GRC Analyst: Cyber Risk & Compliance Expert

Cone Health

Greensboro (NC)

On-site

USD 110,000 - 140,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Cone Health is seeking an Intermediate GRC Analyst to collaborate with process owners, internal and external auditors, and stakeholders to review, monitor, and resolve cybersecurity risk. You will support HITRUST, HIPAA and NIST CSF audits and attestations and help manage IT compliance with SOC2, ISO 27001, PCI-DSS and SOX.

This role contributes to maturing the organization’s compliance program. The ideal candidate has a Bachelor's degree and 5 years of relevant experience, plus CISA

Qualifications

  • Bachelor's Degree or equivalent experience required.
  • Minimum 5 years of experience in governance, risk and compliance.
  • CISA certification required within 12 months.

Responsibilities

  • Lead third party risk assessments and reporting.
  • Manage risk and vulnerability assessments, validation testing, and audits per NIST and HITRUST.
  • Maintain central repository for security risks and audit evidence.
  • Maintain security standards and policies on an annual basis.
  • Manage security awareness training program for associates.
  • Collaborate with legal and compliance teams to align policies and controls with regulations.
  • Conduct internal audits to assess effectiveness of security controls.
  • Perform other duties as assigned.

Skills

Risk assessments
Audits
Security controls
Regulatory compliance
Policy management

Education

Bachelor's Degree

Job description

Cone Health is seeking an Intermediate GRC Analyst to collaborate with process owners, internal and external auditors, and stakeholders to review, monitor, and resolve cybersecurity risk. You will support HITRUST, HIPAA and NIST CSF audits and attestations and help manage IT compliance with SOC2, ISO 27001, PCI-DSS and SOX.

This role contributes to maturing the organization’s compliance program. The ideal candidate has a Bachelor's degree and 5 years of relevant experience, plus CISA

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst: Risk & Compliance Leader
Senior GRC Analyst: Risk & Compliance Leader

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
GRC Analyst: Elevate Security, Compliance & Risk
GRC Analyst: Elevate Security, Compliance & Risk

Visa Hunt • United States

On-site
USD 81,000 - 138,000
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
GRC Analyst: Cyber Risk & Vendor Compliance
GRC Analyst: Cyber Risk & Vendor Compliance

Coretelligent, LLC. • Northern (KY)

Hybrid
USD 70,000 - 88,000
Health insurance
401k
Paid parental leave
+1
GRC Cybersecurity Analyst — Policy, Risk & Compliance
GRC Cybersecurity Analyst — Policy, Risk & Compliance

Central Business Solutions, Inc • Atlanta (GA)

On-site
USD 95,000 - 110,000
Senior InfoSec GRC Analyst – Risk & Compliance
Senior InfoSec GRC Analyst – Risk & Compliance

CareSource • Dayton (OH)

On-site
USD 94,000 - 165,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC & Risk Analyst – SOC 2, ISO 27001, PCI
GRC & Risk Analyst – SOC 2, ISO 27001, PCI

CloudData • United States

On-site
USD 80,000 - 100,000