Cybersecurity GRC Manager

Ann & Robert H. Lurie Children's Hospital of Chicago

$119K — $197K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in cybersecurity GRC, with at least 2 years in a management role.
  • Bachelor's degree required; Master's preferred in Information Security, Computer Science, or related field.
  • Expert knowledge of NIST CSF, PCI DSS, HIPAA, and HITECH.
  • Proven leadership and project management skills.
  • Proficiency in compliance, audit, and monitoring tools.
  • Relevant certifications such as CISM, CISSP, or CISA are required.

Responsibilities

  • Manage and lead the GRC staff, including hiring, training, and career development.
  • Oversee the creation of policies and standards aligned with regulatory requirements.
  • Lead risk assessment activities and track remediation efforts.
  • Manage compliance audits and produce both technical and executive reports.
  • Ensure vendor compliance through third-party risk assessments.
  • Direct enterprise security awareness initiatives and drive continuous improvement.
  • Manage data protection programs to secure sensitive information.

Benefits

  • Medical, dental, and vision insurance
  • Employer-paid group term life and disability
  • Employer contributions toward Health Savings Accounts
  • Flexible Spending Accounts
  • Paid Time Off (PTO) and Paid Holidays
  • 403(b) plan with a 5% employer match
  • Tuition assistance and support for student loans
  • Adoption benefits and backup childcare services
  • Employee Assistance Program and specialized behavioral health resources
  • Discounts on services at Lurie's facilities
Full Job Description
Leads the organization's GRC program to strengthen the security posture, reduce risk, and ensure compliance with NIST CSF, PCI DSS, HIPAA, and HITECH. Oversee team operations, strategy execution, and cross-departmental collaboration.

Essential Job Functions:
  • Manage GRC staff, including hiring, training, performance evaluation, and career development.
  • Oversee policy and standards creation, ensuring alignment with regulatory requirements and best practices.
  • Lead risk assessment activities and track remediation progress.
  • Manage compliance audits, producing technical and executive reports.
  • Oversee third-party risk assessments and ensure vendor compliance.
  • Direct enterprise security awareness initiatives and continuous improvement efforts.
  • Manage data protection programs to ensure security of sensitive information.
  • Lead vulnerability management programs, ensuring timely remediation.
  • Oversee email security programs and enforce related controls.
  • Coordinate with leadership on GRC strategies, metrics, and priorities.
  • Perform other related duties as assigned.


Knowledge, Skills and Abilities:
  • 5-7 years' experience in cybersecurity GRC, including at least 2 years in management.
  • Bachelor's degree required; Master's preferred in Information Security, Computer Science, or related field.
  • Expert knowledge of NIST CSF, PCI DSS, HIPAA/HITECH.
  • Proven leadership and project management skills.
  • Proficiency in compliance, audit, and monitoring tools.
  • Relevant certifications (e.g., CISM, CISSP, CISA) required.


Education
Bachelor's Degree (Required)

Pay Range
$119,600.00-$197,350.40 Salary

At Lurie's, we are committed to competitive and fair compensation aligned with market rates and internal equity, reflecting individual contributions, experience, and expertise. The pay range for this job indicates minimum and maximum targets for the position. Ranges are regularly reviewed to stay aligned with market conditions. In addition to base salary, Lurie's offer a comprehensive rewards package that may include differentials for some hourly employees, leadership incentives for select roles, health and retirement benefits, and wellbeing programs. For more details on other compensation, consult your recruiter or click the following link to learn more about our benefits.

Benefit Statement

For full time and part time employees who work 20 or more hours per week we offer a generous benefits package that includes:

Medical, dental and vision insurance

Employer paid group term life and disability

Employer contribution toward Health Savings Account

Flexible Spending Accounts

Paid Time Off (PTO), Paid Holidays and Paid Parental Leave

403(b) with a 5% employer match

Various voluntary benefits:
  • Supplemental Life, AD&D and Disability
  • Critical Illness, Accident and Hospital Indemnity coverage
  • Tuition assistance
  • Student loan servicing and support
  • Adoption benefits
  • Backup Childcare and Eldercare
  • Employee Assistance Program, and other specialized behavioral health services and resources for employees and family members
  • Discount on services at Lurie's facilities
  • Discount purchasing program

Similar Jobs

More Jobs at Ann & Robert H. Lurie Children's Hospital of Chicago

More Information Technology Jobs

Find similar Cybersecurity GRC Manager jobs: