Demo

Cybersecurity GRC Lead

Trident Consulting
Burlington, MA Full Time
POSTED ON 4/29/2026
AVAILABLE BEFORE 5/27/2026

Trident Consulting is seeking a " Cybersecurity GRC Lead" for one of our clients, an ophthalmic medical technology and pharmaceutical company.


Role: Cybersecurity GRC Lead

Location: Burlington, MA (hybrid - M-W-F (and possibly come in on Tues or Thursday if there is something pressing)

Type: Fulltime

Base Salary: $118,500 – $148,100 10% bonus


The Cybersecurity GRC Lead – Medical Devices (Continuous Control Monitoring Lead) is responsible for overseeing and coordinating cybersecurity governance, risk, and compliance (GRC) activities supporting medical devices produced and supported internationally. This role ensures that cybersecurity “run-the-business” controls and evidence-producing activities—such as access reviews, vulnerability scanning cadence, patch tracking, SBOM governance, and audit readiness—are properly planned, executed by the appropriate teams, and documented.


This is a coordination, governance, and assurance role rather than a hands-on technical execution role. The position partners closely with Engineering/R&D, Quality, Regulatory Affairs, IT, and Information Security to maintain compliance with applicable standards and regulatory guidance and to ensure customer and regulatory cybersecurity requirements are tracked through completion.


Governance & Program Oversight

• Own and maintain the medical device cybersecurity GRC plan, calendar, and control schedule (monthly, quarterly, and annual activities).

• Ensure cybersecurity roles, responsibilities, RACIs, and escalation paths are defined and functioning across IT, Engineering, and Quality teams.

• Maintain governance documentation, including policies, procedures, standards, control narratives, and work instructions related to medical device cybersecurity.

• Provide regular program status reporting (KPIs/KRIs, control execution status, risk posture, overdue actions) to the CISO and other stakeholders.


Risk Management & Requirements Tracking

  • Track cybersecurity requirements from customers, internal stakeholders, and applicable standards and guidance (e.g., FDA expectations, IEC 62304/62443 concepts, NIST-aligned controls) through implementation and evidence completion.
  • Coordinate cybersecurity risk assessments and ensure resulting remediation actions are assigned, tracked, and closed by accountable owners (Engineering, IT, suppliers, etc.).
  • Maintain the cybersecurity risk register for medical device–related risks impacting products, manufacturing/operations, and supporting systems.


Cross-Functional Coordination & Audit / Inspection Readiness

  • Serve as the central coordination point between Sales, Engineering, Quality, Regulatory Affairs, IT, and Information Security for cybersecurity compliance deliverables.
  • Coordinate with Quality and Regulatory Affairs to ensure pre-sale cybersecurity responses meet regulatory and compliance expectations.
  • Escalate and track gaps or risks identified during the pre-sale process to appropriate internal stakeholders.
  • Support Quality and Regulatory teams with audit and inspection readiness by ensuring cybersecurity artifacts are current, approved, and readily retrievable (e.g., threat models, vulnerability management evidence, access review records).
  • Drive continuous improvement of GRC processes, including templates, checklists, evidence repositories, and dashboards.


Control Assurance

  • Ensure execution and evidence capture for recurring cybersecurity controls, including:
  • Monthly and quarterly user and privileged access reviews for applications, cloud portals,and applicable manufacturing-support systems.
  • Vulnerability scanning governance, confirming scans occur on schedule, findings are triaged, and remediation plans are tracked to closure (execution performed by IT, Security Operations, or Engineering).
  • Patch and vulnerability remediation tracking, including SLA monitoring, exception handling, compensating controls, and escalation of overdue items.
  • Backup, restore, and security monitoring attestations for device-supporting environments, where applicable.
  • Supplier and third-party security evidence coordination related to device development or connectivity.


SBOM, Vulnerability Disclosure & Customer Assurance

  • Govern SBOM accuracy and update cadence by coordinating inputs from Engineering and suppliers and ensuring evidence is maintained for audits and customer requests.
  • Coordinate vulnerability intake, triage governance, and coordinated vulnerability disclosure (CVD) processes (with execution performed by product security and engineering teams).
  • Lead and coordinate responses to customer cybersecurity questionnaires, risk assessments, and security audits by gathering SME input and ensuring consistent, compliant responses.


How You’ll Get There:

  • 5 years of experience in cybersecurity, governance, risk management, or regulated technology environments, with strong exposure to medical devices, healthcare technology, life sciences, or similarly regulated products.
  • Recognized as a seasoned subject-matter expert in medical device cybersecurity governance, independently owning and driving GRC programs, continuous control monitoring, audit readiness, and customer assurance activities.
  • Demonstrated ability to analyze and resolve complex, multi-factor cybersecurity and regulatory issues, applying sound judgment with minimal day-to-day guidance.
  • Proven success influencing cross-functional and senior stakeholders (Engineering, Quality, Regulatory, IT, Security, Commercial) to achieve compliant, auditable outcomes without direct authority.
  • Extensive experience supporting regulatory inspections, internal and customer audits, and pre sale cybersecurity assessments, serving as a credible internal and external representative.
  • Track record of managing multiple concurrent initiatives, driving program maturity, and delivering sustained results through scalable processes, metrics, and documentation.
  • Bachelor’s degree in Engineering, Computer Science, Cybersecurity, Biomedical Engineering, or a related field.


About Trident Consulting

Trident Consulting is an award-winning staffing and consulting firm headquartered in San Ramon, CA. Since 2005, we’ve partnered with Fortune 500 and high-growth companies to deliver high-quality talent across technology, engineering, business operations, and professional services.


We specialize in contract, contract-to-hire, and direct hire placements, supporting roles across IT, data & analytics, cloud, cybersecurity, finance & accounting, HR, operations, and more. With a strong focus on hard-to-fill and niche positions, our global recruiting engine enables us to deliver speed, quality, and scale.

Salary : $118,500 - $148,100

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Cybersecurity GRC Lead?

Sign up to receive alerts about other jobs on the Cybersecurity GRC Lead career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$125,027 - $157,872
Income Estimation: 
$149,432 - $188,965
Income Estimation: 
$163,631 - $209,073
Income Estimation: 
$192,911 - $256,346
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Trident Consulting

  • Trident Consulting Minden, NV
  • Trident Consulting is seeking a "Mechanical Assembler" for one of our client in " Minden, NV ". A global leader in business and technology services Job Tit... more
  • Just Posted

  • Trident Consulting Minden, NV
  • Company Description About Trident: Trident Consulting is an award-winning IT/engineering staffing company founded in 2005 and headquartered in San Ramon, C... more
  • Just Posted

  • Trident Consulting Indianapolis, IN
  • Trident Consulting is seeking a " Production Technician ” for one of our clients in " Indianapolis, IN” A global leader in business and technology services... more
  • Just Posted

  • Trident Consulting Nashville, TN
  • Trident Consulting is seeking a "Access control Coordinator" for one of our clients in "Nashville, TN " A global leader in business and technology services... more
  • Just Posted


Not the job you're looking for? Here are some other Cybersecurity GRC Lead jobs in the Burlington, MA area that may be a better fit.

  • Trident Consulting Burlington, MA
  • Trident Consulting is seeking a " Cybersecurity GRC Lead ” for one of our client in " Burlington, MA (Hybrid – Onsite M/W/F required) ” A global leader in ... more
  • 1 Day Ago

  • Central Business Solutions Burlington, MA
  • Trident Consulting is seeking a Cybersecurity GRC Lead for one of our clients in Burlington, MA a global leader in pharmaceutical and medical technology co... more
  • 2 Days Ago

AI Assistant is available now!

Feel free to start your new journey!