Hollister Incorporated

Supervisor, IT Security, Governance, Risk & Compliance

Hollister Incorporated  •  Onsite  •  3 hours ago
Apply
AI can make mistakes so check important info. Chat history is never stored.

Job Description

We Make Life More Rewarding and Dignified

Location: ​Winnersh​

Department: ​IT

Summary

The Supervisor, Governance, Risk & Compliance (GRC) leads and enhances the organization's cybersecurity governance, risk management, regulatory compliance, audit readiness, third-party risk, security awareness, privacy coordination, and policy management programs. The role provides both strategic direction and operational oversight while leading a team responsible for ensuring alignment with regulatory requirements, industry frameworks, contractual obligations, and internal security standards. The position serves as a key liaison across Cybersecurity, IT, Legal, Privacy, Compliance, Internal Audit, Quality, and business functions to ensure cybersecurity risks are effectively identified, assessed, communicated, and managed in accordance with business objectives and risk appetite.

Responsibilities

Governance & Security Program Management

  • Lead the development, implementation, and maintenance of cybersecurity governance programs, policies, standards, procedures, and guidelines.
  • Align governance activities with business objectives, cybersecurity strategy, and enterprise risk appetite.
  • Develop and maintain KPIs, KRIs, program metrics, and executive reporting.
  • Drive cybersecurity program maturity and continuous improvement initiatives.

Cybersecurity Risk Management

  • Lead enterprise cybersecurity risk assessments and maintain the cybersecurity risk register.
  • Facilitate risk reviews, mitigation planning, risk acceptance, and remediation efforts.
  • Evaluate cybersecurity risks associated with new technologies, cloud services, vendors, and business initiatives.
  • Ensure risk decisions are documented, approved, and periodically reviewed.
  • Communicate key risks, trends, and mitigation activities to leadership.

Compliance & Regulatory Oversight

  • Manage compliance programs related to ISO 27001, SOC 2, HIPAA, GDPR, UK Cyber Essentials, NIST Cybersecurity Framework, and other applicable regulations.
  • Coordinate control assessments, evidence collection, gap analyses, corrective actions, and compliance reporting.
  • Monitor regulatory and industry changes and assess organizational impacts.
  • Maintain an audit-ready cybersecurity compliance posture.

Audit & Assurance Management

  • Serve as the primary cybersecurity coordinator for internal and external audits, certifications, and regulatory assessments.
  • Lead audit preparation, evidence validation, stakeholder engagement, and responses.
  • Track audit findings, corrective actions, and remediation progress.
  • Provide status reporting and updates to leadership.

Third-Party Risk Management

  • Oversee cybersecurity due diligence and risk assessments for vendors, suppliers, and service providers.
  • Review security controls, certifications, contracts, and assessment responses for critical vendors.
  • Coordinate remediation activities with vendors, procurement, legal, and business stakeholders.
  • Establish ongoing monitoring and reporting practices for third-party security risks.

Security Awareness, Policy & Culture

  • Lead enterprise security awareness and compliance training initiatives.
  • Measure program effectiveness through participation and behavior-based metrics.
  • Partner with HR and business leaders to strengthen security culture and accountability.
  • Maintain cybersecurity policies through review, approval, communication, and lifecycle management processes.

People Leadership

  • Supervise, coach, mentor, and develop GRC and data protection team members.
  • Establish performance expectations, development plans, and accountability measures.
  • Manage workload prioritization, resource allocation, and operational coverage.
  • Promote collaboration, knowledge sharing, and continuous learning.

Stakeholder Engagement

  • Collaborate with Cybersecurity, IT, Legal, Privacy, Internal Audit, Quality, Regulatory Affairs, Data & AI, and business leaders.
  • Translate cybersecurity and compliance requirements into actionable business processes.
  • Present program updates, compliance status, risks, and recommendations to leadership.

Essential Functions of the Role

  • Communicate effectively via email, phone, and virtual platforms.
  • Collaborate across departments to support organizational goals.
  • Participate in cross-functional meetings and initiatives.
  • Prepare reports and dashboards for internal stakeholders.
  • Ensure data accuracy and confidentiality in compliance with company and legal standards.
  • Demonstrate initiative in identifying process improvements or automation opportunities.
  • Maintain secure handling of sensitive information.
  • Support audits and regulatory reporting as needed.

Education & Work Requirements

  • Bachelor’s Degree with 8-12 years of related experience

Education & Work Preferences

  • Progressive experience in cybersecurity, governance, risk management, compliance, audit, or information security.
  • 3+ years of people leadership, supervisory, or demonstrated workstream leadership experience.
  • Experience supporting or leading ISO 27001, SOC 2, HIPAA, privacy, or similar compliance programs.
  • Experience conducting risk assessments, managing audits, tracking remediation activities, and performing third-party security risk assessments.
  • Experience within healthcare, medical device, manufacturing, life sciences, or other regulated industries.
  • Experience working within a global cybersecurity governance environment.
  • Experience building, implementing, or maturing enterprise GRC programs and reporting outcomes to leadership.
  • Preferred Certifications
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Internal Auditor (CIA)
  • ISO 27001 Lead Implementer or Lead Auditor
  • Certified Data Privacy Solutions Engineer (CDPSE)
  • Preferred Knowledge & Competencies
  • Cybersecurity governance frameworks (ISO 27001, SOC 2, NIST CSF)
  • Risk assessment and audit management methodologies
  • HIPAA, GDPR, privacy, and regulatory compliance requirements
  • Vendor risk management and continuous monitoring
  • Microsoft Purview, Azure security and compliance concepts, identity and access management, and data loss prevention
  • Strategic thinking, business acumen, executive communication, people development, cross-functional collaboration, and risk-based decision making.

Competencies

  • Be Agile - Innovates and adapts quickly, approaching change with curiosity while persisting through obstacles.
  • Be Customer Centric - Considers the needs, experiences and feedback of customers in all we do.
  • Be People-Focused - Builds trust and collaborates with an inclusive and empathetic approach.
  • Be Performance Driven - Operates with an ownership mindset, driving meaningful outcomes.
  • Live The Schneiders’ Legacy, Our Noble Purpose - Passionately serves Our Mission and Vision, while demonstrating the Immutable Principles.

About Hollister Incorporated

Hollister Incorporated is an independent, employee-owned company that develops, manufactures and markets healthcare products worldwide. The company spearheads the advancement of innovative products for ostomy care, continence care and critical care, and also creates educational support materials for patients and healthcare professionals. Headquartered in Libertyville, Illinois, Hollister has manufacturing and distribution centers on three continents and sells in nearly 80 countries. Hollister is a wholly owned subsidiary of The Firm of John Dickinson Schneider, Inc., and is guided both by its Mission to make life more rewarding and dignified for people who use our products and services, as well as its Vision to grow and prosper as an independent, employee-owned company, and in the process, to become better human beings.

EOE Statement

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status.

Job Req ID: 36464

Hollister Incorporated

About Hollister Incorporated

Hollister Incorporated is an independent, employee-owned company that develops, manufactures, and markets healthcare products and services worldwide. Our Mission is to make life more rewarding and dignified for people who use our products and services. Throughout the company, there is the recognition that Hollister is unique, not only as an independent, employee-owned company but also in its Mission and its commitment to The Immutable Principles on which the company was founded.

Through a shared affirmation that every human being has dignity and intrinsic value, the focal point of everything we do at Hollister is people. At Hollister, we realize that each person who uses our products and services is on a distinct, and often challenging, life journey. In every aspect of what we do, the overriding goal and commitment is to make a difference in that journey.

The Immutable Principle of Dignity of the Person means that we believe in the intrinsic dignity of every individual, independent of any differences. This principle is the foundation of our value system and drives our commitment to inclusion.

Integrity is at the heart of how we do business at Hollister, and throughout the company, there is an unwavering conviction that the ethical way is the only way to conduct our business.

The Immutable Principle of Service, to our customers and to each other, inspires us to strive for unconditional customer satisfaction; serving with humility, compassion, and perseverance.

The Immutable Principle of Stewardship inspires Hollister Associates to act as guardians of the company – ensuring that Hollister will continue to be independent, employee-owned, and faithful to its Mission of making a sustained and meaningful difference in the lives of people around the world.

----

Medical devices sold in the EU are marked with CE symbol or CE 0050 symbol as appropriate. For more information, see www.hollister.com.

Industry
Manufacturing & Production
Company Size
1,001-5,000 employees
Headquarters
Libertyville, Illinois
Year Founded
1921
Social Media