degree in information security, Compliance, or a related field (Master's preferred, with coursework or emphasis on AI, quantum computing, or cloud technologies).
Preferred:
Experience: Required: - 7+ years of experience in cybersecurity governance and compliance, preferably in a healthcare system, with exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.
Preferred:
Department Position Summary: This individual will report to the Chief Information Security Officer. The Cybersecurity Governance, Risk, & Compliance (GRC) Manager designs, implements, and maintains Erlanger Health System's cybersecurity policy framework, compliance programs, and governance processes to ensure alignment with NIST CSF 2.0 Govern function and healthcare regulations including HIPAA Security Rule, as well as emerging standards for AI security (e.g., NIST AI RMF), post-quantum cryptography, and cloud security frameworks (e.g., CSA CCM). This role addresses risks from evolving technologies such as AI-integrated systems, quantum computing, and cloud-based infrastructures while prioritizing regulatory compliance and organizational resilience. Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, plus familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (e.g., NIST PQC), and cloud security frameworks (e.g., AWS Well-Architected Security, Azure Security Center, or CSA STAR). Demonstrated ability to communicate complex compliance and risk concepts, including those from AI, quantum, and cloud domains, to both technical and non-technical audiences. Ability to work in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.
Days and hours worked may be variable. (Hybrid/On-site as required)
Similar roles
-
Staff Security Engineer, Abuse Control
Stripe London, England, United Kingdom
-
Senior Infrastructure and Cloud Security Engineer (m/f/d)
ICE Services London, England, United Kingdom
-
Lead - Product Security Engineer
Rocketlane Chennai, Tamil Nadu, India
-
Lead Manager, IT Security Engineer
Make-A-Wish America $70K–$84K/yr
-
Staff Cloud Security Engineer
Xometry Quinte West, Ontario, Canada · $205K–$233K/yr
-
Fire Security Engineer
Allsaved Ltd Glasgow, Scotland, United Kingdom · £38K–£45K/yr