Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Engineer-Governance, Risk & Compliance

AirLife

Job Description

Job Description

COMPANY DESCRIPTION

At AirLife, we are dedicated to improving the quality of every breath. Excellence with Every Breath is not just a tag line, but the way we work and take care of our customers. With a mindset to evolve, innovate, and grow, we are a premier manufacturer of the highest-quality and market-leading breathing consumables. This growth philosophy has positioned us to increase our global footprint and business reach, impacting even more people around the world. Our expanding family of the most trusted brands offers a product portfolio that spans the continuum of care from first responder to home care, with safety, patient comfort, and clinical performance in mind. Collective expertise allows us to provide quality products and experiences to our patients, customers, and our people. Our values of Customer first, Differentiate with our People, Bias for Action, Continuous Improvement and Accountability define who we are and how we work. Join us!

POSITION SUMMARY

The Security Engineer – Governance, Risk & Compliance is responsible for establishing and maturing AirLife's information security risk management and compliance posture. This role evaluates, quantifies, and helps mitigate security risks across IT infrastructure and business systems, while ensuring AirLife's cybersecurity practices remain aligned to applicable regulatory frameworks, industry standards, and internal policies. Operating in a medical device manufacturing environment with FDA and ISO regulatory obligations and a PE ownership structure with specific cybersecurity reporting requirements, this role brings both technical security knowledge and a compliance mindset to a rapidly maturing IT security program. The Security Engineer – GRC plays a critical role in AirLife's ability to satisfy external auditors, insurance underwriters, and PE sponsor security benchmarking requirements.

POSITION QUALIFICATIONS

Knowledge, Skills & Abilities:

  • Strong working knowledge of security risk management frameworks and methodologies, including NIST CSF, NIST SP 800-30/37, ISO 27001, and CIS Controls.
  • Understanding of regulatory compliance requirements relevant to medical device manufacturing, including FDA 21 CFR Part 820 / QMSR and ISO 13485, and their implications for IT General Controls (ITGC) and computer system validation.
  • Experience with IT General Controls frameworks and audit support, including SOX-adjacent controls applicable to PE-backed manufacturing companies.
  • Knowledge of data privacy regulations, including GDPR and applicable US state privacy laws, and their operational IT implications.
  • Experience conducting risk assessments, gap analyses, and security control reviews; ability to document, prioritize, and track findings through to remediation.
  • Experience developing and maintaining security policies, standards, procedures, and control evidence libraries.
  • Familiarity with vulnerability management programs, including scanning tooling, remediation tracking, and risk-based prioritization.
  • Experience administering security awareness training programs, including phishing simulation and completion tracking (KnowBe4 experience preferred).
  • Ability to work with MDR/MSSP providers to ensure managed detection capabilities align with AirLife's compliance posture (Arctic Wolf experience a plus).
  • Strong written communication skills; ability to clearly document findings, prepare audit evidence packages, and present risk posture to non-technical audiences including executives and external auditors.
  • Proficiency with project and task management tools; Smartsheet experience preferred.
  • Industry-recognized GRC or cybersecurity certification(s) preferred (CISA, CRISC, CompTIA Security+, SSCP, or equivalent).

Level of Experience:

Minimum 4–6 years of IT experience with 3+ years in a cybersecurity role with a GRC, compliance, or risk management focus. Experience in a regulated manufacturing, medical device, or life sciences environment strongly preferred.

Level of Education:

Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field, or equivalent experience. GRC-relevant certification(s) preferred.

Travel:

Up to 20% as required by the business.

ESSENTIAL DUTIES AND RESPONSIBILITIES

  • Develop, implement, and maintain AirLife's information security policies, standards, and procedures, ensuring they remain current, compliant with applicable frameworks, and operationally effective for the teams they govern.
  • Conduct and facilitate periodic security risk assessments and gap analyses across IT infrastructure, business applications, and operational technology, documenting findings, quantifying risk, and recommending prioritized remediation measures to IT leadership.
  • Own AirLife's security compliance posture across applicable frameworks (NIST CSF, CIS Controls, ISO 27001, GDPR), including control documentation, evidence collection, ongoing compliance monitoring, and management of compliance calendars.
  • Support IT General Controls (ITGC) compliance, including access control review coordination, change management process documentation, and preparation and management of audit evidence packages for internal and external auditors.
  • Partner with QA/RA and Legal & Compliance to ensure IT security controls are appropriately aligned to AirLife's 21 CFR Part 820 / QMSR and ISO 13485 obligations, particularly as they relate to computer system validation and access control in regulated processes.
  • Own and administer AirLife's security awareness and compliance training program, including planning and coordinating KnowBe4 phishing simulation and training campaigns, tracking completion rates across departments, and reporting to IT leadership on compliance status.
  • Maintain and improve AirLife's vulnerability management program, including scheduling assessments, tracking and prioritizing remediation, and reporting vulnerability posture and trends to IT leadership.
  • Support Frazier Partners' cybersecurity benchmarking and reporting requirements; coordinate with Lockton for cyber insurance assessment preparation and supply requested security metrics, documentation, and evidence as required.
  • Collaborate with Arctic Wolf and other managed security service providers to ensure managed services are operating in alignment with AirLife's compliance posture, risk appetite, and applicable regulatory requirements.
  • Maintain, test, and continuously improve the IT Cyber Incident Response Playbook; support the planning and facilitation of tabletop exercises; assist in incident response coordination and post-incident review when security events occur.
  • Serve as the IT security subject matter expert for IT-related internal and external audits: prepare evidence packages, coordinate audit interviews, manage finding responses, and own remediation tracking through closure (including all enterprise applications and segregation-of-duties findings).
  • Build and maintain a comprehensive GRC documentation library, including the risk register, control matrix, policy library, compliance calendar, and audit history, ensuring currency and accessibility for authorized stakeholders.

OTHER RESPONSIBILITIES

  • Uphold and embody AirLife's values in all aspects of work.
  • Demonstrate accuracy and thoroughness in daily work; look for ways to improve and promote quality & safety.
  • Inspire the trust of others; treat people with respect and dignity and embrace the value of diversity.
  • Use time efficiently; perform job accurately, thoroughly, and conserve Company resources to improve profits.
  • Contribute to building and maintaining a positive team environment.
  • Assure all policies and guidelines are implemented and followed.

QUALITY POLICY

At AirLife, Quality is our promise. It is our commitment to customer satisfaction and our dedication to product excellence in an evolving global healthcare market. This promise is kept through a continuously improving and effective Quality Management System and compliance to Regulatory Requirements.

DEIA STATEMENT

At AirLife, we are committed to building a diverse workforce and an inclusive workplace that reflects the communities and customers we serve. We believe our philosophy on Diversity, Equity, Inclusion, and Advancement (DEIA) encourages excellence and equips us to serve an evolving global marketplace.

Please note: The responsibilities outlined above are not exhaustive and may evolve over time. The role holder may be required to undertake additional duties as reasonably expected to meet the needs of the company.

Benefits

AirLife offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k), paid time off, paid holidays, bereavement leave, Employee Assistance Program resources, and medical leave benefits, subject to applicable eligibility requirements. Certain positions may also be eligible for bonus, commission, or other incentive compensation.

Vacancy posted 23 days ago
Similar jobs that could be interesting for youBased on the Security Engineer-Governance, Risk & Compliance in Grand Rapids, MI vacancy
  •  ...work. Join us! POSITION SUMMARY The Security Engineer – Security Operations & Incident...  ...detection design. Knowledge of security compliance frameworks (NIST, CIS Controls, ISO 270...  ...time to remediate) and identify recurring risks or trends for leadership reporting.... 
    Suggested

    AirLife

    Grand Rapids, MI
    22 days ago
  •  ...the food service industry. There's a seat at our table for you...Position Summary:The Senior Cybersecurity Engineer is a core technical leader within our Security Operations (SecOps) team, responsible for designing, automating, and maintaining the organization’s enterprise... 
    Suggested
    Full time
    Work at office
    Monday to Friday

    Gordon Food Service

    Wyoming, MI
    17 hours ago
  • $105.4k - $207.8k

    Position Summary Cyber Security & Risk Strategy Senior Consultant...  ...organizational structure, governance, roles and responsibilities...  ..., Risk Management, Engineering, or a similar fieldProfessional...  ...with governance, risk, and compliance tools, identity and access... 
    Suggested
    Local area
    Visa sponsorship

    Deloitte

    Grand Rapids, MI
    19 hours ago
  •  ...coordination, remediation tracking, and compliance support. - Assist with...  ...scorecard data. - Monitor security tools and alerts, performing...  ...cybersecurity operations, security governance, or enterprise security...  ...environments - Familiarity with risk management, POA&M governance,... 
    Suggested
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Remote work

    MAXIMUS

    Grand Rapids, MI
    1 day ago
  • IT Security Engineer A career at Auto-Owners is challenging and rewarding. Our group of caring associates...  ...responsible for reducing IT Security risk and responding to incidents for the...  ...an environment of IT security compliance by enforcing corporate policies and facilitating... 
    Suggested
    Currently hiring
    Local area
    3 days per week

    Auto-Owners Insurance

    Grand Rapids, MI
    2 days ago
  • $82.6k - $162.8k

     ...Cyber Security & Risk Strategy Consultant Our Deloitte Cyber team...  ...organizational structure, governance, roles and responsibilities...  ...Technology, Risk Management, Engineering, or a similar field Professional...  ...with governance, risk, and compliance tools, identity and access... 
    Local area
    Visa sponsorship

    Deloitte

    Grand Rapids, MI
    5 days ago
  • $105.4k - $207.8k

     ...Cyber Security & Risk Strategy Senior Consultant Our Deloitte Cyber team understands the unique challenges and opportunities businesses...  ...operating models, including organizational structure, governance, roles and responsibilities, and process design for cyber and... 
    Visa sponsorship

    Deloitte

    Grand Rapids, MI
    5 days ago
  •  ...Responsibilities: - Experience supporting documentation, reporting, and compliance activities - Understanding of network monitoring tools and...  ..., compliance-driven environments - Familiarity with network security concepts, including firewalls, access control, and traffic... 
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    Remote work

    MAXIMUS

    Grand Rapids, MI
    7 hours ago
  •  ...There's a seat at our table for you...Position Summary:The Cloud Security Engineer defines, documents, and implements infrastructure and...  ...team processes and disciplines into cloud environments (e.g. Risk Management, Vulnerability Management, Secure Application Development... 
    Full time
    Work at office
    Monday to Friday

    Gordon Food Service

    Wyoming, MI
    16 hours ago
  • $97.6k - $200.6k

     ...potential SIEM content/level I and II engineering security concerns as this role is the first line...  ...MITRE ATT&CK framework, based on business risk and priorities.Collaborate with...  ...incentive program, subject to the rules governing the program, whereby an award, if any,... 

    Deloitte

    Grand Rapids, MI
    1 day ago
  • $105.4k - $207.8k

     ...through scalable, resilient security operations solutions. In this...  ...SecOps, threat detection engineering, and automation. You will work...  ...threats, vulnerabilities, and compliance trendsA successful candidate...  ..., subject to the rules governing the program, whereby an award... 
    Local area
    Visa sponsorship

    Deloitte

    Grand Rapids, MI
    1 day ago
  • $118.7k - $243.7k

    Position Summary As a Manager in AI Security Engineering, you will play a critical role in...  ...systems meet enterprise security, risk, and compliance expectations. Key Responsibilities...  ...program, subject to the rules governing the program, whereby an award, if any... 

    Deloitte

    Grand Rapids, MI
    19 hours ago
  •  ...enterprise networking and network security and helps clients translate business requirements, cyber risk, and infrastructure...  ...security leaders, architects, and engineering teams on Cisco strategy, modernization...  ...solution ownership, partner governance, and commercial... 
    Full time
    Local area
    Remote work
    Work from home

    Optiv

    Grand Rapids, MI
    2 days ago
  •  ...partner to Optiv’s clients. By combining advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor designs...  ...security environment, business operations, security needs, and risk appetiteIdentify AI related security concerns and/or potential... 
    Full time
    Local area
    Remote work
    Work from home

    Optiv

    Grand Rapids, MI
    19 hours ago
  • $150k - $190k

     ...is look for an Information Security Architect for a Direct...  ...modeling for complex or high-risk implementations Contribute...  ...templates Partner with Governance, Risk, and Compliance (GRC) to ensure controls...  ...Science, Computer Engineering, Cybersecurity, Information... 
    Permanent employment
    Temporary work
    Work experience placement
    Remote work

    Randstad Digital

    Grand Rapids, MI
    4 days ago
  • $150k - $190k

     ...Computer Science, Computer Engineering, Cybersecurity,...  ...experience in information security and/or architecture, with...  ...grasp of security controls, risk management, and compliance integration ~ Ability to...  ...templates Partner with Governance, Risk, and Compliance to... 
    Permanent employment
    Full time
    Temporary work
    Remote work

    Randstad Digital

    Grand Rapids, MI
    9 days ago
  •  ...The Security Architect shall lead information technology security initiatives, identify security issues and provide solutions and mitigations...  ...will verify the security of the systems and maintain compliance with changing system configurations and security requirements.... 
    Home office

    Omega Solutions Inc

    Wyoming, MI
    4 days ago
  •  ...Enterprise Information Security Architect leads the...  ...with other architects, engineers, and IT/Security specialists...  ...support cybersecurity risk reduction efforts...  ...Cloud concepts including: governance, computing, networking...  ..., data protection, compliance, Identity and Access... 
    Full time
    Work experience placement
    Work at office
    Monday to Friday

    Gordon Food Service

    Wyoming, MI
    1 day ago
  • $167k - $223k

     ...market opportunities. The ATO Systems Security Engineering Technical Leader is expected to...  ...standards and methodologies such as the Risk Management Framework (RMF). Security...  ...execution. Experience working with U.S. Government Sponsors. Experience working on... 
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Relocation package

    GE Renewable Energy Power and Aviation

    Grand Rapids, MI
    a month ago
  • $102.17k

     ...Description Join the Trinnex Security Team as a Senior Cyber...  ...You will work closely with engineering and development teams to safeguard...  ...reviews of security controls and compliance with regulatory and security...  ...analysis (SCA), open-source risk management, and vulnerability... 
    Work experience placement
    H1b

    Trinnex

    Grand Rapids, MI
    1 day ago
  • $66.2k - $135.8k

     ...motivated professional to join our Government & Public Services (GPS) BISO...  ...for documenting the security of information systems within...  ...The GPS BISO Analyst ensures compliance with relevant regulations and...  ...security measures, conducting risk assessments, and providing guidance... 

    Deloitte

    Grand Rapids, MI
    2 days ago
  • $80.5k - $159.3k

     ...practical cybersecurity and risk solutions. You will work...  ...cybersecurity posture, design security programs, evaluate IT...  ...programs across domains such as governance, risk, and compliance (GRC) and business...  ...Computer Science, Cybersecurity, Engineering, or related field. ~2+... 
    Local area
    Worldwide

    Crowe

    Grand Rapids, MI
    4 days ago
  •  ...Specialist, located in New York, NY, with flexibility for partial remote work. In this role, you will assist in identifying and mitigating security vulnerabilities, support network monitoring activities, and collaborate with team members to implement effective security measures... 
    Full time
    Remote work

    CyberInterviewPrep

    Wyoming, MI
    more than 2 months ago
  • $40.48 - $46.95 per hour

     ...Job Description Job Description Build. Secure. Defend. Innovate. At Union, technology powers everything we do. We're looking for an IT Infrastructure & Cybersecurity Analyst who is passionate about protecting critical systems, solving complex technical challenges... 
    Hourly pay
    Flexible hours

    Union Wireless

    Wyoming, MI
    10 days ago
  •  ...Job Description Job Description PreSales Engineer Physical Security Overview:   We’re looking for an experienced  Physical Security   Sales Engineer who thrives at the intersection of technology and customer success, someone who can bridge the gap between sales... 
    Local area

    K Group Companies

    Grand Rapids, MI
    a month ago
  •  ...role supporting a complex enterprise network environment across security, routing, switching, wireless, SD-WAN, data center, cloud...  ...This role is ideal for a hands-on NOC Lead or Senior Network Engineer who work in a Hybrid onsite/remote capacity with the team in Grand... 
    Temporary work
    Remote work
    Work from home
    Night shift
    3 days per week

    Delan Associates, Inc

    Grand Rapids, MI
    a month ago
  •  ...the combined business, technology, and engineering experience to deliver these outcomes, in...  ...for an Engineering Assistant, Physical Security to support technical design and project...  ...conflicting direction, and other project risks. Support Quality and Process Improvement... 
    Work at office
    Local area

    People Driven Technology Inc

    Byron Center, MI
    3 days ago
  •  ...With decades of combined experience in business, technology, and engineering, we focus on creating simple, scalable outcomes for our...  ...customers and strategic partners. The  Systems Engineer – Physical Security will be responsible for working alongside project management... 
    Work at office

    People Driven Technology Inc

    Byron Center, MI
    a month ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Engineer-Governance, Risk & Compliance. Be the first to apply!