Haystack
← Back to Jobs
Remote
Technology
FS

Cybersecurity GRC Senior Manager Research Compliance (No 3rd Party) - Remote East Coast

Fusion Solutions, Inc.United States🇺🇸United StatesPosted 26 Aug 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
Yesterday
GDPRHIPAA

Job Description

Cybersecurity GRC Senior Manager Research Compliance

Organization: Academic medical center / healthcare system

Location: REMOTE (resident of greater Philadelphia preferred, or PA, NJ, DE, MD)

Duration: Long-term right to hire (temp to perm FTE)

Position Summary

The Cybersecurity GRC Senior Manager leads cybersecurity compliance for research environments that process, store, or transmit sensitive information. This role is responsible for compliance assessments, control testing, audit readiness, remediation, and adherence to applicable cybersecurity and regulatory frameworks.

Key Responsibilities

  • Lead cybersecurity compliance activities for research environments, with primary focus on NIST SP 800-171, NIST SP 800-53, FISMA, HIPAA, and requirements governing Controlled Unclassified Information (CUI).
  • Establish and manage compliance assessment methodologies, including control testing, assessment planning, scoping, reporting, quality assurance, and continuous monitoring.
  • Lead internal audits, external assessments, and regulatory examinations and serve as the primary cybersecurity compliance contact for auditors and stakeholders.
  • Identify, prioritize, document, and track remediation of compliance gaps and control deficiencies.
  • Maintain compliance documentation and artifacts, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), control documentation, assessment records, and regulatory evidence.
  • Serve as the subject matter expert for NIST SP 800-171 and related cybersecurity frameworks, providing guidance on control implementation and compliance.
  • Develop compliance metrics, risk indicators, dashboards, and reporting to track compliance posture, remediation progress, and emerging risks.
  • Lead and mentor compliance analysts and other compliance resources.

Required Qualifications

  • Bachelor s degree.
  • 6+ years of IT and cybersecurity experience.
  • 3+ years of experience auditing, assessing, and/or ensuring compliance with published cybersecurity frameworks.
  • Strong understanding of cybersecurity principles, risk management, and cybersecurity controls.
  • Expert knowledge of NIST SP 800-171 as applied to scientific research.
  • Experience working in matrixed environments and building cross-functional relationships.
  • Ability to manage multiple concurrent workstreams.
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts to non-technical audiences.

Preferred Qualifications

  • Experience performing control assessments, evidence reviews, and remediation tracking in regulated environments.
  • Information security certification such as CISSP, CGRC, CISM, or CISA.
  • Knowledge of HIPAA, FERPA, PCI-DSS, SOX, GDPR, or other regulatory frameworks.
  • Knowledge of Compliance Forge Secure Controls Framework.

Similar jobs