Назад
Company hidden
4 дня назад

Cyber Security Analyst (GRC)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Security Analyst (GRC) (Cybersecurity Risk Management): Assessing, documenting, and managing cybersecurity risks for a healthcare insurance organization with an accent on governance, third-party risk, regulatory compliance, and control effectiveness. Focus on designing mitigation strategies, managing POA&Ms, developing risk metrics, and supporting NIST, FedRAMP, and HIPAA assessments.

Location: 100% remote

Company

Recruitment provider hiring for a healthcare insurance organization.

What you will do

  • Support the cybersecurity risk management program and collaboration across risk-related teams.
  • Conduct cybersecurity, business, security control, and third-party risk assessments.
  • Identify control gaps, develop mitigation strategies, and manage remediation through closure.
  • Prepare risk assessment reports and maintain assessment documentation and repositories.
  • Design and integrate security solutions addressing enterprise risks and exposures.
  • Develop information security risk metrics, KPIs, and KRIs while supporting vulnerability management and new technology assessments.

Requirements

  • 3+ years of relevant cybersecurity experience, specifically in risk management, including third-party or supplier risk assessments.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field; four additional years of relevant experience may substitute for the degree.
  • At least one required certification: CISSP, CEH, CTIA-ECCOUNCIL, CAP, or EnCase Certified Examiner.
  • Experience with cybersecurity GRC programs and platforms such as Hyperproof, Archer, or ServiceNow GRC.
  • Understanding of the NIST Risk Management Framework, information security risk management methodologies, and the FAIR quantitative model.
  • Knowledge of HIPAA/PHI security standards, network architecture, firewall security, and cybersecurity risk management techniques.

Nice to have

  • SOC reporting or HITRUST knowledge.
  • Background with off-premises or cloud platforms.
  • Experience in the healthcare insurance or payer industry.

Culture & Benefits

  • 100% remote work arrangement.
  • Cross-functional collaboration with TPRM, Procurement, Legal, business stakeholders, analytics, and vulnerability management teams.
  • Work supporting healthcare data protection, regulatory compliance, and enterprise security risk reduction.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →