Lead GRC (Healthcare)
- Free
- Published date: April 22, 2025
-
- Massachusetts, United States
Position: Lead GRC(Healthcare)
Location: Boston, MA
Job Type: Long term Contract
Job Summary:
We are seeking a highly skilled Governance, Risk, and Compliance (GRC) Lead with expertise in the healthcare industry to oversee risk management, regulatory compliance, and IT governance. This role ensures adherence to HIPAA, HITRUST, GDPR, NIST, and other healthcare regulations while driving security best practices. The GRC Lead will work closely with IT, security, legal, and compliance teams to develop and enforce policies that protect patient data and ensure regulatory compliance.
Key Responsibilities:
Governance & Strategy
Develop and implement GRC frameworks and policies aligned with healthcare compliance standards.
Oversee IT governance practices, ensuring alignment with business and regulatory requirements.
Lead risk assessment programs and ensure effective risk mitigation strategies.
Collaborate with stakeholders to integrate GRC best practices across IT and business functions.
Risk Management
Conduct risk assessments, audits, and security evaluations to identify and mitigate vulnerabilities.
Develop and implement incident response plans, disaster recovery (DR), and business continuity plans (BCP) to ensure operational resilience.
Monitor and assess third-party vendors for security risks and compliance gaps.
Work with cybersecurity teams to ensure data protection measures are effective.
Compliance & Regulatory Management
Ensure compliance with HIPAA, HITRUST, NIST, GDPR, SOC 2, PCI-DSS, ISO 27001, and other industry regulations.
Lead and prepare for regulatory audits and assessments conducted by external agencies.
Develop training programs to educate employees on security, compliance, and privacy regulations.
Maintain documentation related to policies, procedures, risk registers, and compliance reports.
Required Qualifications:
10+ years of experience in GRC, healthcare IT compliance, or risk management.
Strong knowledge of HIPAA, HITRUST, NIST, GDPR, SOC 2, PCI-DSS, ISO 27001 frameworks.
Experience with GRC tools (Archer, ServiceNow GRC, MetricStream, etc.).
Proficiency in risk assessments, audits, policy creation, and regulatory reporting.
Ability to work cross-functionally with legal, IT security, and compliance teams.
Excellent communication, analytical, and leadership skills.
Preferred Qualifications:
Certifications: CISA, CISM, CRISC, CISSP, or HITRUST Certified CSF Practitioner.
Experience with cloud security and compliance in healthcare (AWS, Azure, GCP).
Background in third-party risk management and vendor compliance.
Reference : Lead GRC (Healthcare) jobs
Useful information
- Avoid scams by acting locally or paying with PayPal
- Never pay with Western Union, Moneygram or other anonymous payment services
- Don't buy or sell outside of your country. Don't accept cashier cheques from outside your country
- This site is never involved in any transaction, and does not handle payments, shipping, guarantee transactions, provide escrow services, or offer "buyer protection" or "seller certification"
Related listings
-
Home based Job work,form filling work call 7708244092.
Technology (Karnataka) July 1, 2025 FreeWe have the projects called US Medical form filling process. This process is available not only for single system and also bulk systems for centers. We will provide 3000 US Hospital data for the period of 15 days (Including Sundays).After 3 days Qual...
-
Genuine US Medical Form Filling project available call us 7708244092
Technology (Karnataka) July 1, 2025 FreeWe have the projects called US Medical form filling process. This process is available not only for single system and also bulk systems for centers. We will provide 3000 US Hospital data for the period of 15 days (Including Sundays).After 3 days Qual...
-
Earn minimum 30k in Data US Medical Form Filling project 7708244092
Technology (Karnataka) July 1, 2025 Free- Data is provided in TIFF image files. - Adherence to flexible data entry guidelines is necessary. - A total of 3000 records need to be entered in a span of 15 days. - A contract for 11 months will be provided. - Quality checks will be conducted, wi...