LivaNova

Cyber Risk and Compliance Specialist

LivaNova • $100K — $120K *
US-AnywhereRemote in United States
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in IT Audit, IT Compliance, or Cyber Risk.
  • Expert-level understanding of SOX 404 (ITGCs) and strong knowledge of HIPAA Security Rule and NIS2.
  • Proficient in frameworks like NIST 800-53, ISO 27001, NIST CSF, or COBIT.
  • CISA certification preferred; CISSP or CRISC is a significant advantage.
  • Strong communication skills to convey technical controls to non-technical stakeholders.
  • Experience with ERP systems (e.g., SAP), cloud environments (e.g., Microsoft Azure, AWS), and GRC systems (e.g., Auditboard, Workiva).

Responsibilities

  • Lead the IT SOX program, designing and implementing IT General Controls (ITGCs) and IT Application controls (ITACs).
  • Serve as the primary liaison between technical teams and external auditors, ensuring timely and accurate evidence.
  • Conduct root-cause analysis for control failures and collaborate on long-term remediation plans.
  • Act as the technical subject matter expert for HIPAA Security Rule, ensuring protection of PHI.
  • Align security posture with the NIS2 Directive for European operations.
  • Conduct risk assessments for new technologies and vendors, integrating compliance from the start.
  • Manage a comprehensive security awareness program, creating engaging content for all staff levels.

Benefits

  • Comprehensive health and wellness programs.
  • Opportunities for professional development and certifications.
  • Flexible work arrangements to support work-life balance.
  • Engaging company culture focused on security and compliance.
  • Access to cutting-edge technology and tools.
Full Job Description
The Role

As our Cyber Risk and Compliance Specialist, you will occupy a critical role that is 50% technical auditor and 50% security advocate. You will ensure the integrity of our financial systems through IT SOX compliance while simultaneously maturing our global compliance posture (HIPAA/NIS2) and building a high-integrity security culture through a comprehensive Security Awareness program.

Focus A: IT SOX & Financial Integrity (60%)
• Program Ownership: Lead the IT SOX program and design, implement, and test IT General Controls (ITGCs), IT Application controls (ITACs) and Key Reports (IPE) across our enterprise applications, databases, and infrastructure.
• Audit Management: Serve as the primary "translator" between technical teams and external auditors, ensuring evidence is accurate, timely, and defensible.
• Deficiency Management: Lead the root-cause analysis for any control failures and partner with stakeholders to build long-term, remediation plans.

Focus B: HIPAA, NIS2 & Risk Advisory (30%)
• Healthcare Compliance (HIPAA): Act as the technical SME for the HIPAA Security Rule, ensuring controls protect PHI, including controls monitoring and providing guidance to management for new systems.
• International Resilience (NIS2): Lead the alignment of our security posture with the NIS2 Directive, focusing on key areas in the directive for our European operations.
• Strategic Risk Assessments: Conduct deep-dive risk assessments for new technologies and vendors, ensuring compliance is baked in from the procurement stage.

Focus C: Security Awareness & Training (10%)
• Program Development: Manage the security awareness program that goes beyond "check-the-box" training. You will create engaging content for diverse audiences, from senior leadership to staff.
• Policy Promotion: Translate dense Information Security Policies into digestible, actionable "good practices" for IT administrators and data owners.
• Culture Building: Design targeted communication campaigns to increase internal reporting of security incidents and reinforce the importance of compliance.

Qualifications
• Experience: 5-7 years in IT Audit, IT Compliance, or Cyber Risk.
• Regulatory Knowledge: Expert-level understanding of SOX 404 (ITGCs) and a strong working knowledge of the HIPAA Security Rule and NIS2.
• Frameworks: Proficiency in applying NIST 800-53, ISO 27001, NIST CSF, or COBIT.
• Certifications: CISA is highly preferred; CISSP or CRISC is a major plus.
• Skills: The ability to explain to key stakeholders why a certain control is necessary without sounding like an auditor.
• Technology: Experience with ERP systems, such as SAP (ECC/S4 HANA) etc., cloud environments like Microsoft Azure, AWS etc., GRC systems such as Auditboard, Workiva or other.

Valuing different backgrounds:

About LivaNova

LivaNova is a global medical technology company that develops and manufactures innovative therapeutic solutions for patients with chronic and acute conditions. The company operates in two business units: Cardiac Surgery and Neuromodulation. LivaNova's products include heart-lung machines, oxygenators, autotransfusion systems, and neuromodulation devices. The company was formed in 2015 through the merger of Sorin Group and Cyberonics. LivaNova is headquartered in London, UK, and has operations in more than 100 countries.
Learn more about LivaNova
Size
3,000 employees
Market Cap
$2.9 billion
Industry
Net Income
-$345 million
5 Year Trend
+1.4%
Revenue
$934.2 million
NASDAQ

Similar Jobs

More Jobs at LivaNova

More Finance & Insurance Jobs

Find similar Cyber Risk and Compliance Specialist jobs: