Cybersecurity GRC Engineer at Hospital for Special Surgery | United States | Rezi

Cybersecurity GRC Engineer at Hospital for Special Surgery

Cybersecurity GRC Engineer

Hospital for Special Surgery · United States

Today

Cybersecurity GRC Engineer

Hospital for Special Surgery · United States

3 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ideal for someone who understands both the language of security frameworks and the realities of modern technical infrastructure. You will help design, implement, validate, and continuously improve security controls across systems, applications, cloud platforms, vendors, and enterprise technologies.

Responsibilities

  • Translate cybersecurity, privacy, regulatory, and framework requirements into technical control objectives, validation procedures, and measurable security outcomes.
  • Design, implement, and maintain automated workflows for security control testing, evidence collection, compliance monitoring, and audit readiness.
  • Develop and support policy-as-code, configuration checks, compliance dashboards, and repeatable validation methods to reduce manual assessment activities.
  • Perform technical risk assessments and gap analyses for new and existing technologies, systems, applications, cloud services, vendors, and business processes.
  • Partner with cybersecurity engineering, infrastructure, application, cloud, and networking teams to evaluate whether technical controls are implemented effectively and operating as intended.
  • Collaborate with IT and engineering teams to embed secure-by-design and data-by-default protection principles into applications, services, and infrastructure, while staying current on modern attack techniques and translating that knowledge into code and tooling.
  • Review operating systems, applications, cloud resources, network devices, security platforms, and third-party technologies against organizational policies, standards, and secure configuration baselines.
  • Correlate vulnerability findings, control gaps, compliance obligations, and business impact to support risk-based remediation prioritization.
  • Document control evidence, risk decisions, remediation plans, exceptions, and audit artifacts in a structured, accurate, and repeatable format.
  • Collaborate with internal stakeholders, external auditors, and compliance partners to support audits, assessments, regulatory inquiries, and control validation requests.
  • Develop metrics, reports, diagrams, and presentations that communicate cybersecurity risk, compliance posture, control effectiveness, and remediation status to technical and non-technical audiences.
  • Provide deep technical incident response support, including forensic analysis, custom scripting, and tool development during security investigations.
  • Performs other related duties as assigned.

Requirements

  • Technical curiosity
  • Sound judgment
  • Strong documentation skills
  • Ability to translate regulatory and framework requirements into actionable engineering outcomes

Skills

  • Cybersecurity
  • Governance, Risk, and Compliance (GRC)
  • Technical security operations
  • Security frameworks
  • Technical infrastructure
  • Security controls
  • Systems
  • Applications
  • Cloud platforms
  • Vendors
  • Enterprise technologies
  • Risk-based
  • Evidence-driven
  • Automation-enabled practices
  • Continuous compliance
  • Audit readiness
  • Risk assessments
  • Policy-as-code
  • Configuration checks
  • Compliance dashboards
  • Secure-by-design
  • Data-by-default
  • Modern attack techniques
  • Vulnerability findings
  • Control gaps
  • Remediation prioritization
  • Incident response
  • Forensic analysis
  • Custom scripting
  • Tool development
  • Security investigations

Work Type

  • Regular Full time

About the Company

  • HSS is consistently among the top-ranked hospitals for orthopedics and rheumatology by U.S. News & World Report.
  • As a recipient of the Magnet Award for Nursing Excellence, HSS was the first hospital in New York City to receive the distinguished designation.
  • Whether you are early in your career or an expert in your field, you will find HSS an innovative, supportive and inclusive environment.
  • Working with colleagues who love what they do and are deeply committed to our Mission, you too can be part of our transformation across the enterprise.

Equal Opportunity

  • Hospital for Special Surgery is committed to providing high quality care and skilled, compassionate, reliable service to our community in a safe and healing environment.
  • Consistent with this commitment, Hospital for Special Surgery provides care, admits, and treats patients and provides all services without regard to age, race, color, creed, ethnicity, religion, national origin, culture, language, physical or mental disability, socioeconomic status, veteran or military status, marital status, sex, sexual orientation, gender identity or expression, or any other basis prohibited by federal, state, or local law or by accreditation standards.