> Markdown version of [/jobs/ext/2994331-director-of-cybersecurity-grc](https://www.wearedevelopers.com/jobs/ext/2994331-director-of-cybersecurity-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Cybersecurity- GRC - **Company:** Insight Global - **Location:** Austin, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Software Security - **Published:** September 19, 2026 - **Apply:** https://dejobs.org/x/x/6F06F8A0842741FCBE2B9B656E2FEFB7/job/ ## About the Role 8+ years of experience in healthcare, banking, defense, or another highly regulated/high-security environment 5+ years of progressive cybersecurity leadership experience with ownership of GRC programs Strong Governance, Risk & Compliance (GRC) background Experience building, maturing, or transforming cybersecurity governance programs Strong cybersecurity governance, risk management, policy development, and regulatory compliance expertise Experience conducting security risk assessments and managing enterprise risk registers Ability to communicate cybersecurity risk and strategy to executive leadership Experience leading teams and influencing stakeholders across the organization Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, COBIT, NIST 800-171, HIPAA, and related regulations CISSP or CISM certification required Healthcare industry experience Experience conducting HIPAA Security Risk Analyses Experience with CMMC or NIST 800-171 compliance programs Third-party/vendor cybersecurity risk management experience Experience developing cybersecurity awareness programs HCISPP, CRISC, CISA, or other healthcare GRC certifications Experience supporting clinical, research, or academic environments ## Description Insight Global is seeking a Director of Cybersecurity Governance, Risk & Compliance for a leading healthcare and academic organization. This leader will be responsible for building and advancing the organization's cybersecurity governance, risk, and compliance function while supporting a complex clinical, research, and academic environment. The ideal candidate brings a balance of executive-level cybersecurity leadership and deep GRC expertise, with experience assessing risk, developing policies, driving compliance initiatives, and improving overall security maturity. This is not a hands-on security operations role. Instead, the focus is on cybersecurity governance, risk assessments, compliance strategy, vendor risk management, policy development, incident response coordination, and executive communication. The successful candidate will play a critical role in shaping cybersecurity strategy as the organization continues its growth toward future hospital operations while leading teams, influencing stakeholders, and ensuring alignment with healthcare regulatory requirements and industry security frameworks. Day-to-Day: Lead and execute the enterprise cybersecurity GRC strategy for Dell Medical School Build and mentor a team of GRC analysts and compliance professionals Conduct security risk assessments and manage remediation initiatives across the organization Lead annual HIPAA Security Risk Analyses and compliance efforts Develop and maintain cybersecurity policies, standards, and procedures Own vendor and third-party security risk assessments and onboarding approvals Present risk posture, compliance status, and strategic recommendations to executive leadership Lead incident response coordination for major security events beyond enterprise response capabilities Develop business continuity and disaster recovery strategies Oversee cybersecurity governance for research environments, application security, and cloud security programs We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [A Computer Is All You Need](https://www.wearedevelopers.com/videos/100142-a-computer-is-all-you-need) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture)