Senior Security Analyst, Compliance

New
J
JobgetherHealthcare Security
Based in the United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
5+ years of professional experience in information security, including 3+ years managing audit activities.
Required Skills
HIPAARisk Management

Requirements

  • Bachelor’s degree in cybersecurity or a related discipline.
  • 5+ years of professional experience in information security.
  • 3+ years of experience managing information security audit activities (assessor or assessed).
  • Hands-on experience in information security, ideally within a healthcare environment.
  • Direct experience with healthcare security and HITRUST requirements.
  • Proven ability to create and implement structured processes for ongoing security and compliance programs.
  • Experience developing and managing risk-scoring methodologies and establishing baseline risk.
  • Strong experience conducting information security and IT risk assessments.
  • Knowledge of regulatory controls and frameworks including HIPAA, ISO 27001/27002, PCI, NIST, and related industry practices.
  • Experience working with GRC platforms such as Archer.
  • Experience in third-party risk management and security assessment activities.
  • Strong critical-thinking and critical-assessment capabilities.

Responsibilities

  • Lead and mature the information security risk management program, including risk identification, assessment, tracking, remediation, and performance measurement.
  • Develop and report security risk and compliance metrics that provide clear visibility into program performance and organizational risk.
  • Advance the existing security assessment and reporting program while coordinating audits and assessments such as SOC 2, HITRUST, and client security requests.
  • Lead the use of the HITRUST Common Security Framework to assess, measure, and maintain the maturity of the information security program.
  • Manage the information security risk register and coordinate the remediation of identified risks with relevant stakeholders.
  • Perform information security and information technology risk assessments and apply appropriate risk-scoring methodologies to establish baseline risk levels.
  • Respond to client security questionnaires and ad hoc assessment requests.
  • Collaborate with IT, Privacy, Compliance, and other business teams to develop and maintain security and document-control content.
  • Contribute to third-party risk management activities and evaluate security risks associated with external partners.
  • Work with external auditors and internal stakeholders to facilitate evidence collection, assessment activities, remediation, and reporting.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now