Cybersecurity GRC Manager, FCH - IT - SECURITY

Remote Full-time
About the position Healthcare security isn’t a compliance checkbox problem — it’s a patient safety problem. At Froedtert ThedaCare, the Cybersecurity GRC Manager owns the program that connects our governance posture to real-world risk outcomes for patients, clinicians, and the communities we serve across Wisconsin. This is a high-visibility, high-autonomy leadership role inside a Cybersecurity & Infrastructure team that operates with strategic intent and operational rigor. You will build and run a team of 5+ GRC professionals, serve as the internal subject matter authority on compliance and risk, and translate complex regulatory requirements into actionable programs that the broader organization can execute against. If you’ve built GRC programs from scratch (or rebuilt ones that needed it), know your way around a HIPAA gap analysis and a third-party risk assessment in equal measure, are people-focused, and lead with clarity rather than bureaucracy — this is the role for you Responsibilities • Lead, mentor, and grow a team of 5+ GRC analysts and specialists across compliance, risk, policy, and awareness domains • Establish clear role expectations, development pathways, and performance standards for each team member • Foster a team culture that balances rigor with pragmatism — we care about outcomes, not just documentation • Serve as the organization’s functional lead for HIPAA Privacy and Security Rule compliance, including ongoing gap assessment and remediation tracking • Coordinate with Legal, Privacy, and Clinical Operations to ensure compliance obligations are understood and operationalized across the enterprise • Oversee preparation for and response to regulatory inquiries, OCR investigations, and audit activity • Own the enterprise cybersecurity risk register, ensuring risks are identified, assessed, prioritized, and tracked to resolution • Lead the third-party risk management program, including vendor onboarding assessments, ongoing monitoring, and risk-tiering across the supply chain • Develop risk reporting for executive and board audiences, translating technical risk into business impact language • Own the cybersecurity policy lifecycle: authorship, review cadence, version control, approval workflows, and exception management • Maintain alignment to NIST CSF, managing control mapping, evidence collection, and control effectiveness measurement • Drive continuous improvement of the controls environment based on assessment findings, threat intelligence inputs, and regulatory changes • Serve as the primary point of contact and program lead for internal and external cybersecurity audits and assessments • Coordinate evidence collection, manage stakeholder readiness, and oversee finding remediation tracking through to closure • Develop and maintain audit-ready documentation across all GRC domains • Own the enterprise security awareness program, including curriculum development, delivery scheduling, and effectiveness measurement • Manage the phishing simulation program end-to-end: scenario design, cadence, metrics, and targeted follow-up training for at-risk populations • Tailor awareness content for diverse audiences — from clinical staff to executive leadership — with a voice that educates rather than shames Requirements • A minimum of six year experience in a related field. • A Bachelors degree is required. • In-depth knowledge of cybersecurity frameworks including but not limited to NIST CF, HITRUST CSF, ISO 27001. • Experience in managing or leading security organizations responsible for GRC, Cybersecurity, Medical Device Security, Security Operations Centers. • Understanding of general security concepts including but not limited to cryptography, DLP, Security Operations Center, Security Managed Services, SEM, FW, Audit. • Demonstrated record of managing third party security services, preferably with the cloud providers. • Ability to communicate and represent IT Security organization with all business partners and third party vendors. • Strong oral, presentation, writing skills. and demonstrated record to deliver results. • Ability to build relationships with business stakeholders of the IT Security program • Familiarity with HIPAA Privacy and Security Rules and their operational implications for a large health system • Ability to develop and present executive-level risk reporting that communicates risk in business impact terms • Comfort operating in a matrixed environment with multiple stakeholder groups including Legal, HR, IT, Clinical Operations, and executive leadership Nice-to-haves • Prefer 3+ years leading or managing a team in a GRC, compliance, or risk management capacity • Prefer experience in a healthcare or other highly regulated industry, with direct exposure to HIPAA compliance obligations • Demonstrated experience managing a third-party risk program, including vendor assessments and risk tiering • Prefer prior experience building or significantly maturing a GRC program, not just maintaining one • Prefer experience managing external audits or assessments (SOC 2, HITRUST, OCR, internal audit, etc.) • Bachelors in Computer Science or similar degree is preferred. • Experience in Healthcare industry is preferred. • Prefer CISSP, CISM, CRISC, HCISPP, or equivalent certification • Prefer Certified in Healthcare Privacy and Security (CHPS) or equivalent Benefits • Paid time off • Growth opportunity- Career Pathways & Career Tuition Assistance, CEU opportunities • Academic Partnership with the Medical College of Wisconsin • Referral bonuses • Retirement plan - 403b • Medical, Dental, Vision, Life Insurance, Short & Long Term Disability, Free Workplace Clinics • Employee Assistance Programs, Adoption Assistance, Healthy Contributions, Care@Work, Moving Assistance, Discounts on gym memberships, travel and other work life benefits available
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

**Experienced Customer Support Agent – Chat (Remote / Entry Level / Part Time) at blithequark**

Remote Full-time

eDiscovery Forensic Analyst /DC onsite at times and Telework otherwise/

Remote Full-time

[Remote] AI & Automation Operations Support Analyst

Remote Full-time

Work At Home Data Entry - Remote

Remote Full-time

Market VP Philanthropy, Houston

Remote Full-time

Case Manager Registered Nurse - Field (Sussex County, New Jersey)

Remote Full-time

Interior Design Assistant

Remote Full-time

**Experienced Seasonal Customer Service Representative - PSP at arenaflex**

Remote Full-time

**Experienced Healthcare Customer Service Representative – Remote USA Opportunity at arenaflex**

Remote Full-time

Data Engineer - Health Sensing

Remote Full-time
← Back to Home