×
Register Here to Apply for Jobs or Post Jobs. X

Cybersecurity GRC Manager, FCH - IT - Security

Job in Appleton, Outagamie County, Wisconsin, 54911, USA
Listing for: Froedtert Health
Full Time position
Listed on 2026-05-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: Cybersecurity GRC Manager, FCH - IT - SECURITY

#Be Here

Location: US:

WI:

MENOMONEE FALLS at our WOODLAND PRIME 400 facility. This job is remote.

FTE: 1.000000 | Standard

Hours:

40.00

Shift: Flexible 1st shift between 7 am and 5 pm

Job Summary

Healthcare security isn’t a compliance checkbox problem — it’s a patient safety problem. At Froedtert Theda Care, the Cybersecurity GRC Manager owns the program that connects our governance posture to real‑world risk outcomes for patients, clinicians, and the communities we serve across Wisconsin. This is a high‑visibility, high‑autonomy leadership role inside a Cybersecurity & Infrastructure team that operates with strategic intent and operational rigor.

You will build and run a team of 5+ GRC professionals, serve as the internal subject matter authority on compliance and risk, and translate complex regulatory requirements into actionable programs that the broader organization can execute against.

People Leadership
  • Lead, mentor, and grow a team of 5+ GRC analysts and specialists across compliance, risk, policy, and awareness domains
  • Establish clear role expectations, development pathways, and performance standards for each team member
  • Foster a team culture that balances rigor with pragmatism — we care about outcomes, not just documentation
HIPAA & Healthcare Compliance
  • Serve as the organization’s functional lead for HIPAA Privacy and Security Rule compliance, including ongoing gap assessment and remediation tracking
  • Coordinate with Legal, Privacy, and Clinical Operations to ensure compliance obligations are understood and operationalized across the enterprise
  • Oversee preparation for and response to regulatory inquiries, OCR investigations, and audit activity
Risk Management & Third‑Party Risk
  • Own the enterprise cybersecurity risk register, ensuring risks are identified, assessed, prioritized, and tracked to resolution
  • Lead the third‑party risk management program, including vendor onboarding assessments, ongoing monitoring, and risk‑tiering across the supply chain
  • Develop risk reporting for executive and board audiences, translating technical risk into business impact language
Policy & Controls Frameworks
  • Own the cybersecurity policy lifecycle: authorship, review cadence, version control, approval workflows, and exception management
  • Maintain alignment to NIST CSF, managing control mapping, evidence collection, and control effectiveness measurement
  • Drive continuous improvement of the controls environment based on assessment findings, threat intelligence inputs, and regulatory changes
Audit & Assessment Management
  • Serve as the primary point of contact and program lead for internal and external cybersecurity audits and assessments
  • Coordinate evidence collection, manage stakeholder readiness, and oversee finding remediation tracking through to closure
  • Develop and maintain audit‑ready documentation across all GRC domains
Security Awareness & Phishing Simulation
  • Own the enterprise security awareness program, including curriculum development, delivery scheduling, and effectiveness measurement
  • Manage the phishing simulation program end‑to‑end: scenario design, cadence, metrics, and targeted follow‑up training for at‑risk populations
  • Tailor awareness content for diverse audiences — from clinical staff to executive leadership — with a voice that educates rather than shames
Experience
  • A minimum of six‑year experience in a related field
  • Prefer 3+ years leading or managing a team in GRC, compliance, or risk management capacity
  • Prefer experience in a healthcare or other highly regulated industry, with direct exposure to HIPAA compliance obligations
  • Demonstrated experience managing a third‑party risk program, including vendor assessments and risk tiering
  • Prefer prior experience building or significantly maturing a GRC program, not just maintaining one
  • Prefer experience managing external audits or assessments (SOC 2, HITRUST, OCR, internal audit, etc.)
Education

Required:

A Bachelor’s degree. Preferred:
Bachelor’s in Computer Science or a related field.

Special Skills
  • In‑depth knowledge of cybersecurity frameworks including but not limited to NIST CSF, HITRUST CSF, ISO 27001
  • Experience in managing or leading security organizations responsible for GRC,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary