Cybersecurity Governance, Risk, & Compliance Manager

Erlanger Health SystemChattanooga, TN
Hybrid

About The Position

This individual will report to the Chief Information Security Officer. The Cybersecurity Governance, Risk, & Compliance (GRC) Manager designs, implements, and maintains Erlanger Health System's cybersecurity policy framework, compliance programs, and governance processes to ensure alignment with NIST CSF 2.0 Govern function and healthcare regulations including HIPAA Security Rule, as well as emerging standards for AI security (e.g., NIST AI RMF), post-quantum cryptography, and cloud security frameworks (e.g., CSA CCM). This role addresses risks from evolving technologies such as AI-integrated systems, quantum computing, and cloud-based infrastructures while prioritizing regulatory compliance and organizational resilience. Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF, plus familiarity with NIST AI Risk Management Framework (RMF), post-quantum cryptography standards (e.g., NIST PQC), and cloud security frameworks (e.g., AWS Well-Architected Security, Azure Security Center, or CSA STAR). Demonstrated ability to communicate complex compliance and risk concepts, including those from AI, quantum, and cloud domains, to both technical and non-technical audiences. Ability to work in dynamic environments, including occasional after-hours support for compliance-related incidents or audits.

Requirements

  • Bachelor's degree in information security, Compliance, or a related field.
  • 7+ years of experience in cybersecurity governance and compliance.
  • Exposure to AI-integrated compliance, quantum security concepts, or cloud-based governance.
  • Expert knowledge of NIST CSF 2.0, HIPAA Security Rule, and HITRUST CSF.
  • Familiarity with NIST AI Risk Management Framework (RMF).
  • Familiarity with post-quantum cryptography standards (e.g., NIST PQC).
  • Familiarity with cloud security frameworks (e.g., AWS Well-Architected Security, Azure Security Center, or CSA STAR).
  • Demonstrated ability to communicate complex compliance and risk concepts to both technical and non-technical audiences.
  • Ability to work in dynamic environments.
  • Ability to provide occasional after-hours support for compliance-related incidents or audits.

Nice To Haves

  • Master's degree preferred, with coursework or emphasis on AI, quantum computing, or cloud technologies.

Responsibilities

  • Designs, implements, and maintains Erlanger Health System's cybersecurity policy framework.
  • Designs, implements, and maintains compliance programs.
  • Designs, implements, and maintains governance processes.
  • Ensures alignment with NIST CSF 2.0 Govern function and healthcare regulations including HIPAA Security Rule.
  • Ensures alignment with emerging standards for AI security (e.g., NIST AI RMF), post-quantum cryptography, and cloud security frameworks (e.g., CSA CCM).
  • Addresses risks from evolving technologies such as AI-integrated systems, quantum computing, and cloud-based infrastructures.
  • Prioritizes regulatory compliance and organizational resilience.
  • Communicates complex compliance and risk concepts, including those from AI, quantum, and cloud domains, to both technical and non-technical audiences.
  • Provides occasional after-hours support for compliance-related incidents or audits.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service