Cybersecurity Governance, Risk, & Compliance Manager

Medicine Journal$110K — $130K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, compliance, or related field (Master's preferred)
  • 7+ years of cybersecurity governance and compliance experience, preferably in healthcare
  • Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF
  • Familiarity with NIST AI RMF, post-quantum cryptography, and cloud security frameworks
  • Strong communication skills for conveying complex concepts to diverse audiences

Responsibilities

  • Design and implement cybersecurity policy frameworks and compliance programs
  • Maintain governance processes to align with NIST CSF 2.0 and healthcare regulations
  • Address risks associated with AI-integrated systems and cloud infrastructures
  • Ensure organizational resilience through effective compliance strategies
  • Support compliance-related incidents or audits during after-hours as needed

Benefits

  • Hybrid/On-site working arrangement as required
  • Opportunity to work in a dynamic and evolving technology landscape
  • Collaboration with senior leadership including the Chief Information Security Officer
  • Engagement with cutting-edge cybersecurity initiatives and emerging standards
Full Job Description
Job Summary:
This individual will report to the Chief Information Security Officer. The Cybersecurity Governance, Risk, & Compliance (GRC) Manager designs, implements, and maintains Erlanger Health System's cybersecurity policy framework, compliance programs, and governance processes to ensure alignment with NIST CSF 2.0 Govern function and healthcare regulations including HIPAA Security Rule, as well as emerging standards for AI security (e.g., NIST AI RMF), post-quantum cryptography, and cloud security frameworks (e.g., CSA CCM).
This role addresses risks from evolving technologies such as AI-integrated systems, quantum computing, and cloud-based infrastructures while prioritizing regulatory compliance and organizational resilience.
Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, plus familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (e.g., NIST PQC), and cloud security frameworks (e.g., AWS Well-Architected Security, Azure Security Center, or CSA STAR). Demonstrated ability to communicate complex compliance and risk concepts, including those from AI, quantum, and cloud domains, to both technical and non-technical audiences. Ability to work in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.

Days and hours worked may be variable. (Hybrid/On-site as required)

Minimum Qualifications or Competencies: Basic competencies include, but are not limited to education, experience, or certification requirements.

Education:
- Required: Bachelor's degree in information security, Compliance, or a related field (Master's preferred, with coursework or emphasis on AI, quantum computing, or cloud technologies).

Preferred:

Experience:
Required:
- 7+ years of experience in cybersecurity governance and compliance, preferably in a healthcare system, with exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.

Preferred:

Department Position Summary:
This individual will report to the Chief Information Security Officer. The Cybersecurity Governance, Risk, & Compliance (GRC) Manager designs, implements, and maintains Erlanger Health System's cybersecurity policy framework, compliance programs, and governance processes to ensure alignment with NIST CSF 2.0 Govern function and healthcare regulations including HIPAA Security Rule, as well as emerging standards for AI security (e.g., NIST AI RMF), post-quantum cryptography, and cloud security frameworks (e.g., CSA CCM).
This role addresses risks from evolving technologies such as AI-integrated systems, quantum computing, and cloud-based infrastructures while prioritizing regulatory compliance and organizational resilience.
Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, plus familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (e.g., NIST PQC), and cloud security frameworks (e.g., AWS Well-Architected Security, Azure Security Center, or CSA STAR). Demonstrated ability to communicate complex compliance and risk concepts, including those from AI, quantum, and cloud domains, to both technical and non-technical audiences. Ability to work in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.

Days and hours worked may be variable. (Hybrid/On-site as required)

About Medicine Journal

Medicine Journal Careers

There has never been a more opportune time to join the dedicated team at Medicine Journal—the leading platform for medical professionals and researchers worldwide.

Opportunities Await

Medicine Journal invites professionals to be part of a pioneering team dedicated to innovation in healthcare publishing. Joining Medicine Journal allows individuals to engage with some of the most significant advancements in medical science and healthcare solutions. Transform the landscape of medical literature with Medicine Journal, a beacon of knowledge and progress in the medical community. Medicine Journal stands at the nexus of healthcare, research, and digital innovation. Collaborate with a global team of professionals who are committed to reshaping the future of medical publishing.

Medicine Journal Employment Insights

The team is constructing a market-leading network of experts to guide and influence the future of medical literature and professional healthcare publications.

Innovate and Lead

Join the largest cadre of healthcare publication experts—dedicated professionals at the forefront of medical science, industry expertise, and digital transformation.

Engage in Meaningful Work

Deliver targeted solutions and insightful research publications that serve the medical community and contribute to global health advancements.

Be Part of a Dynamic Team

Engage in a wide range of projects involving the latest in medical technology and utilize the combined capabilities, global scale, and collaborative environment that Medicine Journal offers.

Future-Proof Your Career

Advance your career with limitless opportunities supported by unmatched training, development, and certification programs.

Explore Medicine Journal

From groundbreaking research papers to comprehensive medical reviews, Medicine Journal provides the tools and platform for predictive advancements in healthcare.

The Medicine Journal Employment Experience

The combined service capabilities, global reach, and collaborative projects help professionals overcome challenges and lead transformation in the medical publishing industry. Clients and contributors worldwide look to Medicine Journal for innovative strategies and solutions that drive growth and excellence in healthcare.

Stay Connected

Join the Medicine Journal Team

Search open positions that match your skills and interests. Medicine Journal seeks passionate, curious, creative, and solution-driven team players. SEARCH MEDICINE JOURNAL JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the professionals who are part of Medicine Journal.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, the latest news, and insider tips tailored to your preferences. Discover exciting and rewarding opportunities in the field of medical publishing.
Learn more about Medicine Journal
Industry

Similar Jobs

More Jobs at Medicine Journal

More Healthcare Jobs

Find similar Cybersecurity Governance, Risk, & Compliance Manager jobs: