Senior Cybersecurity Risk Governance Analyst

1 Month ago • 5-8 Years

Job Summary

Job Description

The Senior Cybersecurity Risk Governance Analyst will advise IT and senior leadership on technology-related compliance with laws, regulations, and industry standards. They will assess changes in the regulatory, business, and technology environment and recommend changes to IT policies and controls. The role involves managing IT audit activities, including coordinating schedules, providing documentation, and negotiating issues. The analyst will perform IT risk and controls assurance assessments and recurring assessments of information security functions, identifying improvement areas. They will develop metrics, mentor team members, and optimize processes. The job description also includes responsibilities like providing expertise in complying with relevant regulations (HIPAA, PCI-DSS, etc.), facilitating IT audits, and assessing internal and third-party technology processes. The analyst needs to have the ability to solve problems with a systematic approach, build relationships, and effectively communicate.
Must have:
  • 5-8 years of experience in information security and IT audit facilitation.
  • Working knowledge of industry standards like NIST Cybersecurity Framework.
Good to have:
  • Experience in cloud-based environments (AWS, Azure, GCP).
  • Understanding of attack vectors and methodologies.
  • CISSP, CISM, CISA, CCSA or equivalent certification preferred.

Job Details

Job Summary:

Provide professional expertise and advise IT and senior leadership in matters relating to technology-related compliance with all applicable laws, regulations, industry standards and corporate compliance requirements. Assess changes in the regulatory, business and technology environment and recommend and implement or guide appropriate changes to IT policies, controls, and processes to address security and technology issues. Manage and coordinate IT audit activities by working with IT leaders, team members, external auditors, regulators, and other organizations that review and assess IT processes and controls. Lead and execute cybersecurity risk management activities include internal compliance and risk management activities as well as third-party vendor security oversight and response to customer security inquiries.

Responsibilities:

  • Provide professional expertise and advise leadership in complying with all applicable laws, regulations, and accreditations, including Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI-DSS), FedRAMP, HITRUST, ISO 27001, and EU General Data Protection Regulation (GDPR).
  • Facilitate, oversee, and provide point of contact for all IT audits, assessments, and other reviews of processes and technology. Work with teams to coordinate schedules for activity. Work with IT teams to deliver requested evidence, documentation, conduct interviews, walk through processes, test controls, and negotiate issues. Manage and monitor development and execution of action plans by reviewing and evaluating reports for trends, working with leadership to prioritize findings, and track progress toward agreed upon timeframes. Ensure issues are appropriately documented, relevant, and understood.
  • Perform IT risk and controls assurance assessments of internal and third-party technology-related processes and solutions, working with IT leaders, security architects, Procurement, and other subject matter experts.
  • Perform recurring assessments of information security and technology functions to measure maturity against industry standard baselines, identifying improvement areas, registering risks, and assisting with action plans to move processes to a higher level of maturity.
  • Develop and maintain operational metrics to ensure information security and technology risk and the performance of the IT risk and compliance program is measured sufficiently to enable success.
  • Mentor and coach team members through risk assessments, including scoping of an assessment, resolving conflict, and prioritization of issues. Perform peer review of work product and deliverables.
  • Continuously look to optimize processes, technology and capabilities through tactical and strategic development.
  • Other duties as assigned.

Knowledge and Skills:

  • Strong analytical skills;
  • Demonstration of ability to solve problems using best practices and systematic approach
  • Relationship builder; able to create and maintain a trusted network on all levels;
  • Good communication, influencing and negotiating skills;
  • Written and oral communication skills including the ability to communicate complex technical issues to non-technical staff;
  • Project management and organizational skills;
  • Tactful and diplomatic when engaging with all levels of management always maintaining a
    professional demeanor.

Required Experience:

  • 5-8 years direct experience with information security, IT controls assurance and IT audit facilitation
  • Working knowledge of industry standards such as NIST Cybersecurity Framework, FedRAMP, NIST SP 800-53, ISO 27001, Sarbanes-Oxley, SOC1, SOC2, HIPAA, HITRUST and other similar frameworks.

Preferred Experience:

  • Experience in cloud-based environments for production applications, including Amazon Web Services, Microsoft Azure, GCP or other large-scale cloud deployment.
  • Understanding of attack vectors and methodologies.
  • Ability to weigh business risks and enforce appropriate information security measures.
  • CISSP, CISM, CISA, CCSA or equivalent certification preferred.

Proficient in the use of Microsoft Office (Excel and PowerPoint), Power BI and Power Automate.

GHX: It's the way you do business in healthcare
Global Healthcare Exchange (GHX) enables better patient care and billions in savings for the healthcare community by maximizing automation, efficiency and accuracy of business processes.

GHX is a healthcare business and data automation company, empowering healthcare organizations to enable better patient care and maximize industry savings using our world class cloud-based supply chain technology exchange platform, solutions, analytics and services. We bring together healthcare providers and manufacturers and distributors in North America and Europe - who rely on smart, secure healthcare-focused technology and comprehensive data to automate their business processes and make more informed decisions.

It is our passion and vision for a more operationally efficient healthcare supply chain, helping organizations reduce - not shift - the cost of doing business, paving the way to delivering patient care more effectively. Together we take more than a billion dollars out of the cost of delivering healthcare every year. GHX is privately owned, operates in the United States, Canada and Europe, and employs more than 1000 people worldwide. Our corporate headquarters is in Colorado, with additional offices in Europe.

Disclaimer
Global Healthcare Exchange, LLC and its North American subsidiaries (collectively, “GHX”) provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. All qualified applicants will receive consideration for employment without regard to any status protected by applicable law. This EEO policy applies to all terms, conditions, and privileges of employment, including hiring, training and development, promotion, transfer, compensation, benefits, educational assistance, termination, layoffs, social and recreational programs, and retirement.


GHX believes that employees should be provided with a working environment which enables each employee to be productive and to work to the best of his or her ability. We do not condone or tolerate an atmosphere of intimidation or harassment based on race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. GHX expects and requires the cooperation of all employees in maintaining a discrimination and harassment-free atmosphere. Improper interference with the ability of GHX’s employees to perform their expected job duties is absolutely not tolerated.

Similar Jobs

Universal Music - Senior Vice President, eCommerce & Artist Services

Universal Music

New York, New York, United States (On-Site)
3 Months ago
Kokotree - Marketing Interns

Kokotree

Wilmington, North Carolina, United States (On-Site)
6 Months ago
UPF Industries  - Transportation Analyst

UPF Industries

Grand Rapids, Michigan, United States (On-Site)
1 Week ago
Starschema - Senior Account Executive, Pathology Sales- Oncology Division (Northwest)

Starschema

Salt Lake City, Utah, United States (Remote)
1 Week ago
Biofire DX - Lab Technologist II - QC (Night Shift)

Biofire DX

Salt Lake City, Utah, United States (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Feld Entertainment - Accounts Payable Processor/Vendor Maintenance

Feld Entertainment

Ellenton, Florida, United States (Hybrid)
1 Month ago
quience - Executive Assistant

quience

Palo Alto, California, United States (On-Site)
1 Month ago
Barracuda Networks Inc - Partner Success Manager

Barracuda Networks Inc

Ottawa, Ontario, Canada (Hybrid)
2 Months ago
Dave Ramsey - Client Relationship Manager

Dave Ramsey

Franklin, Tennessee, United States (On-Site)
3 Weeks ago
Motorola solutions - Apprentice Trainee

Motorola solutions

Bengaluru, Karnataka, India (On-Site)
1 Year ago
Haleon - Planning & Forecasting Intern

Haleon

Tres Rios, Cartago Province, Costa Rica (On-Site)
5 Days ago
Scopely - Senior Executive Assistant

Scopely

California, United States (Hybrid)
3 Months ago
FORTUNE - Associate Account Executive

FORTUNE

New York, New York, United States (On-Site)
1 Month ago
Philips - Sales, Clinical Sales Manager, Hospital Respiratory Care (East Zone)

Philips

Boston, Massachusetts, United States (On-Site)
3 Weeks ago
NinjaVan - Intern, Finance

NinjaVan

Subang Jaya, Selangor, Malaysia (Hybrid)
7 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Hyderabad, Telangana, India

Interface AI - SDE II - Engineering Delivery

Interface AI

India (Remote)
2 Weeks ago
Ruselle Investments - Graduate Trainee, Asset Allocation

Ruselle Investments

Mumbai, Maharashtra, India (On-Site)
3 Weeks ago
Qualcomm - V&V Vehicle System Test Lead Engineer

Qualcomm

Bengaluru, Karnataka, India (On-Site)
3 Weeks ago
warner bros games - Staff Software Engineer - Cloud Support and Operations

warner bros games

Bengaluru, Karnataka, India (Hybrid)
2 Months ago
Capgemini - Gen AI Developer

Capgemini

Hyderabad, Telangana, India (On-Site)
2 Weeks ago
Prophecy - Backend Engineer

Prophecy

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Capgemini - Data Engineer

Capgemini

Bengaluru, Karnataka, India (On-Site)
1 Week ago
Green gold animation - Production Coordinator

Green gold animation

Hyderabad, Telangana, India (On-Site)
2 Weeks ago
Accenture - Quality Assurance Analyst

Accenture

Bengaluru, Karnataka, India (On-Site)
3 Weeks ago
Reltio - Advanced Customer Engineer

Reltio

Bengaluru, Karnataka, India (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded

Similar Category Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Global Healthcare Exchange (GHX) enables better patient care and billions in savings for the healthcare community by maximizing automation, efficiency and accuracy of business processes. GHX is a healthcare business and data automation company, empowering healthcare organizations to enable better patient care and maximize industry savings using our world class cloud-based supply chain technology exchange platform, solutions, analytics and services. We bring together healthcare providers and manufacturers and distributors in North America and Europe - who rely on smart, secure healthcare-focused technology and comprehensive data to automate their business processes and make more informed decisions. It is our passion and vision for a more operationally efficient healthcare supply chain, helping organizations reduce - not shift - the cost of doing business, paving the way to delivering patient care more effectively.

Colorado, United States (Remote)

Hyderabad, Telangana, India (On-Site)

Hyderabad, Telangana, India (On-Site)

United States (On-Site)

United States (On-Site)

Hyderabad, Telangana, India (On-Site)

Ontario, California, United States (On-Site)

United States (On-Site)

Hyderabad, Telangana, India (On-Site)

United States (On-Site)

View All Jobs

Get notified when new jobs are added by GHX

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug