Cybersecurity GRC Engineer

Hospital for Special Surgery

New York (NY)

Hybrid

USD 110,000 - 160,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Hospital for Special Surgery in New York City is seeking a Cybersecurity GRC Engineer to bridge governance, risk, and compliance with technical security operations.

You will design, implement, and automate security controls across systems, cloud resources, vendors, and enterprise technologies, working with cybersecurity engineers, IT, and auditors to strengthen our security posture.

Qualifications

  • Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives.
  • Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.
  • Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.
  • Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.
  • Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure.
  • Document control evidence, risk decisions, remediation plans, exceptions, and audit artifacts in a structured, repeatable format.

Responsibilities

  • Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives, validation procedures, and measurable security outcomes.
  • Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.
  • Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.
  • Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.
  • Partner with cybersecurity engineering, infrastructure, application, cloud, and networking teams to evaluate whether technical controls are implemented effectively and operating as intended.
  • Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure, while staying current on modern attack techniques and translating that knowledge into code and tooling.
  • Review operating systems, applications, cloud resources, network devices, security platforms, and third-party technologies against organizational policies, standards, and secure configuration baselines.
  • Correlate vulnerability findings, control gaps, compliance obligations, and business impact to support risk-based remediation prioritization.
  • Document control evidence, risk decisions, remediation plans, exceptions, and audit artifacts in a structured, accurate, and repeatable format.
  • Collaborate with internal stakeholders, external auditors, and compliance partners to support audits, assessments, regulatory inquiries, and control validation requests.
  • Develop metrics, reports, diagrams, and presentations that communicate cybersecurity risk, compliance posture, control effectiveness, and remediation status to technical and non-technical audiences.
  • Provide deep technical incident response support, including forensic analysis, custom scripting, and tool development during security investigations.

Job description

## Cybersecurity GRC EngineerApplyremote type: Hybridlocations: New York, NYtime type: Full timeposted on: Posted Todayjob requisition id: JR2026-105817**How you move is why we’re here. Now more than ever.**Get back to what you need and love to do. The possibilities are endless... Now more than ever, our guiding principles are helping us in our search for exceptional talent - candidates who align with our unique workplace culture and who want to maximize the abundant opportunities for growth and success. If this describes you then let’s talk! HSS is consistently among the top-ranked hospitals for orthopedics and rheumatology by U.S. News & World Report. As a recipient of the Magnet Award for Nursing Excellence, HSS was the first hospital in New York City to receive the distinguished designation. Whether you are early in your career or an expert in your field, you will find HSS an innovative, supportive and inclusive environment.Working with colleagues who love what they do and are deeply committed to our Mission, you too can be part of our transformation across the enterprise.**Emp Status**Regular Full time**Work Shift****Compensation Range**# **What you will be doing**# # PRINCIPAL DUTIES & RESPONSIBILITIES Are you energized by the challenge of turning cybersecurity requirements into practical, measurable, and automated controls? We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment.This role is ideal for someone who understands both the language of security frameworks and the realities of modern technical infrastructure. You will help design, implement, validate, and continuously improve security controls across systems, applications, cloud platforms, vendors, and enterprise technologies. You will work closely with cybersecurity engineers, analysts, architects, IT teams, compliance partners, privacy stakeholders, and auditors to strengthen Hospital for Special Surgery’s cybersecurity posture through risk-based, evidence-driven, and automation-enabled practices.The Cybersecurity GRC Engineer will play a key role in advancing continuous compliance, improving audit readiness, supporting risk assessments, and developing repeatable methods for validating security controls. This position requires technical curiosity, sound judgment, strong documentation skills, and the ability to translate regulatory and framework requirements into actionable engineering outcomes.# Position Activities* Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives, validation procedures, and measurable security outcomes.* Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.* Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.* Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.* Partner with cybersecurity engineering, infrastructure, application, cloud, and networking teams to evaluate whether technical controls are implemented effectively and operating as intended.* Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure, while staying current on modern attack techniques and translating that knowledge into code and tooling.* Review operating systems, applications, cloud resources, network devices, security platforms, and third-party technologies against organizational policies, standards, and secure configuration baselines.* Correlate vulnerability findings, control gaps, compliance obligations, and business impact to support risk-based remediation prioritization.* Document control evidence, risk decisions, remediation plans, exceptions, and audit artifacts in a structured, accurate, and repeatable format.* Collaborate with internal stakeholders, external auditors, and compliance partners to support audits, assessments, regulatory inquiries, and control validation requests.* Develop metrics, reports, diagrams, and presentations that communicate cybersecurity risk, compliance posture, control effectiveness, and remediation status to technical and non-technical audiences.* Provide deep technical incident response support, including forensic analysis, custom scripting, and tool development during security investigations.* Performs other related duties as assigned.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Hospital for Special Surgery • New York (NY), Northern (KY)

Hybrid
USD 140,000 - 175,000
Security Engineer
Security Engineer

Astera Cancer Care • Village of Port Jefferson (NY)

On-site
USD 90,000 - 105,000
Health Insurance starting Day 1
Dental, Vision, Life Insurance
Short & Long-Term Disability
+1
DevSecOps Engineer
DevSecOps Engineer

Hospital for Special Surgery • Richmond (AL)

On-site
USD 120,000 - 180,000
Senior Systems Engineer
Senior Systems Engineer

Hospital for Special Surgery • New York (NY)

Hybrid
USD 167,000 - 256,000
Cybersecurity Engineering Manager
Cybersecurity Engineering Manager

2000 Montefiore Health System, Inc. • Town of Greenburgh (NY)

On-site
USD 136,000 - 170,000
Cybersecurity Engineer (JR229560)
Cybersecurity Engineer (JR229560)

ViziRecruiter,LLC. • Village of Elmsford (NY)

On-site
USD 80,000 - 100,000
Finance Coordinator
Finance Coordinator

Hospital for Special Surgery • New York (NY)

Hybrid
USD 70,000 - 90,000
Patient Care Coordinator - Dr. Barsoum
Patient Care Coordinator - Dr. Barsoum

Hospital for Special Surgery • Northern (KY), New York (NY)

Hybrid
USD 78,713,000 - 120,061,000
Security Engineer
Security Engineer

New York Cancer & Blood Specialists • Terryville (NY)

On-site
USD 90,000
Health Insurance starting Day 1
Dental, Vision, Life Insurance
Short & Long-Term Disability
+1
Manager Operational Excellence
Manager Operational Excellence

Hospital for Special Surgery • New York (NY)

Hybrid
USD 109,000 - 166,000