Insight Global logo

REMOTE Director of Cybersecurity- GRC

Insight Global

Remote · USJobSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Remote · US
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

CISSP Or CISM Certification

Job overview

Insight Global seeks a Director of Cybersecurity Governance, Risk & Compliance to lead GRC strategy for a healthcare and academic organization, building teams, conducting risk assessments, managing compliance, and advising executive leadership on security posture and regulatory requirements.

Skills & qualifications

RequiredNice to have

Skills

Governance Risk ComplianceCybersecurity GovernancePolicy DevelopmentRegulatory ComplianceSecurity Risk AssessmentsVendor Risk ManagementIncident Response CoordinationBusiness ContinuityDisaster RecoveryCloud SecurityApplication SecurityNIST CSFISO 27001COBITNIST 800‑171HIPAACMMCCISSPCISMHCISPPCRISCCISAExecutive CommunicationLeadershipTeam Mentoring

Qualifications

CISSP or CISM CertificationHCISPP, CRISC, CISA or Other Healthcare GRC Certifications5+ Years Progressive Cybersecurity Leadership Experience3+ Years Provider Healthcare Experience

Full job description

Job Description

Insight Global is seeking a Director of Cybersecurity Governance, Risk & Compliance for a leading healthcare and academic organization. This leader will be responsible for building and advancing the organization's cybersecurity governance, risk, and compliance function while supporting a complex clinical, research, and academic environment. The ideal candidate brings a balance of executive-level cybersecurity leadership and deep GRC expertise, with experience assessing risk, developing policies, driving compliance initiatives, and improving overall security maturity. This is not a hands-on security operations role. Instead, the focus is on cybersecurity governance, risk assessments, compliance strategy, vendor risk management, policy development, incident response coordination, and executive communication. The successful candidate will play a critical role in shaping cybersecurity strategy as the organization continues its growth toward future hospital operations while leading teams, influencing stakeholders, and ensuring alignment with healthcare regulatory requirements and industry security frameworks.

Day-to-Day: Lead and execute the enterprise cybersecurity GRC strategy for Dell Medical School Build and mentor a team of GRC analysts and compliance professionals Conduct security risk assessments and manage remediation initiatives across the organization Lead annual HIPAA Security Risk Analyses and compliance efforts Develop and maintain cybersecurity policies, standards, and procedures Own vendor and third-party security risk assessments and onboarding approvals Present risk posture, compliance status, and strategic recommendations to executive leadership Lead incident response coordination for major security events beyond enterprise response capabilities Develop business continuity and disaster recovery strategies Oversee cybersecurity governance for research environments, application security, and cloud security programs

Skills and Requirements

3+ years of recent experience in a provider healthcare space. 5+ years of progressive cybersecurity leadership experience with ownership of GRC programs Strong Governance, Risk & Compliance (GRC) background Experience building, maturing, or transforming cybersecurity governance programs Strong cybersecurity governance, risk management, policy development, and regulatory compliance expertise Experience conducting security risk assessments and managing enterprise risk registers Ability to communicate cybersecurity risk and strategy to executive leadership Experience leading teams and influencing stakeholders across the organization Working knowledge of cybersecurity frameworks such as NIST CSF, ISO 27001, COBIT, NIST 800-171, HIPAA, and related regulations CISSP or CISM certification required Experience conducting HIPAA Security Risk Analyses Experience with CMMC or NIST 800-171 compliance programs Third-party/vendor cybersecurity risk management experience Experience developing cybersecurity awareness programs HCISPP, CRISC, CISA, or other healthcare GRC certifications Experience supporting clinical, research, or academic environments Day-to-Day:

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.