You are on page 1of 1

Cybersecurity Analyst

Remote (Central Time Zone Hours)

Job Summary:
As the Cybersecurity Analyst, you will own PatientPoint’s Risk Management, and Compliance
(GRC) programs. This mission-critical individual will perform IT risk assessments, manage risk
register items, manage the lifecycle of all risk acceptances and policy exceptions, and support
third-party/vendor risk management.

What You Will Do:


· Own the day-to-day management of the IT GRC program and identify opportunities to
improve existing processes and controls.
· Perform and manage IT Risk assessments and audits to support requirements of various
security frameworks and professionally articulate technical risks in terms of business impact.
· Identify critical risks and issues and drive issue resolution, escalating to senior
management/stakeholders, using contingency planning, and demonstrating appropriate risk
management.
· Manage all Risk Register items by assigning owner, tracking status, and actively managing
remediation.
· Facilitates the overall planning, execution, and reporting of risk assessments and audits to
support CIS, HIPAA, NIST, ISO types of requirements, and other compliance-related initiatives.
· Develop vendor assessment standards and processes for 3rd party technology vendors.
· Participating in incident response activities in the event of a cybersecurity incident.
· Assessing the impact of incidents and initiating appropriate remediation measures
· Conducting audits and assessments to verify adherence to security controls.
· Participating in internal and external security audits and assessments.
· Generating regular reports on the organization's risk posture and security status.
· Presenting findings and recommendations to management and stakeholders.

What We Need:
· 5+ years of professional information technology experience.
· 2+ years of experience in an IT security position with oversight of GRC process.
· Experience building and managing GRC frameworks and processes required.
· Experience with Agile Project Management methodologies.
· Experience using a ticketing system such as JIRA or ServiceNow.
· Strong, practical experience working in a HIPAA environment.
· Direct experience with implementation and management of security frameworks such as
ISO 27001, NIST, or CSF.

Desired Qualifications:
· Experience with GDPR, CCPA, VCDPA or related State or Federal privacy laws.
· One or more security related certifications such as Certified Information Systems Auditor
(CISA), or Certified Internal Auditor (CIA), Certified Information Systems Security Professional
(CISSP), Certified Information Systems Auditor (CISM), Certified Ethical Hacking (CEH), GIAC
Information Security Professional (GISP).

What You will Need to Succeed


· Self-motivation, strong ambition, and interest in directly impacting business results.
· Resourcefulness, multi-tasking skills and creative problem-solving skills.
· Resiliency and ability to overcome challenges, sound business judgment.
· Passion for relationship building and building trusted partnerships.

You might also like