Senior Security Analyst, Compliance
New
J
JobgetherHealthcare Security
Based in the United StatesFull-TimeSenior
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of professional experience in information security, including 3+ years managing audit activities.
- Required Skills
- HIPAARisk Management
Requirements
- Bachelor’s degree in cybersecurity or a related discipline.
- 5+ years of professional experience in information security.
- 3+ years of experience managing information security audit activities (assessor or assessed).
- Hands-on experience in information security, ideally within a healthcare environment.
- Direct experience with healthcare security and HITRUST requirements.
- Proven ability to create and implement structured processes for ongoing security and compliance programs.
- Experience developing and managing risk-scoring methodologies and establishing baseline risk.
- Strong experience conducting information security and IT risk assessments.
- Knowledge of regulatory controls and frameworks including HIPAA, ISO 27001/27002, PCI, NIST, and related industry practices.
- Experience working with GRC platforms such as Archer.
- Experience in third-party risk management and security assessment activities.
- Strong critical-thinking and critical-assessment capabilities.
Responsibilities
- Lead and mature the information security risk management program, including risk identification, assessment, tracking, remediation, and performance measurement.
- Develop and report security risk and compliance metrics that provide clear visibility into program performance and organizational risk.
- Advance the existing security assessment and reporting program while coordinating audits and assessments such as SOC 2, HITRUST, and client security requests.
- Lead the use of the HITRUST Common Security Framework to assess, measure, and maintain the maturity of the information security program.
- Manage the information security risk register and coordinate the remediation of identified risks with relevant stakeholders.
- Perform information security and information technology risk assessments and apply appropriate risk-scoring methodologies to establish baseline risk levels.
- Respond to client security questionnaires and ad hoc assessment requests.
- Collaborate with IT, Privacy, Compliance, and other business teams to develop and maintain security and document-control content.
- Contribute to third-party risk management activities and evaluate security risks associated with external partners.
- Work with external auditors and internal stakeholders to facilitate evidence collection, assessment activities, remediation, and reporting.
View Full Description & ApplyYou'll be redirected to the employer's site