Franciscan Health is a leading healthcare organization dedicated to providing exceptional patient care and promoting health and wellness in our community. Our mission is to ensure that every patient receives the highest quality of care through innovation, compassion, and excellence. With 12 ministries and access points across Indiana and Illinois, Franciscan Health is one of the largest Catholic health care systems in the Midwest. Franciscan Health takes pride in hiring coworkers who provide compassionate, comprehensive care for our patients and the communities we serve.
Director Cyber Security GRC, Resiliency, Data Privacy
Location
United States
Posted
3 days ago
Salary
$212K - $267K / year
No structured requirement data.
Job Description
The Director Cyber Resiliency, GRC & Data Privacy provides strategic leadership, executive-level reporting, and cross-functional coordination to ensure security programs are risk-informed, audit-ready, and aligned with business objectives. In this role you will establish and sustain a unified security governance and resiliency framework that ensures regulatory compliance, operational resilience, and protection of sensitive data across the organization.
WHO WE ARE
Franciscan Health is a leading healthcare organization dedicated to providing exceptional patient care and promoting health and wellness in our community. Our mission is to ensure that every patient receives the highest quality of care through innovation, compassion, and excellence. With 12 ministries and access points across Indiana and Illinois, Franciscan Health is one of the largest Catholic health care systems in the Midwest. Franciscan Health takes pride in hiring coworkers who provide compassionate, comprehensive care for our patients and the communities we serve.
WHAT YOU CAN EXPECT
Establish and lead the GRC strategy aligned with organizational risk tolerance and regulatory obligations.
Own and maintain the information security governance framework, including policies, standards, procedures, and exception management.
Oversee enterprise risk assessments, risk registers, risk treatment plans, and executive risk reporting.
Own the enterprise Business Continuity Management (BCM) and Disaster Recovery (DR) programs.
Lead and develop managers and teams across GRC, security program management, BC/DR, and privacy functions.
Build strong partnerships with Legal, Compliance, Risk Management, Internal Audit, IT, and business leaders.
QUALIFICATIONS
Bachelor's Degree Information Security, Information Systems, MBA, or other related field - Required -OR-
10 years experience in lieu of degree - Required
8 years progressive experience in information security, risk management, compliance, privacy, or resiliency roles Required
Licensure - . CISSP, CISM, CISA, CRISC, CBCP, or equivalent industry certifications obtain within 180 days - Required
TRAVEL IS REQUIRED:
EQUAL OPPORTUNITY EMPLOYER
It is the policy of Franciscan Alliance to provide equal employment to its employees and qualified applicants for employment as otherwise required by an applicable local, state or Federal law.
Franciscan Alliance reserves a Right of Conscience objection in the event local, state or Federal ordinances that violate its values and the free exercise of its religious rights.
Franciscan Alliance is committed to equal employment opportunity.
Franciscan provides eligible employees with comprehensive benefit offerings. Find an overview on the benefit section of our career site, jobs.franciscanhealth.org.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Security Engineer
AbnormalAbnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law.
This role focuses on security operations engineering within a FedRAMP environment, requiring the engineer to maintain and improve technical workflows related to CI/CD, access management, patching, and change reviews. The engineer will also be responsible for triaging security incidents and refining operational documentation to ensure compliance and resilience at scale.
The engineer will be hands-on building core endpoint privilege capabilities, focusing on agent behavior, policy enforcement, elevation workflows, auditing, and integrations for enterprise and MSP environments. Responsibilities include designing, building, and maintaining these capabilities while hardening agent components and implementing platform integrations.
The role involves owning features across the full stack, from initial detection requirements through production, spanning browser extension code, backend services for event ingestion and alerting, and data pipelines. Responsibilities include writing content scripts to interact with web pages, building backend services, and collaborating with security researchers to implement threat intelligence into working detections.
The Red Team Researcher will be responsible for identifying and exploiting vulnerabilities across Ford's applications, cloud implementations, APIs, infrastructure, and in-vehicle systems to enhance the overall security posture. This involves collaborating through all phases of an engagement, from initial identification and access to establishing persistence and consulting on remediation.