GRC IT Audit & Readiness Specialist

Henry Ford HealthTroy, MI

About The Position

The Governance, Risk, and Compliance (GRC) Information Technology (IT) Audit and Readiness Specialist facilitates and supports IT audits and compliance assessments for Henry Ford Health and its subsidiaries. Reporting to the IT Security Compliance Manager within Cybersecurity Governance, Risk, and Compliance (CGRC), the Specialist collaborates with Information Privacy and Security Office (IPSO) and IT team members to coordinate SOC 1, SOC 2, General IT Controls, and other assessments. The Specialist applies technical and operational knowledge of information security, auditing, risk management, and applicable legal and regulatory requirements affecting enterprise privacy, security, and risk.

Requirements

  • Bachelor’s degree in Accounting, Information Systems, Computer Science or related field preferred, relevant work experience/certification considered.
  • Two plus (2+) years of experience in IT risk, IT Controls or IT Audit.
  • Demonstrates strong and effective verbal, written, and interpersonal communication skills, with experience in all at the executive level.
  • Ability to prioritize and multi-task in a dynamic, fast-paced, and challenging environment.
  • Experience with federal and state healthcare information regulations and requirements (e.g., HIPAA) preferred.
  • Advanced knowledge of IT systems and functions, process development, change management, and service and implementation lifecycle.
  • Knowledge of information security best practices, NIST Cybersecurity Framework , and common risk frameworks.
  • Can conform to shifting priorities, demands, and timelines through analytical and problem-solving capabilities.

Nice To Haves

  • CISSP, CISA, CISM preferred.

Responsibilities

  • Develop work with minimal supervision, maintain and report against a work plan, give appropriate updates and status reports, and serve as a point of contact and liaison with internal and external auditors, assessors, vendors, and clients and assist other staff members.
  • Provide Governance Risk and Compliance (GRC) support for third-party audit requests and reporting requests from leadership.
  • Coordinate and facilitate IT audits (internal and external), acting as the central point of contact between auditors and internal stakeholders.
  • Collect, review, and organize audit evidence to ensure accuracy, completeness, and timely delivery.
  • Partner with control owners to support audit readiness, including guidance on documentation, control execution, and remediation efforts.
  • Track audit requests, milestones, and deliverables to ensure deadlines are met and risks are escalated as needed.
  • Utilize GRC tools to manage audit workflows, extract evidence, and monitor control performance and compliance status.
  • Communicate audit requirements, follow-ups, and status updates clearly to internal teams and external auditors.
  • Run reports from the GRC tool to provide third-party audit requests and related reporting.
  • Develop and maintain relationships with key stakeholders across IPSO, IT, and business teams.
  • Execute GRC tool system test plans as necessary (ex. For system upgrades, updates, enhancements, new reporting).
  • Participate in continuous learning initiatives specifically related to the GRC system, IT governance, controls, insurance, healthcare, leading security frameworks, and information technology.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service