Governance, Risk, and Compliance (GRC) Specialist

Listed via Recruitee
Posted Aug 10, 2026 · Apply by Oct 10
Recently checked

Last checked active on Aug 11, 2026.

Position Overview

Compensation: Not disclosed
Position: Mid
Type: Job
Employment: Full time
Practice Area: Compliance
Remote: Yes
Deadline: Oct 10, 2026

Job Description

The Governance, Risk, and Compliance (GRC) Specialist is a strategic role within DeepHealth’s Quality, Regulatory, and Compliance department, responsible for assisting in the development, implementation, and maintenance of comprehensive information security compliance strategies.  This position is critical in protecting organizational data, ensuring regulatory adherence, and mitigating potential security risks in the complex digital health landscape.

Requirements

Duties and Responsibilities 

As the Governance, Risk, and Compliance Specialist, this position will work with Information Security, IT Operations, Sec Operations and the broader Compliance team to:

A successful GRC Specialist will:

·        Develop and implement holistic security compliance programs

·        Use Vanta to manage existing security certifications and requirements

·        Manage comprehensive risk management frameworks

·        Design and maintain security policies, procedures, and guidelines

·        Continuously assess and update security strategies

·        Ensure alignment with organizational objectives and regulatory requirements

Regulatory Compliance:

·        Ensure compliance with complex regulatory standards and certifications including, but not limited to:

  • HIPAA

  • SOC 2

  • ISO 27001

  • C5

  • DSP Toolkit

  • Cyber Essentials

  • HITRUST

·        Conduct thorough risk assessments and vulnerability evaluations

·        Prepare detailed compliance reports and documentation

·        Support external and internal audit processes

·        Track and implement regulatory changes

Technical Security:

·        Perform comprehensive security vulnerability assessment

·        Develop and implement security control frameworks

·        Monitor and analyze security incidents and breaches

·        Design and conduct security awareness training programs

·        Manage access control and identity management systems

·        Evaluate and recommend security technologies and solutions

Incident Response and Management:

·        Develop and maintain incident response plans

·        Coordinate rapid and effective responses to security incidents

·        Conduct pos-incident analysis and implement preventive measures

·        Maintain detailed incident documentation and reporting

Interdepartmental Collaboration:

·        Work closely with IT, Legal, Compliance, and Clinical teams

·        Provide security guidance and recommendations to maintain the Security by Design concept

·        Facilitate cross-functional security awareness and training

·        Support technology implementation and security best practices

 

Please Note: This is not an exhaustive list of all duties, responsibilities and requirements of the position described above.  Other functions may be assigned, and management retains the right to add or change duties at any time.

Qualifications

Qualifications include:

● Bachelor’s degree in Cybersecurity, Information Security, Computer Science or related field (or equivalent experience). Master’s degree or advanced security certifications preferred, such as:

  • CISSP (Certified Information Systems Security Professional)

  • CISM (Certified Information Security Manager)

  • CRISC (Certified in Risk and Information Systems Control)

● 3-5 years of progressive experience in security compliance with healthcare, medical technology, or highly regulated industries

● Proven track record of developing and implementing security strategies

● Experience with regulatory compliance in complex environments, including:

  • An advanced understanding of security frameworks and compliance standards

  • Proficiency in security tools and technologies

  • Experience with risk assessment and management tools

● Excellent written and oral communication and interpersonal skills with the ability to explain complex security concepts to diverse audiences, including upper management.

● High level of integrity and confidentiality

4. Working conditions

This position may be based in the European Union in a typical office setting.

This position will have the ability to work remotely.

5. Physical requirements

This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally. The position requires the ability to travel (~10% of time), drive a vehicle, and utilize other forms of transportation

ACCOMMODATIONS
Reasonable accommodations may be made to enable people with disabilities to perform the essential functions of the job.

Salary Range:

€65,000 - €75,000 EUR Annually

£55,000 - £65,000 GBP Annually

Practice Area

Position

Mid

Applicant Location Requirements

Applicants must be located in: Netherlands

Application Deadline

October 10, 2026

Employment Type

Full time

Work Arrangement

Remote/Telecommute Position

Members-only application to DeepHealth

Unlock this application

See the complete description, requirements, and every detail of this role, then apply with unlimited human CV reviews from a real specialist.

Apply to this job and future roles across 93 countries
Get unlimited CV / resume reviews from real human experts
Get added to a private, members-only group for legal professionals
Carry verified member status across LegalAlphabet
Return to this job immediately after checkout
Report this job
Thank you. Our team will review this report.

Tell us if this listing is inaccurate, closed, fake, duplicated, or unsafe. You do not need an account to report it.