Governance, Risk, and Compliance Lead
University of ChicagoAbout the role
Department
About the Department
Job Summary
Globus capabilities are offered for use with protected data and adhere to NIST 800-53 controls and the HIPAA Security Rule. In your capacity, you'll oversee the compliance program to uphold these standards, crafting and leading initiatives aimed at enhancing operational efficiency as we expand. Your focus will be on ensuring that we consistently meet our customers' compliance requirements while scaling our operations effectively. As the resident expert within the team, you'll manage security assessments, monitoring compliance status, providing procedural guidance, implementing security controls, and driving process improvement and maturity initiatives.
Beyond sustaining our current compliance framework, your role will involve leveraging your expertise and insights into the Globus customer base to advocate for and implement additional compliance standards in response to customer demand and market trends. This will entail conducting thorough gap analyses and collaborating with third-party vendors as necessary.
If you thrive in collaborative, innovative, mission-oriented environments, consider joining Globus where your skills and passion for compliance can make a meaningful impact on research worldwide!
Responsibilities
Leads implementation and maintenance of NIST risk management framework and 800-53 controls to manage security and privacy risks for the Unit.
Develops compliance strategy, and leads and executes various tasks based on those strategies, including development and maintenance of policies and procedures, system security plan, plans of actions and milestones.
Reviews technical procedures developed by the operations team, and ensure compliance with policies.
Supports the operations team in managing security incidents, generating reports, and serving as the primary liaison for communication with both internal and external stakeholders, in adherence to established policies.
Serves as compliance lead on internal and external assessments and audits.
Assists customers with security risk assessment of Globus products, and owns all customer communication on security and compliance.
Collaborates with the procurement team to review contract terms and data protection agreements pertaining to product and operational security. Ensures that contractual obligations are in line with the current operational standards of Globus.
Serves as a mentor to staff providing compliance and security consulting and awareness efforts, including engaging with the product team to analyze security of applications to provide risk recommendations.
Uses a deep understanding of IT expertise to develop and implement security and compliance policies, guidelines, and safe practices for the unit.
Leads teams to conduct in-depth information technology risk assessments; makes recommendations and designs improvements to IT security procedures.
Performs other related work as needed.
Minimum Qualifications
Education:
Minimum requirements include a college or university degree in related field.---
Work Experience:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s