Hospital for Special Surgery

Cybersecurity GRC Engineer

Hospital for Special Surgery$99K — $150K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in Cybersecurity, with a focus on Governance, Risk, and Compliance (GRC)
  • Strong understanding of security frameworks and compliance regulations
  • Proficiency in designing and implementing automated security controls
  • Experience in performing technical risk assessments and gap analyses
  • Excellent documentation and communication skills, with the ability to convey complex information to diverse audiences

Responsibilities

  • Translate cybersecurity and regulatory requirements into actionable technical control objectives
  • Design and maintain automated workflows for compliance monitoring and audit readiness
  • Develop policy-as-code and validation methods to enhance efficiency in security assessments
  • Conduct risk assessments and gap analyses of technologies and systems
  • Collaborate with IT and engineering teams to ensure effective implementation of security controls
  • Review and validate system configurations against organizational security standards
  • Document evidence and decisions in a structured and repeatable manner
  • Support audits and assessments by interacting with both internal and external stakeholders

Benefits

  • Regular full-time employment status
  • Opportunity to work in a mission-driven healthcare environment
  • Collaboration with diverse technical teams
  • Involvement in advancing and shaping cybersecurity practices
  • Professional growth opportunities within the organization
Full Job Description

Emp Status

Regular Full time

Work Shift

Compensation Range

The base pay scale for this position is $99,000.00 - $150,750.00. In addition, this position will be eligible for additional benefits consistent with the role. The salary of the finalist selected for this role will be determined based on various factors, including but not limited to: scope of role, level of experience, education, accomplishments, internal equity, budget, and subject to Fair Market Value evaluation. The hiring range listed is a good faith determination of potential compensation at the time of this job advertisement and may be modified in the future.

What you will be doing

PRINCIPAL DUTIES & RESPONSIBILITIES
Are you energized by the challenge of turning cybersecurity requirements intopractical, measurable, and automated controls? We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment.

This role is ideal for someone who understands both the language of security frameworks and the realities of modern technical infrastructure. You will help design, implement, validate, and continuously improve security controls across systems, applications, cloud platforms, vendors, and enterprise technologies. You will work closely with cybersecurity engineers, analysts, architects, IT teams, compliance partners, privacy stakeholders, and auditors to strengthen Hospital for Special Surgery9s cybersecurity posture through risk-based, evidence-driven, and automation-enabled practices.

The Cybersecurity GRC Engineer will play a key role in advancing continuous compliance, improving audit readiness, supporting risk assessments, and developing repeatable methods for validating security controls. This position requires technical curiosity, sound judgment, strong documentation skills, and the ability to translate regulatory and framework requirements into actionable engineering outcomes.

Position Activities
  • Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives, validation procedures, and measurable security outcomes.
  • Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.
  • Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.
  • Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.
  • Partner with cybersecurity engineering, infrastructure, application, cloud, and networking teams to evaluate whether technical controls are implemented effectively and operating as intended.
  • Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure, while staying current on modern attack techniques and translating that knowledge into code and tooling.
  • Review operating systems, applications, cloud resources, network devices, security platforms, and third-party technologies against organizational policies, standards, and secure configuration baselines.
  • Correlate vulnerability findings, control gaps, compliance obligations, and business impact to support risk-based remediation prioritization.
  • Document control evidence, risk decisions, remediation plans, exceptions, and audit artifacts in a structured, accurate, and repeatable format.
  • Collaborate with internal stakeholders, external auditors, and compliance partners to support audits, assessments, regulatory inquiries, and control validation requests.
  • Develop metrics, reports, diagrams, and presentations that communicate cybersecurity risk, compliance posture, control effectiveness, and remediation status to technical and non-technical audiences.
  • Provide deep technical incident response support, including forensic analysis, custom scripting, and tool development during security investigations.
  • Performs other related duties as assigned.

About Hospital for Special Surgery

Hospital for Special Surgery (HSS) is a hospital in New York City that specializes in orthopedic surgery and the treatment of rheumatologic conditions. Founded in 1863 by James Knight, HSS is the oldest orthopedic hospital in the United States. The hospital has been ranked the top orthopedic hospital in the United States by U.S. News & World Report for 11 consecutive years. HSS has a staff of over 4000 employees, including more than 200 physicians and surgeons, and treats over 32,000 inpatients and 300,000 outpatients annually.
Learn more about Hospital for Special Surgery
Size
4,000 employees
Industry
Founded
1863

Similar Jobs

More Jobs at Hospital for Special Surgery

More Healthcare Jobs

Find similar Cybersecurity GRC Engineer jobs: