Governance Risk and Compliance Analyst Intermediate

Cone Health

Greensboro (NC)

On-site

USD 110,000 - 140,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Cone Health is seeking an Intermediate GRC Analyst to collaborate with process owners, internal and external auditors, and stakeholders to review, monitor, and resolve cybersecurity risk. You will support HITRUST, HIPAA and NIST CSF audits and attestations and help manage IT compliance with SOC2, ISO 27001, PCI-DSS and SOX.

This role contributes to maturing the organization’s compliance program. The ideal candidate has a Bachelor's degree and 5 years of relevant experience, plus CISA

Qualifications

  • Bachelor's Degree or equivalent experience required.
  • Minimum 5 years of experience in governance, risk and compliance.
  • CISA certification required within 12 months.

Responsibilities

  • Lead third party risk assessments and reporting.
  • Manage risk and vulnerability assessments, validation testing, and audits per NIST and HITRUST.
  • Maintain central repository for security risks and audit evidence.
  • Maintain security standards and policies on an annual basis.
  • Manage security awareness training program for associates.
  • Collaborate with legal and compliance teams to align policies and controls with regulations.
  • Conduct internal audits to assess effectiveness of security controls.
  • Perform other duties as assigned.

Skills

Risk assessments
Audits
Security controls
Regulatory compliance
Policy management

Education

Bachelor's Degree

Job description

The Governance, Risk & Compliance (GRC) Analyst - Intermediate will collaborate with process owners, internal auditors, external auditors, and other stakeholders in order to assist in reviewing, monitoring, and resolving cybersecurity risk. This includes helping the organization manage HITRUST, HIPAA and NIST Common Security Framework (CSF) audits and attestations. By supporting the implementation of internal and external assessments, responding to and managing the full lifecycle of compliance audits, and ensuring compliance with existing and emerging regulations and standards including SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities, the Principal GRC Analyst will also contribute to managing the organization's IT compliance program.

Essential Job Function
  • Lead the execution and reporting of outcomes derived from Third Party Risk Assessments.
  • Manage the completion of risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with NIST and HITRUST standards.
  • Manage and monitor a central repository for all security risks and audit evidence.
  • Maintain security standards, policies, and practices on an annual basis to make sure they meet organizational and regulatory requirements.
  • Manage a security awareness training program in order to educate associates about security compliance standards, risk management practices, and ethical behavior.
  • Collaborate with legal and compliance teams to ensure policies and security controls align with regulatory requirements.
  • Conduct internal audits to assess the effectiveness of security controls and identify areas for improvement.
  • Performs other duties as assigned.
Education
  • Required: Bachelor's Degree and/or equivalent experience.
Experience
  • Required: 5 years
Licensure/Certification/Listing
  • Required: Certified Information Systems Auditor(CISA) - Obtain within 12 months.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
GRC Analyst: Cyber Risk & Compliance Expert
GRC Analyst: Cyber Risk & Compliance Expert

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark • Ridgeland (MS)

Hybrid
USD 65,000 - 85,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark Bank • Ridgeland (MS)

Hybrid
USD 60,000 - 80,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000