Cybersecurity Governance, Risk, & Compliance Manager

Cybersecurity Jobs

Chattanooga (TN)

Hybrid

USD 110,000 - 170,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Erlanger Health System seeks a GRC Manager to build and sustain cybersecurity governance and compliance. The hybrid role aligns policy, risk, and control practices with healthcare and cybersecurity requirements, including NIST CSF 2.0 Govern and HIPAA Security Rule.

The role focuses on policy framework, compliance programs, and governance, translating complex topics for both technical and non-technical stakeholders while supporting after-hours audits and incidents.

Qualifications

  • Bachelor’s degree in information security, compliance, or a related field.
  • 7+ years of experience in cybersecurity governance and compliance, preferably in a healthcare system.
  • Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF.
  • Familiarity with NIST AI RMF, post-quantum cryptography standards, and cloud security frameworks.
  • Demonstrated ability to communicate complex compliance and risk concepts to both technical and non-technical audiences.

Responsibilities

  • Design, implement, and maintain the cybersecurity policy framework, compliance programs, and governance processes.
  • Ensure alignment with HIPAA Security Rule and evolving standards including AI security and cloud frameworks.
  • Identify risks related to AI, quantum computing, and cloud infrastructures, ensuring regulatory compliance.
  • Translate complex compliance topics for technical and non-technical stakeholders.
  • Provide occasional after-hours support for compliance-related incidents or audits.

Skills

GRC governance
Healthcare cybersecurity
Policy alignment
Risk management
Stakeholder communication
AI security awareness

Education

Bachelor’s degree in information security or related field

Tools

NIST CSF 2.0
HIPAA Security Rule
HITRUST CSF
NIST AI RMF
NIST PQC
CSA CCM
AWS Well-Architected Security
Azure Security Center
CSA STAR

Job description

The Cybersecurity Governance, Risk, & Compliance (GRC) Manager will build and sustain Erlanger Health System’s cybersecurity governance and compliance capabilities. This hybrid role focuses on aligning policy, risk, and control practices with healthcare and cybersecurity requirements, including NIST CSF 2.0 Govern and the HIPAA Security Rule.

Role Overview

The GRC Manager designs, implements, and maintains Erlanger Health System’s cybersecurity policy framework, compliance programs, and governance processes. The position ensures organizational alignment with NIST CSF 2.0 Govern function, the HIPAA Security Rule, and other emerging standards relevant to AI security, post-quantum cryptography, and cloud security.

Key Responsibilities
  • Design, implement, and maintain the cybersecurity policy framework, compliance programs, and governance processes to support alignment with NIST CSF 2.0 Govern function and healthcare regulations, including the HIPAA Security Rule.
  • Ensure alignment with emerging standards for AI security (such as NIST AI RMF), post-quantum cryptography, and cloud security frameworks (such as CSA CCM).
  • Identify and address risks associated with evolving technologies, including AI-integrated systems, quantum computing, and cloud-based infrastructures, with a focus on regulatory compliance and organizational resilience.
  • Apply expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, along with familiarity with NIST AI Risk Management Framework (RMF), NIST PQC post-quantum cryptography standards, and cloud security frameworks such as AWS Well-Architected Security, Azure Security Center, or CSA STAR.
  • Translate complex compliance and risk topics, including those related to AI, quantum, and cloud domains, for both technical and non-technical stakeholders.
  • Operate effectively in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.
  • Perform duties in a hybrid/on-site capacity as required, with variability in days and hours.
Required Qualifications
  • Bachelor’s degree in information security, compliance, or a related field.
  • 7+ years of experience in cybersecurity governance and compliance, preferably within a healthcare system, with exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.
  • Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF.
  • Familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (such as NIST PQC), and cloud security frameworks including AWS Well-Architected Security, Azure Security Center, or CSA STAR.
  • Demonstrated ability to communicate complex compliance and risk concepts to both technical and non-technical audiences.
Education
  • Required: Bachelor’s degree in information security, compliance, or a related field.
  • Preferred: Master’s degree, with coursework or emphasis on AI, quantum computing, or cloud technologies.
Experience
  • Required: 7+ years of experience in cybersecurity governance and compliance, preferably in a healthcare system, with exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.
Department Reporting Line

This role reports to the Chief Information Security Officer.

Relevant Technologies and Frameworks
  • NIST CSF 2.0
  • HIPAA Security Rule
  • HITRUST CSF
  • NIST AI Risk Management Framework (RMF)
  • NIST AI RMF
  • NIST PQC and NIST PQC standards
  • CSA CCM
  • AWS Well-Architected Security
  • Azure Security Center
  • CSA STAR
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Health Cyber GRC Leader: Policy, Risk & Compliance
Health Cyber GRC Leader: Policy, Risk & Compliance

Cybersecurity Jobs • Chattanooga (TN)

Hybrid
USD 110,000 - 170,000
Senior Security Engineer
Senior Security Engineer

AgelessRx • Town of Montana (WI)

On-site
USD 140,000 - 170,000
Cyber Security Manager
Cyber Security Manager

ESP Enterprises Inc. • The Woodlands (TX)

On-site
USD 150,000 - 210,000
Enterprise Cybersecurity Architect
Enterprise Cybersecurity Architect

Cybersecurity Jobs • Plano (TX)

Remote
USD 140,000 - 180,000
VP Info Security
VP Info Security

Piedmont • Atlanta (GA)

On-site
USD 180,000 - 260,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
Executive Director Cybersecurity
Executive Director Cybersecurity

The Security Executive Council • Miami (FL)

On-site
USD 100,000 - 130,000
Competitive salary
Health insurance
Professional development opportunities
Cyber Security Lead
Cyber Security Lead

Mednition • Burlingame (CA)

On-site
USD 140,000 - 230,000
VP Information Security
VP Information Security

The Security Executive Council • Dallas (TX)

On-site
USD 150,000 - 200,000
Competitive salary
Health insurance
Retirement plan