Olympus Corporation of the Americas

IT Security GRC Expert, Global

Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security/Technology or equivalent experience.
  • Relevant security certification (e.g., CISM, CISSP, CISA, CRISC) required.
  • Minimum 8 years of experience in IT Security or GRC roles.
  • At least 5 years of experience in a lead or managerial position.
  • Thorough knowledge of cybersecurity frameworks (ISO 27001/27002, NIST, CoBiT, etc.).
  • Excellent communication skills in both local language and English.

Responsibilities

  • Establish and operationalize IT Security governance structures.
  • Ensure consistent application of security-related policies across regions.
  • Translate regulatory requirements into actionable governance expectations.
  • Manage the lifecycle of IT Security risk including assessment and reporting.
  • Evaluate security risks from systems and third-party providers.
  • Govern security-related exception management and reporting.
  • Develop dashboards and executive-level reporting on IT Security risk.

Benefits

  • Competitive salaries and annual bonuses.
  • Comprehensive medical, dental, and vision coverage effective on start date.
  • 24/7 Employee Assistance Program.
  • Generous paid vacation and sick time.
  • Paid parental leave and adoption assistance.
  • On-site childcare, café, and fitness center.
Full Job Description
Working Location: PENNSYLVANIA, CENTER VALLEY; MASSACHUSETTS, WESTBOROUGH

Workplace Flexibility: Hybrid

Job Description

The Senior IT Security GRC Analyst (Global) is responsible for the governance, oversight, and lifecycle management of IT Security risk across Olympus. This role ensures that security-related risks, controls, and obligations are identified, assessed, governed, and transparently communicated in alignment with internal policy, external regulatory requirements, and recognized industry frameworks.

This position operates as a senior, globally consistent IT Security GRC role. While execution activities are distributed across regions, service providers, and technical teams, this role retains accountability for security risk governance, control framework alignment, exception management, and executive-level visibility.

The role functions as a leader by default, exercising judgment, influence, and authority without requiring formal people management, and serves as a trusted partner to IT, business, security operations, architecture, privacy, and assurance functions.

Job Duties

  • The Senior IT Security GRC Analyst (Global) is accountable for the following core responsibility areas. Responsibilities are global in scope, with execution assigned based on regional needs, maturity, and business priorities.
  • Establish, maintain, and operationalize IT Security governance structures aligned to Olympus policies and global standards.
  • Ensure security-related policies, standards, and procedures are consistently interpreted and applied across regions and systems.
  • Translate regulatory and framework requirements into actionable governance expectations for IT Security.
  • Own the end-to-end lifecycle of IT Security risk, including identification, assessment, prioritization, treatment tracking, escalation, and reporting.
  • Supports and escalates IT Security risk acceptance decisions in alignment with the enterprise risk management model and defined approval thresholds.
  • Maintain and govern the IT Security risk register within approved GRC tooling.
  • Evaluate security risks arising from systems, services, projects, third parties, and control gaps.
  • Ensure material security risks are communicated upward in a timely and disciplined manner.
  • Ensures material or unresolved IT Security risks are escalated and made visible in accordance with established governance processes.
  • This role owns IT Security risk. Enterprise-wide IT risk ownership and acceptance resides with IT Assurance.
  • Own governance of IT Security control frameworks (e.g., NIST, ISO), including control definition, mapping, and alignment to policy and regulatory requirements.
  • Monitor and assess control effectiveness using evidence, metrics, and tool outputs.
  • Validates security control effectiveness through evidence-based assessment methods aligned to recognized security frameworks.
  • Govern security-related exception management, including documentation, risk evaluation, treatment tracking, and reporting.
  • Partner with technical and operational teams responsible for control execution without assuming operational responsibility.
  • Conduct and govern IT Security risk assessments for third-party vendors and service providers.
  • Analyze security posture, identify control gaps, and recommend risk treatment options.
  • Track and report third-party security risks and remediation commitments.
  • Support secure procurement and onboarding processes through a security risk lens.
  • Support internal and external audits by providing security-focused evidence, analysis, and responses.
  • Coordinate security-related audit activities, timelines, and stakeholder engagement.
  • Ensure security control obligations are traceable, defensible, and audit-ready.
  • This role is not an audit function. Audit independence and ownership reside with IT Assurance.
  • Interpret outputs from security and compliance tools to identify trends, risks, and control performance.
  • Develop and maintain dashboards, KPIs, and executive-level reporting related to IT Security risk.
  • Translate technical security data into clear business-relevant insights for executive leadership.
  • Act as a leader and representative of IT Security GRC across global and regional stakeholders.
  • Direct and oversee MSSP activities within defined GRC scope, ensuring alignment to governance expectations.
  • Exercise judgment on escalation while maintaining proactive upward information sharing.
  • Influence outcomes through collaboration, clarity, and accountability rather than hierarchy.


Job Qualifications

Required:
  • A minimum of a Bachelor's degree in Information Security/ Technology is preferred or equivalent experience.
  • Should hold at least one relevant and related security certification (Ex: CISM, CISSP, CISA, CRISC, etc.)
  • Minimum 8 years of relevant work experience (IT Security, GRC, etc.)
  • At least 5 years of Lead/Manager experience.
  • Thorough Knowledge and understanding of Cybersecurity Frameworks, like ISO 27001/27002, NIST, CoBiT, BCM, ITIL, GDPR, ITAR, SOX (JSox) and IT Risk Management.
  • Excellent oral and written communication skills in local language.
  • Excellent oral and written communication skills in English.

Why join Olympus?

We offer a holistic employee experience supporting personal and professional well-being through meaningful work, equitable offerings, and a connected culture.

Equitable Offerings you can count on:
  • Competitive salaries, annual bonus and 401(k)* with company match
  • Comprehensive medical, dental, vision coverage effective on start date
  • 24/7 Employee Assistance Program
  • Free live and on-demand Wellbeing Programs
  • Generous Paid Vacation and Sick Time
  • Paid Parental Leave and Adoption Assistance*
  • 12 Paid Holidays
  • On-Site Child Daycare, Café, Fitness Center**


Connected Culture you can embrace:
  • Work-life integrated culture that supports an employee centric mindset
  • Offers onsite, hybrid and field work environments
  • Paid volunteering and charitable donation/match programs
  • Employee Resource Groups
  • Dedicated Training Resources and Learning & Development Programs
  • Paid Educational Assistance


*US Only

**Center Valley, PA and Westborough, MA

Are you ready to be a part of our team?

Learn more about our benefits and incentives: https://www.olympusamerica.com/careers/benefits-perks.

At Olympus, we are committed to Our Purpose of making people's lives healthier, safer and more fulfilling. As a global medical technology company, we partner with healthcare professionals to provide best-in-class solutions and services for early detection, diagnosis and minimally invasive treatment, aiming to improve patient outcomes by elevating the standard of care in targeted disease states.

For more than 100 years, Olympus has pursued a goal of contributing to society by producing products designed with the purpose of delivering optimal outcomes for its customers around the world.

Headquartered in Tokyo, Japan, Olympus employs more than 31,000 employees worldwide in nearly 40 countries and regions. Olympus Corporation of the Americas, a wholly owned subsidiary of Olympus Corporation, is headquartered in Center Valley, Pennsylvania, USA, and employs more than 5,200 employees throughout locations in North and South America. For more information, visit www.olympusamerica.com.

About Olympus Corporation of the Americas

Olympus Corporation of the Americas is a subsidiary of Olympus Corporation, a Japanese manufacturer of optics and reprography products. The company is a leading manufacturer of medical and surgical products, including endoscopes, laparoscopes, and video imaging systems. Olympus Corporation of the Americas was founded in 1968 and is headquartered in Center Valley, Pennsylvania. The company operates in the Americas region, including North and South America.
Learn more about Olympus Corporation of the Americas
Size
31,557 employees
Industry
Founded
1919
NASDAQ

Similar Jobs

More Jobs at Olympus Corporation of the Americas

More Information Technology Jobs

Find similar IT Security GRC Expert, Global jobs: