Governance, Risk, and Compliance (GRC) Specialist at DeepHealth | Amsterdam, North Holland, NL | Rezi

Governance, Risk, and Compliance (GRC) Specialist at DeepHealth

Governance, Risk, and Compliance (GRC) Specialist

DeepHealth · Amsterdam, North Holland, NL

1 months ago

Governance, Risk, and Compliance (GRC) Specialist

DeepHealth · Amsterdam, North Holland, NL

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Governance, Risk, and Compliance (GRC) Specialist role.

Rezi rewrites your resume against DeepHealth's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Governance, Risk, and Compliance (GRC) Specialist posting at DeepHealth — free, in seconds.

About the Role

The Governance, Risk, and Compliance (GRC) Specialist is a strategic role within DeepHealth’s Quality, Regulatory, and Compliance department, responsible for assisting in the development, implementation, and maintenance of comprehensive information security compliance strategies. This position is critical in protecting organizational data, ensuring regulatory adherence, and mitigating potential security risks in the complex digital health landscape.

Responsibilities

  • Develop and implement holistic security compliance programs
  • Use Vanta to manage existing security certifications and requirements
  • Manage comprehensive risk management frameworks
  • Design and maintain security policies, procedures, and guidelines
  • Continuously assess and update security strategies
  • Ensure alignment with organizational objectives and regulatory requirements
  • Ensure compliance with complex regulatory standards and certifications including, but not limited to: HIPAA, SOC 2, ISO 27001, C5, DSP Toolkit, Cyber Essentials, HITRUST
  • Conduct thorough risk assessments and vulnerability evaluations
  • Prepare detailed compliance reports and documentation
  • Support external and internal audit processes
  • Track and implement regulatory changes
  • Perform comprehensive security vulnerability assessment
  • Develop and implement security control frameworks
  • Monitor and analyze security incidents and breaches
  • Design and conduct security awareness training programs
  • Manage access control and identity management systems
  • Evaluate and recommend security technologies and solutions
  • Develop and maintain incident response plans
  • Coordinate rapid and effective responses to security incidents
  • Conduct pos-incident analysis and implement preventive measures
  • Maintain detailed incident documentation and reporting
  • Work closely with IT, Legal, Compliance, and Clinical teams
  • Provide security guidance and recommendations to maintain the Security by Design concept
  • Facilitate cross-functional security awareness and training
  • Support technology implementation and security best practices

Requirements

  • Bachelor’s degree in Cybersecurity, Information Security, Computer Science or related field (or equivalent experience)
  • Master’s degree or advanced security certifications preferred, such as: CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CRISC (Certified in Risk and Information Systems Control)
  • 3-5 years of progressive experience in security compliance with healthcare, medical technology, or highly regulated industries
  • Proven track record of developing and implementing security strategies
  • Experience with regulatory compliance in complex environments
  • An advanced understanding of security frameworks and compliance standards
  • Proficiency in security tools and technologies
  • Experience with risk assessment and management tools
  • Excellent written and oral communication and interpersonal skills with the ability to explain complex security concepts to diverse audiences, including upper management
  • High level of integrity and confidentiality
  • Must be able to lift up to 10 pounds occasionally
  • Ability to travel (~10% of time), drive a vehicle, and utilize other forms of transportation

Skills

  • HIPAA
  • SOC 2
  • ISO 27001
  • C5
  • DSP Toolkit
  • Cyber Essentials
  • HITRUST
  • Vanta
  • CISSP
  • CISM
  • CRISC

Location

  • European Union
  • Remote

Work Type

  • Office setting
  • Remote

Experience Level

  • 3-5 years

Education Level

  • Bachelor’s degree
  • Master’s degree preferred
  • Advanced security certifications preferred

Salary/Compensations

  • €65,000 - €75,000 EUR Annually
  • £55,000 - £65,000 GBP Annually

Equal Opportunity

  • Reasonable accommodations may be made to enable people with disabilities to perform the essential functions of the job.