Dir., Cybersecurity Governance, Risk, and Compliance
Tandem Diabetes CareAbout the role
GROW WITH US:
Tandem Diabetes Care creates new possibilities for people living with diabetes, their loved ones, and their healthcare providers through a positively different experience. We’d love for you to team up with us to “innovate every day,” put “people first,” and take the “no-shortcuts” approach that has propelled us to become a leader in the diabetes technology industry.
STAY AWESOME:
Tandem Diabetes Care is proud to manufacture and sell the Tandem Mobi system and t:slim X2 insulin pump with Control -IQ technology — an advanced predictive algorithm that automates insulin delivery. But we’re so much more than that. Our company’s human-centered approach to design, development, and support delivers innovative products and services for people who use insulin. Because many of our own team members live with type 1 diabetes, or have a loved one impacted by diabetes, the work is personal, and we are committed to the cause. Learn more at https://www.tandemdiabetes.com/
A DAY IN THE LIFE:
The Director, Cybersecurity Governance, Risk, and Compliance (GRC) is a leadership role within the cybersecurity organization, responsible for establishing and maintaining the enterprise cybersecurity GRC program. This role ensures that the organization's cybersecurity practices are aligned with business objectives, compliant with applicable laws and regulations, and resilient against evolving cyber threats. The Director will lead a team of GRC professionals and collaborate closely with stakeholders across the organization to develop, implement, and monitor cybersecurity policies, standards, and procedures. This role is also responsible for the enterprise cybersecurity risk management program, cybersecurity awareness and training programs, and driving the organization towards achieving relevant cybersecurity certifications.
YOU’RE AWESOME AT:
- Develop, implement, and oversee the enterprise cybersecurity GRC strategy and roadmap, aligning it with the overall business strategy and risk appetite.
- Establish and maintain a comprehensive cybersecurity governance framework, including policies, standards, procedures, and guidelines, ensuring they are communicated effectively across the organization.
- Lead the development and execution of the enterprise cybersecurity risk management program, including risk identification, assessment, mitigation, monitoring, and reporting. Identify and manage information security risks through comprehensive risk assessment methodologies, industry frameworks, and compliance requirements.
- Implement risk mitigation strategies and controls, collaborating with relevant teams to ensure effective risk reduction.
- Ensure compliance with relevant internal cybersecurity policies and external laws, regulations, and industry standards applicable to medical device manufacturers, such as FDA cybersecurity guidance, HIPAA, GDPR, ISO 27001, NIST Cybersecurity Framework, and others as required.
- Oversee internal and external cybersecurity audits and assessments, manage remediation efforts, and report on compliance status to executive leadership.
- Lead the development and management of the cybersecurity third-party risk management program.
- Develop and deliver a comprehensive cybersecurity awareness and training program to educate employees on cybersecurity risks, policies, and best practices.
- Lead the organization's efforts to achieve and maintain relevant cybersecurity certifications, such as ISO 27001, HITRUST, or SOC 2.
- Provide GRC expertise and support during cybersecurity incident response activities.
EXTRA AWESOME:
- Bachelor's degree (Master's preferred) in Cybersecurity, Information Technology, Computer Science, or a related field.
- Professional certifications, such as CISSP, CISM, CISA, CRISC, or equivalent.
- Additional relevant certifications (e.g., ISO 27001 Lead Auditor, HITRUST CCSFP).
- 10+ years of experience in cybersecurity, with at least 5+ years in a GRC leadership role.
- Experience in the medical device or healthcare industry is highly desirable.
- Experience with GRC tools and technologies.
- Experience presenting to executive leadership and boards of directors.
- Knowledge of medical device security and regulatory requirements.
- Deep understanding of cybersecurity GRC principles, frameworks, and best practices.
- Strong knowledge of relevant laws, regulations, and industry standards (e.g., FDA cybersecurity guidance, HIPAA, GDPR, ISO 27001, NIST Cybersecurity Framework).
- Proven experience in developing and implementing cybersecurity policies, standards, and procedures.
- Expertise in cybersecurity
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s