Director of Cybersecurity- GRC
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Insight Global is seeking a Director of Cybersecurity Governance, Risk & Compliance for a leading healthcare and academic organization. This leader will be responsible for building and advancing the organization’s cybersecurity governance, risk, and compliance function while supporting a complex clinical, research, and academic environment. The ideal candidate brings a balance of executive-level cybersecurity leadership and deep GRC expertise, with experience assessing risk, developing policies, driving compliance initiatives, and improving overall security maturity. This is not a hands-on security operations role. Instead, the focus is on cybersecurity governance, risk assessments, compliance strategy, vendor risk management, policy development, incident response coordination, and executive communication. The successful candidate will play a critical role in shaping cybersecurity strategy as the organization continues its growth toward future hospital operations while leading teams, influencing stakeholders, and ensuring alignment with healthcare regulatory requirements and industry security frameworks.
Day-to-Day:
Lead and execute the enterprise cybersecurity GRC strategy for Dell Medical School
Build and mentor a team of GRC analysts and compliance professionals
Conduct security risk assessments and manage remediation initiatives across the organization
Lead annual HIPAA Security Risk Analyses and compliance efforts
Develop and maintain cybersecurity policies, standards, and procedures
Own vendor and third-party security risk assessments and onboarding approvals
Present risk posture, compliance status, and strategic recommendations to executive leadership
Lead incident response coordination for major security events beyond enterprise response capabilities
Develop business continuity and disaster recovery strategies
Oversee cybersecurity governance for research environments, application security, and cloud security programs
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global’s Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Requirements
8+ years of experience in healthcare, banking, defense, or another highly regulated/high-security environment
5+ years of progressive cybersecurity leadership experience with ownership of GRC programs
Strong Governance, Risk & Compliance (GRC) background
Experience building, maturing, or transforming cybersecurity governance programs
Strong cybersecurity governance, risk management, policy development, and regulatory compliance expertise
Experience conducting security risk assessments and managing enterprise risk registers
Ability to communicate cybersecurity risk and strategy to executive leadership
Experience leading teams and influencing stakeholders across the organization
Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, COBIT, NIST 800-171, HIPAA, and related regulations
CISSP or CISM certification required Healthcare industry experience
Experience conducting HIPAA Security Risk Analyses
Experience with CMMC or NIST 800-171 compliance programs
Third-party/vendor cybersecurity risk management experience
Experience developing cybersecurity awareness programs
HCISPP, CRISC, CISA, or other healthcare GRC certifications
Experience supporting clinical, research, or academic environments
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Building Security Champions
What Are The Top Skills Required For Azure Developers?