Jobs and Careers
OL

IT Security GRC Expert, Global

Olympus Corporation of the Americas
Center Valley, PA, US, 18034-0610, United Statesfull_timeVerifiedPosted 7 Apr 2026

About the role

Working Location: PENNSYLVANIA, CENTER VALLEY; MASSACHUSETTS, WESTBOROUGH 

Workplace Flexibility: Hybrid

 

For more than 100 years, Olympus has focused on making people’s lives healthier, safer and more fulfilling. ​

Every day, we live by our philosophy, True to Life, by advancing medical technologies and elevating the standard of patient care so people everywhere can fulfill their desires, dreams, and lives.

Our five Core Values empower us to achieve Our Purpose: 

Patient Focus, Integrity, Innovation, Impact and Empathy. 

 

Learn more about Life at Olympus: https://www.olympusamerica.com/careers.

Job Description

The Senior IT Security GRC Analyst (Global) is responsible for the governance, oversight, and lifecycle management of IT Security risk across Olympus. This role ensures that security-related risks, controls, and obligations are identified, assessed, governed, and transparently communicated in alignment with internal policy, external regulatory requirements, and recognized industry frameworks.

 

This position operates as a senior, globally consistent IT Security GRC role. While execution activities are distributed across regions, service providers, and technical teams, this role retains accountability for security risk governance, control framework alignment, exception management, and executive-level visibility.

 

The role functions as a leader by default, exercising judgment, influence, and authority without requiring formal people management, and serves as a trusted partner to IT, business, security operations, architecture, privacy, and assurance functions.

 

“The job is conducted in line with our Core Values which are: agility, empathy, long-term view, unity and integrity. Olympus is an equal opportunities employer championing a culture of equality, diversity and inclusion embedded throughout the organization and workforce.”

Job Duties

  • The Senior IT Security GRC Analyst (Global) is accountable for the following core responsibility areas. Responsibilities are global in scope, with execution assigned based on regional needs, maturity, and business priorities.
  • Establish, maintain, and operationalize IT Security governance structures aligned to Olympus policies and global standards.
  • Ensure security-related policies, standards, and procedures are consistently interpreted and applied across regions and systems.
  • Translate regulatory and framework requirements into actionable governance expectations for IT Security.
  • Own the end-to-end lifecycle of IT Security risk, including identification, assessment, prioritization, treatment tracking, escalation, and reporting.
  • Supports and escalates IT Security risk acceptance decisions in alignment with the enterprise risk management model and defined approval thresholds.
  • Maintain and govern the IT Security risk register within approved GRC tooling.
  • Evaluate security risks arising from systems, services, projects, third parties, and control gaps.
  • Ensure material security risks are communicated upward in a timely and disciplined manner.
  • Ensures material or unresolved IT Security risks are escalated and made visible in accordance with established governance processes.
  • This role owns IT Security risk. Enterprise-wide IT risk ownership and acceptance resides with IT Assurance.
  • Own governance of IT Security control frameworks (e.g., NIST, ISO), including control definition, mapping, and alignment to policy and regulatory requirements.
  • Monitor and assess control effectiveness using evidence, metrics, and tool outputs.
  • Validates security control effectiveness through evidence-based assessment methods aligned to recognized security frameworks.
  • Govern security-related exception management, including documentation, risk evaluation, treatment tracking, and reporting.
  • Partner with technical and operational teams responsible for control execution without assuming operational responsibility.
  • Conduct and govern IT Security risk assessments for third-party vendors and service providers.
  • Analyze security posture, identify control gaps, and recommend risk treatment options.
  • Track and report third-party security risks and remediation commitments.
  • Support secure procurement and onboarding processes through a security risk len

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Olympus Corporation of the Americas

View company profile →