Security Engineer-Governance, Risk & Compliance
Listed on 2026-08-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Security Engineer-Governance, Risk & ComplianceFull Time AZ Phoenix, Glendale, AZ, US
6 days ago Requisition
Salary Range: $ To $ Annually
COMPANY DESCRIPTIONAt Air Life, we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line, but the way we work and take care of our customers. With a mindset to evolve, innovate, and grow, we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach, impacting even more people around the world.
Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care, with safety, patient comfort, and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients, customers, and our people. Our values of Customer first, Differentiate with our People, Bias for Action, Continuous Improvement and Accountability define who we are and how we work.
Join us!
The Security Engineer – Governance, Risk & Compliance is responsible for establishing and maturing Air Life's information security risk management and compliance posture. This role evaluates, quantifies, and helps mitigate security risks across IT infrastructure and business systems, while ensuring Air Life's cybersecurity practices remain aligned to applicable regulatory frameworks, industry standards, and internal policies. Operating in a medical device manufacturing environment with FDA and ISO regulatory obligations and a PE ownership structure with specific cybersecurity reporting requirements, this role brings both technical security knowledge and a compliance mindset to a rapidly maturing IT security program.
The Security Engineer – GRC plays a critical role in Air Life's ability to satisfy external auditors, insurance underwriters, and PE sponsor security benchmarking requirements.
- Strong working knowledge of security risk management frameworks and methodologies, including NIST CSF, NIST SP 800-30/37, ISO 27001, and CIS Controls.
- Understanding of regulatory compliance requirements relevant to medical device manufacturing, including FDA 21 CFR Part 820 / QMSR and ISO 13485, and their implications for IT General Controls (ITGC) and computer system validation.
- Experience with IT General Controls frameworks and audit support, including SOX-adjacent controls applicable to PE-backed manufacturing companies.
- Knowledge of data privacy regulations, including GDPR and applicable US state privacy laws, and their operational IT implications.
- Experience conducting risk assessments, gap analyses, and security control reviews; ability to document, prioritize, and track findings through to remediation.
- Experience developing and maintaining security policies, standards, procedures, and control evidence libraries.
- Familiarity with vulnerability management programs, including scanning tooling, remediation tracking, and risk-based prioritization.
- Experience administering security awareness training programs, including phishing simulation and completion tracking (KnowBe4 experience preferred).
- Ability to work with MDR/MSSP providers to ensure managed detection capabilities align with Air Life's compliance posture (Arctic Wolf experience a plus).
- Strong written communication skills; ability to clearly document findings, prepare audit evidence packages, and present risk posture to non-technical audiences including executives and external auditors.
- Proficiency with project and task management tools;
Smartsheet experience preferred. - Industry-recognized GRC or cybersecurity certification(s) preferred (CISA, CRISC, CompTIA Security+, SSCP, or equivalent).
Experience:
Minimum 4–6 years of IT experience with 3+ years in a cybersecurity role with a GRC, compliance, or risk management focus. Experience in a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).