Overview
Client is seeking a detail-oriented Cybersecurity Analyst to join the Cybersecurity Governance team for a leading healthcare organization. In this role, you will execute Governance, Risk, and Compliance (GRC) functions, evaluating technical and operational risks, ensuring adherence to regulatory frameworks, and coordinating compliance assessments across the enterprise.
Key Responsibilities
- Perform risk assessments covering third-party vendors, policy exceptions, data sharing requests, and travel risks.
- Conduct compliance assessments against established industry frameworks and regulations, including HIPAA and NIST.
- Coordinate evidence collection for internal, external, and SOC 2 audits.
- Respond to incoming customer questionnaires regarding the organization's security and control environment.
- Utilize ServiceNow to track incoming governance requests and manage findings within the enterprise risk register.
- Assist with Identity and Access Management (IAM) governance and controls reviews.
Required Qualifications
- Minimum 3 years of cybersecurity experience focused on Governance, Risk, and Compliance (GRC) or IT Audit.
- Must possess at least one recognized cybersecurity or audit certification (e.g., CISA, CISSP, CRISC).
- Core understanding of security controls, policies, and risk management principles.
- Excellent verbal and written communication skills to effectively engage across business units and external auditors.
- Proficiency with basic enterprise productivity tools (e.g., Microsoft Office Suite).
Preferred Qualifications
- Previous experience working within the healthcare or health insurance sector.
- Familiarity with ServiceNow ticketing and basic workflow processes.
- Hands-on experience mapping controls to NIST and HIPAA frameworks.