Information Security Risk Analyst

Gulf Coast Automation Group

Chicago (IL)

Remote

USD 105,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k)
Paid time off

Job summary

TalentFish is seeking an Information Security Risk Analyst to join the GRC team in a Direct Hire role. The position can be remote and focuses on executing and enhancing the organization’s information security risk management program across IT assets, processes, and vendors.

You will lead risk assessments, document findings, and communicate with leadership while aligning with HIPAA, NIST, and healthcare regulations. A strong background in audits and risk reporting is essential.

Qualifications

  • Bachelor's degree required; master's preferred.
  • 3+ years in cybersecurity or risk management; healthcare exp. preferred.
  • Experience with risk assessment methodologies and audits.
  • Familiarity with HIPAA, NIST, and healthcare regulations.
  • CRISC/CISM/CISA or equivalent within 12 months.

Responsibilities

  • Lead and conduct comprehensive information security risk analysis for IT assets, applications, processes, medical devices, and third-party vendors.
  • Evaluate threats and vulnerabilities affecting confidentiality, integrity, and availability of ePHI and sensitive data, aligning with HIPAA and NIST.
  • Lead and manage risk management initiatives, maintain risk register and scoring methodology.
  • Oversee CAPs, penetration testing results, audit findings, and risk treatment outcomes.
  • Collaborate with IT partners to prioritize, implement, and track remediation efforts.
  • Monitor regulatory changes and industry threats to identify emerging risks and mitigate.
  • Contribute to risk reporting, dashboards, and governance reviews.
  • Help develop and improve cybersecurity policies and procedures; evaluate policy exceptions.
  • Enhance cybersecurity awareness by communicating risk insights to technical and non-technical audiences.

Skills

Risk assessment
Regulatory knowledge
HIPAA/NIST
Stakeholder communication
Lead risk assessments
Audit tracking

Education

Bachelor's degree in IS/CS/IT

Tools

Risk management platforms

Job description

Job Title: Information Security Risk Analyst
Primary Location: Remote
Position Type: Direct Hire

Overview

TalentFish is casting a line for an Information Security Risk Analyst. This is a Direct Hire role that can sit remotely. This position exists to play a critical role within the Governance, Risk and Compliance (GRC) team, executing and enhancing the organization's information security risk management program. The analyst will independently conduct risk analysis on information systems, platforms, and processes in accordance with established regulatory requirements, organizational policies, and industry standards, leading and contributing to the identification, assessment, documentation, mitigation, and communication of information security risks across the organization.

What You Bring to the Role. (Ideal Experience)
  • Bachelor's degree required in Information Security, Computer Science, Engineering, Information Technology, or a related field; master's degree preferred.
  • 3+ years of experience in cybersecurity, information security risk management, or audit; healthcare industry experience strongly preferred.
  • Demonstrated experience with risk assessment methodologies, auditing, information security practices, and familiarity with risk management platforms and risk registers.
  • Strong understanding of regulatory compliance and industry best practices for maintaining compliance with HIPAA, NIST, and other relevant healthcare regulations and standards.
  • One or more of the following certifications required, or must be obtained within 12 months of hire: CRISC, CISM, CISA, or any other applicable certification.
  • Ability to lead and structure risk assessments with limited supervision, and manage multiple concurrent assessments and projects in a fast-paced healthcare setting.
  • Experience preparing both detailed technical risk reports and executive-level summaries tailored to varied audiences.
  • Strong written, verbal, and interpersonal communication skills, with the ability to translate technical findings into business-relevant language for leadership audiences.
  • Experience tracking audit findings, third-party vendor risks, and remediation efforts, and analyzing contractual security language to identify risk exposure.
What You'll Do. (Skills Used in this Position)
  • Lead and conduct comprehensive information security risk analysis for IT assets, applications, processes, medical devices, and third-party vendors.
  • Evaluate threats and vulnerabilities affecting the confidentiality, integrity, and availability of ePHI and other confidential or sensitive information, ensuring alignment with HIPAA Security Rule requirements and other applicable regulatory frameworks (e.g., NIST).
  • Lead and manage risk management initiatives based on analysis of outcomes, including maintaining the organization's risk register and scoring methodology.
  • Oversee corrective action plans (CAPs), penetration testing results, audit findings, and risk treatment outcomes.
  • Collaborate with IT partners and key stakeholders to prioritize, implement, and track remediation efforts.
  • Monitor regulatory changes and industry threats to proactively identify emerging risks, recommend mitigation strategies, and document findings.
  • Contribute to risk reporting, including executive dashboards, and participate in risk acceptance processes and governance reviews.
  • Contribute to the development, review, and improvement of cybersecurity policies, standards, and procedures, and evaluate policy exceptions for governance committees.
  • Enhance the organization's cybersecurity awareness and training efforts by communicating risk insights to technical and non-technical audiences.
Compensation Information

The expected salary range for this position is $105,000-$110,000 per year, depending on experience and qualifications. This role also qualifies for comprehensive benefits such as health insurance, 401(k), and paid time off. TalentFish is committed to pay transparency and equal opportunity. The salary range provided is in compliance with applicable state and federal regulations.
This role requires authorization to work in the U.S. without current or future visa sponsorship.
All offers are contingent upon the completion of a background check, which may include but is not limited to reference checks, education verification, employment verification, drug testing, criminal records checks, and any required certifications or compliance requirements based on the end client's background check policies and applicable laws.
TalentFish is an employee-owned company pioneering a new realm in talent acquisition. We are redefining IT staffing by evolving AI, video screening, and our unique platform. TalentFish focuses on providing the best employee, consultant, and client experience possible.
At TalentFish we are an Equal Opportunity Employer; we embrace and encourage diversity!

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Analyst
Senior Security Analyst

Gulf Coast Automation Group • Bloomingdale (IL)

On-site
USD 150,000 - 195,000
Health insurance
401(k)
Paid time off
Remote Information Security Risk Analyst — HIPAA & Compliance
Remote Information Security Risk Analyst — HIPAA & Compliance

Gulf Coast Automation Group • Chicago (IL)

Remote
USD 105,000 - 110,000
Health insurance
401(k)
Paid time off
Information Security Engineer
Information Security Engineer

TalentFish • Schaumburg (IL)

Hybrid
USD 120,000 - 165,000
Health insurance
401(k)
Paid time off
Information Security Risk Analyst
Information Security Risk Analyst

Compunnel, Inc. • San Francisco (CA)

On-site
USD 90,000 - 120,000
Sr Data Analyst Third Party Risk
Sr Data Analyst Third Party Risk

HealthEquity • United States

Remote
USD 92,000 - 125,000
Medical, dental, and vision
HSA contribution and match
401(k) match
+1
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Cybersecurity/Information Security Analyst
Cybersecurity/Information Security Analyst

Bee On The Job • United States

Remote
USD 70,000 - 100,000
Competitive salary
Performance bonuses
Health, dental, and vision insurance
+3
Information Security Analyst
Information Security Analyst

Talener • Boston (MA)

On-site
USD 125,000 - 175,000
Comprehensive benefits
Information Security Analyst
Information Security Analyst

Gifthealth • Columbus (OH)

On-site
USD 73,000 - 86,000