← Back to jobs

GRC & Compliance Specialist — Healthcare

  • Remote
  • Sweden
  • English
  • Posted 15.09.26 14:53

We’re looking for the special, unique, and amazing YOU!@ KCS IT, we look for the ones that stand out, for those that always want to be better and fight for it, and for those who have the same values that we do: dedication, energy, integrity, transparency, flexibility, trust, honesty, hard work, proactivity, teamwork.We are looking for an Amazing: GRC & Compliance Specialist — Healthcare 🚀Seniority: +6 yearsWork model: RemoteThe amazing you, will have:Bachelor's or Master's degree in Information Security, Cybersecurity, IT, Risk Management, Compliance, or a similar area;At least 6 years of professional experience in GRC, Information Security, Compliance, Risk Management, or a related field;Strong knowledge of ISO 27001;Proven experience with Information Security Management Systems (ISMS);Strong understanding of GDPR and data protection requirements;Experience with information security and compliance risk assessments;Previous experience supporting and participating in internal and external audits;Experience developing, implementing, and maintaining security policies, procedures, controls, and compliance documentation;Good understanding of Governance, Risk, and Compliance principles;Strong analytical and problem-solving skills;Excellent communication and stakeholder management skills;Ability to work independently and collaboratively with different teams;Fluent English required.Responsibilities:Support the development, implementation, and maintenance of the organization's GRC framework;Maintain and continuously improve the Information Security Management System (ISMS);Support compliance with ISO 27001, GDPR, and other applicable regulatory and industry requirements;Conduct and support information security and compliance risk assessments;Identify, assess, document, and monitor security and compliance risks;Support internal and external audits, including preparation, evidence gathering, and follow-up of findings;Develop, review, and maintain security policies, procedures, controls, and compliance documentation;Monitor the effectiveness of security controls and identify opportunities for improvement;Support the implementation and follow-up of corrective and preventive actions;Work with internal teams and stakeholders to ensure security and compliance requirements are properly understood and implemented;Support third-party and supplier security assessments;Track regulatory and compliance requirements and identify potential gaps;Prepare reports and documentation for management and relevant stakeholders;Support the continuous improvement of the organization's security and compliance posture;Contribute to security awareness and compliance initiatives across the organization.To turn yourself from amazing to unique, you´ll have (plus):ISO 27001 Lead Auditor or Lead Implementer certification;CISA, CISM, CRISC, or similar certification;Previous experience in Healthcare, Pharma, MedTech, or another highly regulated industry;Experience with GRC platforms and risk management tools;Knowledge of NIST, CIS Controls, SOC 2, or other security frameworks;Experience with third-party risk management;Experience working with regulatory authorities or external auditors;Experience with business continuity and operational resilience;Knowledge of cybersecurity risk management;Experience working with international clients and multicultural teams;Speak other languages.Why should you become part of our family?You can develop a career that fits you: your career development is personalized, taking into consideration your needs and goals from a short to long term;Interesting Challenges Ahead: you can work for several clients from different sectors of activity;Free training programs: our training and certification programs in languages, tech, behavior, and business will help you to reach your full potential faster;International projects: you can gain international experience and balance a new way of living with work;Type of projects (depending on the project you might find one of these types of projects):Hybrid Systems: it’s important to balance work with socialization, that’s because a hybrid system works for us and for you;Full Remote projects: if you want to work while enjoying the comfort of your home;Full Onsite projects: if you prefer the company of your colleagues!Take care of your well-being: enjoy our free nutrition, psychologist, general medicine appointments and our yoga and personal training days… all remote!Who are we?Founded in 2008 and based in Lisbon, KCS IT is a consulting company in the field of Information Technology and Services, focused on creating value for our clients through three main areas: Consulting, Outsourcing, Innovation and Training.Our commitment to talent development is unmistakable in the recent opening of the Porto and Azores hubs, which aims to develop technology for the national and international market.Since 2018 we have been elected one of the 10 major companies in the “Index of Excellence”, an initiative that aims to reward organizations that invest most in the development and satisfaction of their employees.At KCS IT,We stand for equality and value diversity. We foster a safe, diverse environment where opportunities are equal for all employees!We do not discriminate based on age, ethnicity, sexual orientation, gender, disability, or any factor other than merit.All applications with the required skills for the position are welcome!