Governance, Risk and Compliance Analyst Senior

Cone Health

Greensboro (NC)

On-site

USD 90,000 - 130,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Cone Health is seeking a Senior GRC Analyst to collaborate with process owners, internal and external auditors, and stakeholders to review, monitor, and resolve cybersecurity risk. You will support HITRUST, HIPAA and NIST CSF audits and attestations, respond to assessments, and ensure compliance with SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities.

The role involves implementing internal and external assessments, managing the lifecycle of audits, and contributing to the IT compliance

Qualifications

  • Bachelor's degree or equivalent experience is required.
  • 7+ years of experience is required.
  • CISM certification is required.

Responsibilities

  • Lead the execution and reporting of outcomes derived from Third Party Risk Assessments.
  • Manage the completion of risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with NIST and HITRUST standards.
  • Manage and monitor a central repository for all security risks and audit evidence.
  • Maintain security standards, policies, and practices on an annual basis to meet organizational and regulatory requirements.
  • Manage a security awareness training program to educate associates about security compliance standards, risk management practices, and ethical behavior.
  • Collaborate with legal and compliance teams to ensure policies and security controls align with regulatory requirements.
  • Conduct internal audits to assess the effectiveness of security controls and identify areas for improvement.
  • Performs other duties as assigned.

Skills

Risk assessments
Audits
Security controls
Compliance programs
Security awareness

Education

Bachelor's degree or equivalent experience

Job description

The Governance, Risk & Compliance (GRC) Analyst - Senior will collaborate with process owners, internal auditors, external auditors, and other stakeholders in order to assist in reviewing, monitoring, and resolving cybersecurity risk. This includes helping the organization manage HITRUST, HIPAA and NIST Common Security Framework (CSF) audits and attestations. By supporting the implementation of internal and external assessments, responding to and managing the full lifecycle of compliance audits, and ensuring compliance with existing and emerging regulations and standards including SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities, the Principal GRC Analyst will also contribute to managing the organization's IT compliance program.

Essential Job Function:
  • Lead the execution and reporting of outcomes derived from Third Party Risk Assessments.
  • Manage the completion of risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with NIST and HITRUST standards.
  • Manage and monitor a central repository for all security risks and audit evidence.
  • Maintain security standards, policies, and practices on an annual basis to make sure they meet organizational and regulatory requirements.
  • Manage a security awareness training program in order to educate associates about security compliance standards, risk management practices, and ethical behavior.
  • Collaborate with legal and compliance teams to ensure policies and security controls align with regulatory requirements.
  • Conduct internal audits to assess the effectiveness of security controls and identify areas for improvement.
  • Performs other duties as assigned.
Education:
  • Required: Bachelor's Degree and/or equivalent experience.
Experience:
  • Required: 7 years
Licensure/Certification/Listing:
  • Required: Certified Information Security Manager (CISM)certification.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Sr. IT Security Analyst
Sr. IT Security Analyst

The Marzetti Company • Columbus (OH)

On-site
USD 90,000 - 120,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade • Oxford (MS)

On-site
USD 110,000 - 160,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Information Security Sr Anlyst
Information Security Sr Anlyst

TALENT Software Services • Cary (NC)

On-site
USD 100,000 - 130,000