CybersecurityJobs.io
← Back to all jobs

Job Description

The Cybersecurity Governance, Risk, & Compliance (GRC) Manager will build and sustain Erlanger Health System’s cybersecurity governance and compliance capabilities. This hybrid role focuses on aligning policy, risk, and control practices with healthcare and cybersecurity requirements, including NIST CSF 2.0 Govern and the HIPAA Security Rule.

Role Overview

The GRC Manager designs, implements, and maintains Erlanger Health System’s cybersecurity policy framework, compliance programs, and governance processes. The position ensures organizational alignment with NIST CSF 2.0 Govern function, the HIPAA Security Rule, and other emerging standards relevant to AI security, post-quantum cryptography, and cloud security.

Key Responsibilities

  • Design, implement, and maintain the cybersecurity policy framework, compliance programs, and governance processes to support alignment with NIST CSF 2.0 Govern function and healthcare regulations, including the HIPAA Security Rule.
  • Ensure alignment with emerging standards for AI security (such as NIST AI RMF), post-quantum cryptography, and cloud security frameworks (such as CSA CCM).
  • Identify and address risks associated with evolving technologies, including AI-integrated systems, quantum computing, and cloud-based infrastructures, with a focus on regulatory compliance and organizational resilience.
  • Apply expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, along with familiarity with NIST AI Risk Management Framework (RMF), NIST PQC post-quantum cryptography standards, and cloud security frameworks such as AWS Well-Architected Security, Azure Security Center, or CSA STAR.
  • Translate complex compliance and risk topics, including those related to AI, quantum, and cloud domains, for both technical and non-technical stakeholders.
  • Operate effectively in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.
  • Perform duties in a hybrid/on-site capacity as required, with variability in days and hours.

Required Qualifications

  • Bachelor’s degree in information security, compliance, or a related field.
  • 7+ years of experience in cybersecurity governance and compliance, preferably within a healthcare system, with exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.
  • Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF.
  • Familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (such as NIST PQC), and cloud security frameworks including AWS Well-Architected Security, Azure Security Center, or CSA STAR.
  • Demonstrated ability to communicate complex compliance and risk concepts to both technical and non-technical audiences.

Education

  • Required: Bachelor’s degree in information security, compliance, or a related field.
  • Preferred: Master’s degree, with coursework or emphasis on AI, quantum computing, or cloud technologies.

Experience

  • Required: 7+ years of experience in cybersecurity governance and compliance, preferably in a healthcare system, with exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.

Department Reporting Line

This role reports to the Chief Information Security Officer.

Relevant Technologies and Frameworks

  • NIST CSF 2.0
  • HIPAA Security Rule
  • HITRUST CSF
  • NIST AI Risk Management Framework (RMF)
  • NIST AI RMF
  • NIST PQC and NIST PQC standards
  • CSA CCM
  • AWS Well-Architected Security
  • Azure Security Center
  • CSA STAR

Similar Jobs