Information Security Compliance Analyst

Holmes Murphy

West Des Moines (IA)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid parental leave
Tuition reimbursement
401k matching
Generous leave
Volunteer time off
Diversity & inclusion programs
Merit increases
Discretionary bonus

Job summary

Holmes Murphy seeks an Information Security Compliance Analyst II to join the Information Security team in West Des Moines, IA. You will conduct risk assessments, develop security policies, and oversee controls and audits to protect client data.

You will collaborate with vendors, support SOC2 and other audits, mentor junior staff, and contribute to regulatory alignment across the organization.

Qualifications

  • Bachelor's or higher in cybersecurity, technology, information systems, or related field.
  • 3–5 years of information security/compliance experience preferred.
  • Relevant certifications encouraged.

Responsibilities

  • Conduct comprehensive risk assessments and provide detailed reports with mitigations.
  • Lead development and maintenance of policies aligning with regulatory requirements.
  • Oversee risk mitigation controls, risk management, and follow-up audits.
  • Manage vendor risk assessments with third parties to close gaps.
  • Review contracts against compliance standards and HMA requirements.
  • Develop and present compliance metrics to management and auditors.
  • Mentor junior analysts and oversee documentation quality.
  • Lead special compliance projects aligned with strategic goals.
  • Assist with SOC2 and other audits as appropriate.

Skills

Privacy policies
GRC tools
Network security
Cloud security
Application security
SDLC compliance
Automation tools
Risk assessments
Audits

Education

Bachelor's degree in cybersecurity

Tools

Apptega
Archer

Job description

Job Description

We are looking to add an Information Security Compliance Analyst II to join our Information Security team in West Des Moines, Iowa.

Essential Responsibilities
  • Conduct comprehensive risk assessments and provide detailed reports on findings and required mitigations.
  • Lead the development and maintenance of policies, ensuring they address regulatory requirements.
  • Oversee implementation of risk mitigation controls, risk management, and conduct follow-up audits.
  • Manage vendor risk assessments, working with third parties to address any gaps.
  • Review contractual agreements against compliance standards and in alignment with HMA contractual requirements.
Additional Responsibilities
  • Develop and present compliance metrics and reports to senior management and auditors.
  • Mentor junior analysts and oversee documentation quality.
  • Take the lead on special compliance projects, ensuring alignment with strategic goals.
  • Assist with the annual SOC2 audit and other audits or assessments as appropriate.
Knowledge, Skills & Abilities
  • Strong understanding and application of privacy policies, compliance standards and regulations such as NIST, HIPAA, NYDFS or GLBA.
  • Solid knowledge of GRC tools such as Apptega, Archer, etc.
  • Broad technical knowledge of network, cloud, and application security.
  • Ability to conduct internal and external risk assessments and identify various types of risks, such as operational, cybersecurity, regulatory, and reputational risks, and recognize the implications of these risks on the organization.
  • Proficient with mapping and analyzing workflows to identify points of inefficiency, risk, or non‑compliance.
  • Strong understanding of SDLC and experience in compliance integration.
  • Ability to analyze complex issues and implement effective solutions.
  • Experience using automation tools within the work environment.
  • Ability and willingness to consistently participate in internal and external educational opportunities to enhance knowledge of current insurance topics or relevant system improvements.
  • Ability to be available for work on a daily basis and extended hours as necessary.
  • Ability and willingness to pursue relevant designations and/or continuing education, as appropriate.
  • Ability to apply common sense understanding to carry out instructions furnished in written, oral or diagram form. Ability to deal with problems involving several concrete variables in standardized situations.
  • Ability to exert up to 10 pounds of force occasionally, and/or negligible amount of force frequently or constantly to lift, carry, push, or pull objects.
  • Must be knowledgeable of and comply with HMA's Client Privacy Policy, HIPAA regulations and E&O procedures and policies.
Qualifications
  • Education: Associate's or Bachelor's degree in cybersecurity, technology, information systems, or related area or an equivalent combination of education, training, and experience.
  • Experience: 3-5 years of relevant experience in Information Security, compliance, governance, or other security-related fields. Relevant certifications preferred.
  • Ability and willingness to pursue relevant designations and/or continuing education, as appropriate.
Core Competencies
  • Trust: Build trust through honest and caring actions and consistently do the right thing.
  • Communication: Seek understanding to convey messages and information to others in a caring and constructive manner.
  • Client Focus: Establish meaningful relationships with clients (internal and external) by supporting their unique potential and delivering an impactful experience.
  • Teamwork: Contributes to the success of the organization by effectively influencing others and uplifting their experiences and unique strengths.
Technical Competencies
  • Business & Technology Knowledge: Invests in the development of technical knowledge, understands business needs to make informed decisions and deliver technology solutions, including effective related processes and procedures.
  • Problem Solving: Ability to efficiently identify problem(s), leverage resources to determine root cause(s) and propose and implement solutions or make improvements.
Benefits
  • Paid Parental Leave and supportive New Parent Benefits.
  • Company paid continuing Education & Tuition Reimbursement.
  • 401k Profit Sharing.
  • Generous time off practices in addition to paid holidays.
  • Supportive of community efforts with paid Volunteer time off and employee matching gifts to charities.
  • Inclusion & Belonging Programs.
  • Consistent merit increase and promotion opportunities.
  • Discretionary bonus opportunity.

Holmes Murphy & Associates is an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Compliance Analyst
Information Security Compliance Analyst

HMA Group Holdings, LLC • West Des Moines (IA)

On-site
USD 70,000 - 95,000
Health, dental and vision
Paid parental leave
401k profit sharing
+4
InfoSec Compliance Analyst II — Risk & Audit Champion
InfoSec Compliance Analyst II — Risk & Audit Champion

Holmes Murphy • West Des Moines (IA)

On-site
USD 90,000 - 120,000
Paid parental leave
Tuition reimbursement
401k matching
+5
Senior Information Security Analyst
Senior Information Security Analyst

Telligen • West Des Moines (IA)

On-site
USD 110,000 - 150,000
InfoSec Compliance Analyst II: Risk, Governance & SOC2
InfoSec Compliance Analyst II: Risk, Governance & SOC2

HMA Group Holdings, LLC • West Des Moines (IA)

On-site
USD 70,000 - 95,000
Health, dental and vision
Paid parental leave
401k profit sharing
+4
InfoSec Compliance Analyst II: Risk, Policies & Audits
InfoSec Compliance Analyst II: Risk, Policies & Audits

Yourcaptive • West Des Moines (IA)

On-site
USD 70,000 - 100,000
Health insurance
401(k) plan with company match
Tuition reimbursement
+1
Information Security Compliance Analyst
Information Security Compliance Analyst

Yourcaptive • West Des Moines (IA)

On-site
USD 70,000 - 100,000
Health insurance
401(k) plan with company match
Tuition reimbursement
+1
Senior Information Security Analyst
Senior Information Security Analyst

Socket.dev • West Des Moines (IA)

On-site
USD 110,000 - 140,000
Information Security Risk & Vulnerability Management Analyst
Information Security Risk & Vulnerability Management Analyst

Experis • West Des Moines (IA)

On-site
USD 85,000 - 120,000
Systems Administrator
Systems Administrator

Holmes Murphy Insurance • West Des Moines (IA)

On-site
USD 75,000 - 98,000
Health insurance
Dental & vision coverage
401k with match
+2
Information Security Risk and Compliance Analyst
Information Security Risk and Compliance Analyst

Sunflower Bank, N.A. • Denver (CO)

Hybrid
USD 65,000 - 75,000
401(k) Plan
Health/Dental/Vision Insurance
Company‑paid Life Insurance
+5