About The Position

As a global medtech company, LivaNova is driven by its Vision of changing the trajectory of lives for a new day and its Mission to create ingenious solutions that ignite patient turnarounds. The Cyber Risk and Compliance Specialist will occupy a critical role that is 50% technical auditor and 50% security advocate. This role will ensure the integrity of financial systems through IT SOX compliance, mature the global compliance posture (HIPAA/NIS2), and build a high-integrity security culture through a comprehensive Security Awareness program.

Requirements

  • 5–7 years in IT Audit, IT Compliance, or Cyber Risk.
  • Expert-level understanding of SOX 404 (ITGCs).
  • Strong working knowledge of the HIPAA Security Rule and NIS2.
  • Proficiency in applying NIST 800-53, ISO 27001, NIST CSF, or COBIT.
  • The ability to explain to key stakeholders why a certain control is necessary without sounding like an auditor.
  • Experience with ERP systems, such as SAP (ECC/S4 HANA) etc.
  • Experience with cloud environments like Microsoft Azure, AWS etc.
  • Experience with GRC systems such as Auditboard, Workiva or other.

Nice To Haves

  • CISA is highly preferred
  • CISSP or CRISC is a major plus

Responsibilities

  • Lead the IT SOX program and design, implement, and test IT General Controls (ITGCs), IT Application controls (ITACs) and Key Reports (IPE) across enterprise applications, databases, and infrastructure.
  • Serve as the primary "translator" between technical teams and external auditors, ensuring evidence is accurate, timely, and defensible.
  • Lead the root-cause analysis for any control failures and partner with stakeholders to build long-term, remediation plans.
  • Act as the technical SME for the HIPAA Security Rule, ensuring controls protect PHI, including controls monitoring and providing guidance to management for new systems.
  • Lead the alignment of our security posture with the NIS2 Directive, focusing on key areas in the directive for our European operations.
  • Conduct deep-dive risk assessments for new technologies and vendors, ensuring compliance is baked in from the procurement stage.
  • Manage the security awareness program that goes beyond "check-the-box" training, creating engaging content for diverse audiences.
  • Translate dense Information Security Policies into digestible, actionable "good practices" for IT administrators and data owners.
  • Design targeted communication campaigns to increase internal reporting of security incidents and reinforce the importance of compliance.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service