Security Engineer, GRC & Compliance — Risk & Audit Ready

AirLife group

Grand Rapids (MI)

Hybrid

USD 115,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision coverage
401(k)
Paid time off

Job summary

AirLife is seeking a Security Engineer – Governance, Risk & Compliance to advance our information security program in a regulated medical device manufacturing environment. You will lead risk assessments, ensure regulatory alignment (FDA 21 CFR Part 820, ISO 13485, GDPR), and manage audit readiness across IT and operational technology.

The role requires 4–6 years IT, 3+ years cybersecurity with a GRC focus, plus strong policy development and coordination with QA/RA, Legal, and external auditors.

Qualifications

  • Knowledge of security risk management frameworks and regulatory regimes.
  • Experience with ITGC and audit support in regulated environments.
  • Familiarity with GDPR and US state privacy laws and IT implications.
  • Ability to document findings and remediation plans for leadership.
  • Proven ability to create and maintain security policies and control evidence.

Responsibilities

  • Develop and maintain AirLife's security policies, standards, and procedures.
  • Conduct periodic risk assessments and gap analyses and prioritize remediation.
  • Own AirLife's security compliance posture across frameworks (NIST, ISO, GDPR).
  • Support ITGC compliance and prepare audit evidence for auditors.
  • Coordinate with QA/RA and Legal to align controls with FDA/ISO obligations.
  • Administer security awareness training and phishing simulations.
  • Maintain vulnerability management program and report trends to leadership.
  • Collaborate with MDR/MSSP providers to ensure aligned security services.
  • Prepare evidence packages and manage remediation tracking for audits.

Skills

NIST CSF
NIST SP 800-30/37
ISO 27001
CIS Controls
FDA 21 CFR Part 820 / QMSR
ISO 13485
ITGC controls
SOX controls
GDPR knowledge
risk assessments
security policies
vulnerability management
KnowBe4
MDR/MSSP coordination
Arctic Wolf
audit coordination
communication with executives

Education

Bachelor's degree in Cybersecurity/IT/CS
GRC-relevant certification(s)

Tools

Smartsheet

Job description

AirLife is seeking a Security Engineer – Governance, Risk & Compliance to advance our information security program in a regulated medical device manufacturing environment. You will lead risk assessments, ensure regulatory alignment (FDA 21 CFR Part 820, ISO 13485, GDPR), and manage audit readiness across IT and operational technology.

The role requires 4–6 years IT, 3+ years cybersecurity with a GRC focus, plus strong policy development and coordination with QA/RA, Legal, and external auditors.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security GRC Engineer: Compliance & Risk
Security GRC Engineer: Compliance & Risk

Airlife • El Paso (TX)

On-site
USD 115,000 - 130,000
GRC Security Engineer – Regulated Manufacturing
GRC Security Engineer – Regulated Manufacturing

AirLife • Grand Rapids (MI)

On-site
USD 90,000 - 140,000
medical coverage
dental coverage
vision coverage
+9
Security Engineer-Governance, Risk & Compliance
Security Engineer-Governance, Risk & Compliance

Airlife • El Paso (TX)

On-site
USD 115,000 - 130,000
Security Engineer-Governance, Risk & Compliance
Security Engineer-Governance, Risk & Compliance

AirLife • Grand Rapids (MI)

On-site
USD 90,000 - 140,000
medical coverage
dental coverage
vision coverage
+9
Security Engineer-Governance, Risk & Compliance
Security Engineer-Governance, Risk & Compliance

AirLife group • Grand Rapids (MI)

Hybrid
USD 115,000 - 130,000
Medical, dental, and vision coverage
401(k)
Paid time off
Security & Compliance Leader: Governance, Audits & AI Readiness
Security & Compliance Leader: Governance, Audits & AI Readiness

RL People • Mather (CA)

On-site
USD 110,000 - 170,000
Senior GRC Lead — Build Compliance that Drives Confidence
Senior GRC Lead — Build Compliance that Drives Confidence

ClearData Networks, Inc. in • Raleigh (NC)

On-site
USD 130,000 - 170,000
Opportunity to learn
Vacation + personal days
Employee stock ownership
+2
Senior InfoSec Engineer: GRC, AI Security & Automation
Senior InfoSec Engineer: GRC, AI Security & Automation

SmartRecruiters Inc • Town of Poland (NY)

Hybrid
USD 110,000 - 150,000
Competitive salaries
Remote-friendly culture
Strong internal mobility
Security GRC Engineer: Risk, Audit & Compliance
Security GRC Engineer: Risk, Audit & Compliance

Whatnot • Seattle (WA)

On-site
USD 175,000 - 230,000
Health Insurance options including US
Work From Home support
Home office setup allowance
+5
Product Security Engineer (Med Device)
Product Security Engineer (Med Device)

Insight Global • Warsaw (IN)

On-site
USD 120,000 - 180,000