Position Details
About this role
Global healthcare vendor seeks a Cyber Risk and Compliance Specialist to own IT SOX/ITGCs, HIPAA/NIS2 alignment, and security-awareness programs. The role balances technical auditing with risk advisory and policy promotion across enterprise applications, cloud environments, and governance programs.
Key Responsibilities
- Lead IT SOX program and test ITGCs/ITACs/IPE
- Translate between technical teams and auditors
- Deficiency root-cause analyses and remediation planning
- HIPAA/NIS2 risk advisory and procurement risk assessments
- Security Awareness program development and policy translation
Technical Overview
Hands-on experience with ITGCs/ITACs, HIPAA Security Rule, NIS2, and frameworks (NIST 800-53, ISO 27001, NIST CSF, COBIT). Familiarity with SAP ECC/S4 HANA, Azure, AWS, and GRC tools (Auditboard, Workiva). Requires strong communication with stakeholders and external auditors.
Ideal Candidate
The ideal candidate is a mid-to-senior cyber risk and compliance professional with 5-7 years of IT audit/compliance experience. They excel at IT SOX, HIPAA, and NIS2, and can translate technical controls into business terms while driving a multinational compliance program and security-awareness culture.
Must-Have Skills
Nice-to-Have Skills
Tools & Platforms
Required Skills
Hard Skills
Soft Skills
Certifications
Preferred
Industry & Role
Keywords for Your Resume
Deal Breakers
Must have 5–7 years IT Audit / IT Compliance / Cyber Risk, Experience with SAP ECC/S4 HANA, Proficiency with AWS/Azure, CISA/CISSP/CRISC preferred
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile