See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewUpload your resume and we draft a letter for this exact role, tailored to what it asks for.
The role involves managing IT SOX compliance and financial integrity while overseeing HIPAA and NIS2 regulatory adherence. Additionally, the specialist will lead security awareness programs and conduct strategic risk assessments for new technologies.
As a global medtech company, we are driven by our Vision of changing the trajectory of lives for a new day and our Mission to create ingenious solutions that ignite patient turnarounds. Our relentless commitment to patients and strong legacy of innovation in healthcare are the foundation of our future. If you're looking for a new chance, a new beginning, a new trajectory, LivaNova is where your talent can truly thrive. Join our talented team members worldwide to become a pioneer of tomorrow—because at LivaNova, we don’t just treat conditions — we aspire to alter the course of lives.
The Role
As our Cyber Risk and Compliance Specialist, you will occupy a critical role that is 50% technical auditor and 50% security advocate. You will ensure the integrity of our financial systems through IT SOX compliance while simultaneously maturing our global compliance posture (HIPAA/NIS2) and building a high-integrity security culture through a comprehensive Security Awareness program.
Focus A: IT SOX & Financial Integrity (60%)
• Program Ownership: Lead the IT SOX program and design, implement, and test IT General Controls (ITGCs), IT Application controls (ITACs) and Key Reports (IPE) across our enterprise applications, databases, and infrastructure.
• Audit Management: Serve as the primary "translator" between technical teams and external auditors, ensuring evidence is accurate, timely, and defensible.
• Deficiency Management: Lead the root-cause analysis for any control failures and partner with stakeholders to build long-term, remediation plans.
Focus B: HIPAA, NIS2 & Risk Advisory (30%)
• Healthcare Compliance (HIPAA): Act as the technical SME for the HIPAA Security Rule, ensuring controls protect PHI, including controls monitoring and providing guidance to management for new systems.
• International Resilience (NIS2): Lead the alignment of our security posture with the NIS2 Directive, focusing on key areas in the directive for our European operations.
• Strategic Risk Assessments: Conduct deep-dive risk assessments for new technologies and vendors, ensuring compliance is baked in from the procurement stage.
Focus C: Security Awareness & Training (10%)
• Program Development: Manage the security awareness program that goes beyond "check-the-box" training. You will create engaging content for diverse audiences, from senior leadership to staff.
• Policy Promotion: Translate dense Information Security Policies into digestible, actionable "good practices" for IT administrators and data owners.
• Culture Building: Design targeted communication campaigns to increase internal reporting of security incidents and reinforce the importance of compliance.
Qualifications
• Experience: 5–7 years in IT Audit, IT Compliance, or Cyber Risk.
• Regulatory Knowledge: Expert-level understanding of SOX 404 (ITGCs) and a strong working knowledge of the HIPAA Security Rule and NIS2.
• Frameworks: Proficiency in applying NIST 800-53, ISO 27001, NIST CSF, or COBIT.
• Certifications: CISA is highly preferred; CISSP or CRISC is a major plus.
• Skills: The ability to explain to key stakeholders why a certain control is necessary without sounding like an auditor.
• Technology: Experience with ERP systems, such as SAP (ECC/S4 HANA) etc., cloud environments like Microsoft Azure, AWS etc., GRC systems such as Auditboard, Workiva or other.
Valuing different backgrounds:
LivaNova values equality and diversity. We are committed to ensuring that our recruitment process is fair, transparent and free from unlawful discrimination. Our selection process is driven by the key demands/requirements for the role rather than bias or discrimination on the basis of a candidate’s sex, gender identity, age, marital status, veteran status, non-job-related disability/handicap or medical condition, family status, sexual orientation, religion, color, ethnicity, race or any other legally protected classification.
Notice to third party agencies:
Please note that we do not accept unsolicited resumes from recruiters or employment agencies. In the absence of a signed Recruitment Services Agreement, we will not consider, or agree to, payment of any referral compensation or recruiter fee. In the event that a recruiter or agency submits a resume or candidate without a previously signed agreement, we explicitly reserve the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency.
Beware of Job Scams:
Please beware of potentially fraudulent job postings or suspicious recruiting activity by persons posing as LivaNova recruiters or employees. The scammers may attempt to solicit confidential, personal information, such as a social security number, or your financial information. LivaNova will never ask for fees prior/during/after the application process, nor will we ask for banking details or personal financial information in return for the assurance of employment. If you are concerned that an offer of employment might be a scam or that the recruiter is not legitimate, please verify by searching for “See Open Jobs” on https://www.livanova.com/en-us/careers, and check that all recruitment emails come from an @livanova.com email address.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 217,890+ Jobs in Legal
Answer easy questions
217,890+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”