Cybersecurity GRC Lead
Glaukos Corporation
Job Description What You'll Do: The Cybersecurity GRC Lead - Medical Devices (Continuous Control Monitoring Lead) is responsible for overseeing and coordinating cybersecurity governance, risk, and compliance (GRC) activities supporting medical devices produced and supported internationally. This role ensures that cybersecurity "run-the-business" controls and evidence-producing activities-such as access reviews, vulnerability scanning cadence, patch tracking, SBOM governance, and audit readiness-are properly planned, executed by the appropriate teams, and documented. This is a coordination, governance, and assurance role rather than a hands-on technical execution role. The position partners closely with Engineering/R&D, Quality, Regulatory Affairs, IT, and Information Security to maintain compliance with applicable standards and regulatory guidance and to ensure customer and regulatory cybersecurity requirements are tracked through completion. Governance & Program Oversight
Innovation is at the core of everything we do, and we are resolute in our commitment to challenge conventional thinking with new treatment alternatives that are supported by real science, robust clinical evidence, and an unrelenting focus on patients.
Our constant pursuit of game-changing technologies that disrupt legacy treatment paradigms is encapsulated in the Glaukos mantra "We'll Go First," which articulates our willingness to take chances, our determination to forge new ground, and our commitment to continuous improvement in all that we do.
Our company completed an initial public offering in June of 2015, and our shares are traded on the New York Stock Exchange under the ticker symbol "GKOS". Our global headquarters is in Aliso Viejo, California with additional locations in San Clemente, California, and Burlington, Massachusetts. Glaukos Corporation is an Equal Opportunity/Affirmative Action Employer . All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.
All offers of employment are contingent upon the successful completion of a background check, including successfully passing a drug screen, based on the position and local regulations.
- Own and maintain the medical device cybersecurity GRC plan, calendar, and control schedule (monthly, quarterly, and annual activities).
- Ensure cybersecurity roles, responsibilities, RACIs, and escalation paths are defined and functioning across IT, Engineering, and Quality teams.
- Maintain governance documentation, including policies, procedures, standards, control narratives, and work instructions related to medical device cybersecurity.
- Provide regular program status reporting (KPIs/KRIs, control execution status, risk posture, overdue actions) to the CISO and other stakeholders.
- Track cybersecurity requirements from customers, internal stakeholders, and applicable standards and guidance (e.g., FDA expectations, IEC 62304/62443 concepts, NIST-aligned controls) through implementation and evidence completion.
- Coordinate cybersecurity risk assessments and ensure resulting remediation actions are assigned, tracked, and closed by accountable owners (Engineering, IT, suppliers, etc.).
- Maintain the cybersecurity risk register for medical device-related risks impacting products, manufacturing/operations, and supporting systems.
- Serve as the central coordination point between Sales, Engineering, Quality, Regulatory Affairs, IT, and Information Security for cybersecurity compliance deliverables.
- Coordinate with Quality and Regulatory Affairs to ensure pre-sale cybersecurity responses meet regulatory and compliance expectations.
- Escalate and track gaps or risks identified during the pre-sale process to appropriate internal stakeholders.
- Support Quality and Regulatory teams with audit and inspection readiness by ensuring cybersecurity artifacts are current, approved, and readily retrievable (e.g., threat models, vulnerability management evidence, access review records).
- Drive continuous improvement of GRC processes, including templates, checklists, evidence repositories, and dashboards.
- Ensure execution and evidence capture for recurring cybersecurity controls, including:
- Monthly and quarterly user and privileged access reviews for applications, cloud portals,and applicable manufacturing-support systems.
- Vulnerability scanning governance, confirming scans occur on schedule, findings are triaged, and remediation plans are tracked to closure (execution performed by IT, Security Operations, or Engineering).
- Patch and vulnerability remediation tracking, including SLA monitoring, exception handling, compensating controls, and escalation of overdue items.
- Backup, restore, and security monitoring attestations for device-supporting environments, where applicable.
- Supplier and third-party security evidence coordination related to device development or connectivity.
- SBOM, Vulnerability Disclosure & Customer Assurance
- Govern SBOM accuracy and update cadence by coordinating inputs from Engineering and suppliers and ensuring evidence is maintained for audits and customer requests.
- Coordinate vulnerability intake, triage governance, and coordinated vulnerability disclosure (CVD) processes (with execution performed by product security and engineering teams).
- Lead and coordinate responses to customer cybersecurity questionnaires, risk assessments, and security audits by gathering SME input and ensuring consistent, compliant responses.
- 5+ years of experience in cybersecurity, governance, risk management, or regulated technology environments, with strong exposure to medical devices, healthcare technology, life sciences, or similarly regulated products.
- Recognized as a seasoned subject-matter expert in medical device cybersecurity governance, independently owning and driving GRC programs, continuous control monitoring, audit readiness, and customer assurance activities.
- Demonstrated ability to analyze and resolve complex, multi-factor cybersecurity and regulatory issues, applying sound judgment with minimal day-to-day guidance.
- Proven success influencing cross-functional and senior stakeholders (Engineering, Quality, Regulatory, IT, Security, Commercial) to achieve compliant, auditable outcomes without direct authority.
- Extensive experience supporting regulatory inspections, internal and customer audits, and pre-sale cybersecurity assessments, serving as a credible internal and external representative.
- Track record of managing multiple concurrent initiatives, driving program maturity, and delivering sustained results through scalable processes, metrics, and documentation.
- Bachelor's degree in Engineering, Computer Science, Cybersecurity, Biomedical Engineering, or a related field.
Innovation is at the core of everything we do, and we are resolute in our commitment to challenge conventional thinking with new treatment alternatives that are supported by real science, robust clinical evidence, and an unrelenting focus on patients.
Our constant pursuit of game-changing technologies that disrupt legacy treatment paradigms is encapsulated in the Glaukos mantra "We'll Go First," which articulates our willingness to take chances, our determination to forge new ground, and our commitment to continuous improvement in all that we do.
Our company completed an initial public offering in June of 2015, and our shares are traded on the New York Stock Exchange under the ticker symbol "GKOS". Our global headquarters is in Aliso Viejo, California with additional locations in San Clemente, California, and Burlington, Massachusetts. Glaukos Corporation is an Equal Opportunity/Affirmative Action Employer . All qualified applicants will receive consideration for employment without regard to race, color, religion, sex including sexual orientation and gender identity, national origin, disability, protected Veteran Status, or any other characteristic protected by applicable federal, state, or local law.
All offers of employment are contingent upon the successful completion of a background check, including successfully passing a drug screen, based on the position and local regulations.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Cybersecurity GRC Lead in Burlington, MA vacancy
$118k - $146k
...Trident Consulting is seeking a " Cybersecurity GRC Lead" for one of our client in " Burlington, MA (Hybrid - Onsite M/W/F required)" A global leader in business and technology services. Please find additional details about the role below: Job Title: Cybersecurity...SuggestedFull timeContract workRelocation package- ...demands a proactive approach to maintain and secure supply chain systems. Ideal candidates have knowledge of MITRE Framework and relevant cybersecurity certifications. The position offers a competitive salary and comprehensive benefits. #J-18808-Ljbffr Koitecc SolutionsSuggested
- Energetiq Technology Inc in Wilmington, MA, is seeking an IT & Security Sr. Manager to oversee enterprise technology and cybersecurity in a high-IP environment. This full-time leadership role focuses on improving security posture while managing both day-to-day operations...SuggestedFull time
$110k - $129k
A leading cybersecurity company based in Chelmsford, Massachusetts, is seeking a Global MDF Program Manager. This role involves developing frameworks for MDF programs, defining guidelines for usage, and ensuring compliance across regions. Candidates should have a Bachelor...SuggestedFlexible hours- ...Title: Lead System/Solution Architect The Lead System/Solution Architect is a senior technology leader responsible for defining... ...ecosystems, cloud infrastructure, data platforms, AI/ML, and cybersecurity. The successful candidate will serve as the technical lead...SuggestedLocal area
- ...serve as a subject matter expert and final escalation point for cybersecurity events. The ideal candidate will independently investigate and... ...a dynamic opportunity to contribute to cybersecurity at a leading institution. #J-18808-Ljbffr Massachusetts Institute of Technology
$83k - $123k
...the barriers that come with traditional therapy practices. Note--this is a hybrid position, not 00% remote. As a supervising Lead Marriage and Family Therapist at Ellie Mental Health's locally owned and operated clinic in Lexington, MA, you'll share our vision for...Full timeWork at officeLocal areaFlexible hours$83k - $123k
...barriers that come with traditional therapy practices. Note--this is a hybrid position, not a 100% remote position. As a supervising Lead Marriage and Family Therapist at Ellie Mental Health’s locally owned and operated clinic in Newton, MA, you'll share our vision for...Full timeWork at officeLocal areaFlexible hours$132.4k - $251.6k
...solving the world's most complex problems. With our three market leading businesses, world-class operations and investments in research... ...us and help shape the future of aerospace and defense. Our cybersecurity team, is seeking a Site Lead and Information System...Contract workTemporary workWork experience placementWork at officeRemote workRelocation packageFlexible hours$107.5k - $204.5k
...solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in... ...Join us and help shape the future of aerospace and defense. Our cybersecurity organization is seeking a Cybersecurity Reporting & Analytics...Full timeTemporary workWork experience placementWork at officeRemote workWorldwideRelocationRelocation packageFlexible hours$22.79 - $24.19 per hour
A leading toy manufacturer is searching for a part-time Retail Supervisor for their Burlington Mall location. This role involves supervising sales associates, managing store operations, and enhancing customer service through effective training and leadership. Ideal candidates...Hourly payPart time$31.25 - $38 per hour
.... Provide leadership, guidance, and day-to-day support to Materials team members. Mentor and train junior staff; partner with Leads and management to support development and process improvements. Assist in developing work plans, assigning tasks, and monitoring...Hourly payFor contractorsWeekend work- ...marketplace | Employee Resource Groups such as VetConnect, DEI Committee, Women’s Committee. Position Summary: The Field Canvassing Team Lead is responsible for hiring, training, and developing a team of Field Canvassers to build Leaf Home brand awareness in pre-selected...H1bWork at officeLocal areaWork from homeShift workAfternoon shift
$108k - $135k
...Job Title: Lead, Commercial Strategy and Pricing Job Description: The Role Entegris is seeking a Lead, Commercial Strategy & Pricing to support enterprise-level commercial execution across growth planning, pricing, and deal strategy. This is a senior...H1bWork at office$107.5k - $204.5k
...You will ensure customer expectations and end-user objectives are satisfied, interfaces with program and functional partners, and lead teams focused on Quality and Mission Assurance capability, execution and performance excellence across the full product life cycle,...Temporary workWork experience placementFor subcontractorWork at officeRemote workRelocation packageFlexible hours- ...R&D Procurement Contracts Lead II A Few Words About Us Integrated Resources, Inc is a premier staffing firm recognized as one of the tri-states most well-respected professional specialty firms. IRI has built its reputation on excellent service and integrity since its...Contract work
- ...You will ensure customer expectations and end-user objectives are satisfied, interfaces with program and functional partners, and lead teams focused on Quality and Mission Assurance capability, execution and performance excellence across the full product life cycle,...Work experience placementRelocation package
$119.5k - $149k
...Job Title: Lead, Global Shop Floor Execution Enablement Job Description: The Role: Entegris is seeking a highly motivated Global Shop Floor Execution Enablement Lead to support our Advanced Purity Solutions division. This role is accountable for improving...Temporary workH1bWork at officeLocal area- ...end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Lead, Subcontracts Job Code: 36143 Job Location: Wilmington, MA Job Schedule: 9/80: Employees work 9 out of every 14 days - totaling...For subcontractorLocal areaFlexible hours
$21 - $28.26 per hour
Under direction from the Manager, Health Information Management, a Lead Health Information Management Audit Specialist collaborates closely with other departments and teams to provide efficient and thorough healthcare claims auditing for Beth Israel Lahey Health (BILH)...Hourly payWork experience placementWork at officeShift work$20 per hour
...Lead Distribution Generalist (Part Time) 0171 Plant 171 Montvale - Woburn, MA 01801 Overview Salary Range $20.00 - $20.00 Hourly Description PCF is a Distribution Service Provider focused on the delivery needs of the high-density, high-pressure Northeast...Hourly payPart timeWork at officeNight shiftDay shiftEarly shift$132.4k - $251.6k
...Our team solves tough, meaningful problems that create a safer, more secure world. Join our team as a Senior Program Quality Lead (PQL) supporting the Advanced Technologies (AT) Strategic Business Unit. Program Quality drives customer, program, and business success...Temporary workWork experience placementFor subcontractorWork at officeRemote workRelocation packageFlexible hours- ...Job Details React Native Onshore Lead React Native Onshore Lead where they are looking for someone with at least 10 years of React Native hands on development experience as a technical lead of a mobile app development team. ** they are in urgent...Immediate start
- Starting Pay Rate: $26Shift: Monday-Thursday 2:30pm-12am, Friday 1:30pm-10pmOccasional Saturdays and overtime based on business needsWhat is the value of a WM job?The value of a WM job is more than a paycheck. It's a way to create opportunities forAfternoon shift
- ...Senior BI Team Lead Apex Systems is a world-class technology services business that incorporates industry insights and experience to deliver solutions that fulfill our clients’ digital visions. Apex has an opportunity for a Senior BI Team Lead role in the Boston...Contract work
- ...Contract CSV Lead Woburn, MA Required Skills / Job Description: Job Description The role is to lead and manage the CSV requirements for the laboratory applications and Benchtop equipment which includes software applications like...Contract work
- Software Developer Develop cutting edge technology solutions for a fast-changing healthcare landscape. Our products are built on top of a cloud-based multi-tenanted environment. Develop, design, and integrate ElasticSearch, an open source full-text search engine...Temporary work
- ...Job Title: Oracle Fusion Financials Functional Lead / Finance Transformation Consultant Job Location: Burlington, MA Duration: Contract Job Summary We are seeking an experienced Oracle Fusion Financials Functional professional to review...Hourly payContract workRelocation
$140k - $225k
...and development of staff and the development of new business opportunities with support from our business development team. Help lead the office in technical excellence and employee development and collaborate with our other Principals to provide vision and...Full timeWork at officeFlexible hours$24.21 per hour
Garda World Security in Billerica, MA is seeking a dedicated Concierge Security Supervisor. This role emphasizes exceptional customer service while overseeing access control and ensuring safety in environments such as office towers and shopping centers. The position offers...Hourly payWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity GRC Lead. Be the first to apply!

