> Markdown version of [/jobs/ext/532737-grc-cybersecurity-lead](https://www.wearedevelopers.com/jobs/ext/532737-grc-cybersecurity-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Cybersecurity Lead - **Company:** Osg Inc - **Location:** Carol Stream, IL, United States - **Experience:** Expert - **Salary:** $90,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Information Systems, Information Technology Audit, PCI Data Security Standards, Google Cloud, Cloud Platform System, Information Technology, Software Version Control, Servicenow - **Published:** June 14, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1a705437ff5cb89d ## About the Role Do you have experience in Information security auditing?, Do you have a Bachelor's degree?, * Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field. * 8+ years of progressive experience in cybersecurity GRC, IT audit, information security, or compliance (at least 3 years focused on policy, risk, and/or compliance). * Hands-on experience operating a cybersecurity risk register and end-to-end risk management lifecycle. * Experience supporting audits or certifications under at least two of: NIST CSF, HITRUST, HIPAA, PCI DSS, SOC 2. * Deep working knowledge of NIST CSF, HITRUST CSF, HIPAA Security and Privacy Rules, and PCI DSS 4.0. * Familiarity with adjacent frameworks: SOC 2, ISO/IEC 27001, NIST SP 800-53, NIST SP 800-171. * Experience reviewing and red-lining cybersecurity provisions in commercial contracts, BAAs, and DPAs. * Experience with at least one GRC platform (Archer, ServiceNow GRC, OneTrust, LogicGate, AuditBoard, Hyperproof, Drata, Vanta, or similar). * Strong written and verbal communication; able to translate technical risk into business language for executive, board, and client audiences. * Proven ability to manage multiple workstreams and deadlines in a matrixed, cross-functional environment. Preferred: * One or more of: CISSP, CISA, CISM, CRISC, CIPP, HCISPP, HITRUST CCSFP, or PCI ISA. * Experience in healthcare, financial services, fintech, payments, or other heavily regulated industries. * Hands-on experience supporting HITRUST r2 certification and/or PCI DSS 4.0 attestation. * Working knowledge of HIPAA, GDPR, CCPA/CPRA, and U.S. state privacy laws. * Familiarity with cloud platforms (AWS, Azure, GCP) and SaaS environments, including shared responsibility models. * Experience in an organization undergoing rapid growth, M&A activity, or platform modernization. ## Description As a GRC Cybersecurity Lead, you will own OSG's cybersecurity GRC program end-to-end. This is a high-visibility role and you will work shoulder-to-shoulder with executive leadership, Legal, Compliance, Privacy, Internal Audit, IT, Engineering, Product, and Sales. Reporting directly to the CISO and have a meaningful seat at the table where risk decisions get made., * Own enterprise-wide cyber risk analysis and reporting, from methodology to board-level dashboards. * Develop and continuously refine risk assessment methodologies, scoring models, and risk appetite statements. * Identify, evaluate, and quantify cybersecurity risks; recommend mitigation strategies and track remediation to closure. * Lead annual and ad hoc enterprise risk assessments, including third-party/vendor risk reviews. * Coordinate tabletop exercises and Incident Response Plan testing., * Keep all cybersecurity policies, standards, and procedures current and aligned to NIST CSF, HITRUST CSF, HIPAA, and PCI DSS 4.0. * Lead the annual policy review and approval cycle, including version control, exception management, and stakeholder sign-off. * Develop and map controls across frameworks to minimize duplication and audit fatigue. * Communicate policy changes and provide interpretive guidance to internal stakeholders and control owners., * Partner with Compliance, IT, Engineering, Product, Legal, HR, Finance, and Operations to ensure risks are captured in OSG's enterprise risk register. * Maintain accuracy and completeness of the risk register; track treatment plans and accept/transfer/mitigate/avoid decisions. * Facilitate risk review forums, steering committees, and quarterly risk governance meetings. * Escalate critical or unresolved risks to the CISO and executive leadership. Compliance & Regulatory Partnership * Work with Compliance to ensure cybersecurity policies meet regulatory requirements (HIPAA, PCI DSS, state privacy laws) and client contractual obligations. * Support internal and external audits; HITRUST, SOC 2, PCI DSS, HIPAA, and client audits including coordinating evidence, responses, and remediation. * Track regulatory and framework changes and translate them into actionable policy and control updates. * Manage client-facing security questionnaires and assessments (CAIQ, SIG, HITRUST inheritance, custom questionnaires). Contract Review * Review MSAs, vendor contracts, BAAs, DPAs, and other agreements to confirm cybersecurity and data protection sections meet OSG and regulatory requirements. * Validate clauses covering data protection, breach notification, audit rights, subcontractor controls, encryption, retention, and data return/destruction. * Partner with Legal, Procurement, and Sales to negotiate security-related contract language. * Maintain a library of standard security clauses, fallback positions, and contract templates. Cross-Functional Leadership * Serve as the senior subject-matter expert for GRC, mentoring analysts and influencing stakeholders across the organization without formal reporting authority. * Build strong relationships with IT, Engineering, Product, Legal, Compliance, Privacy, Internal Audit, and HR. ## Related Videos - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)