Enable job alerts via email!

Security Risk Analyst

NYC Health + Hospitals

New York (NY)

Hybrid

USD 75,000 - 140,000

Full time

16 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Security Risk Analyst to enhance its information security and risk management services. This role involves translating IT risk requirements into actionable strategies, conducting thorough risk assessments, and ensuring compliance with key regulations. The ideal candidate will possess a strong background in the healthcare sector, with expertise in HIPAA and data privacy issues. Join a dynamic team dedicated to empowering New Yorkers to live healthier lives while contributing to a robust security framework that safeguards sensitive information. This is an exciting opportunity to make a significant impact in a vital public health organization.

Benefits

Comprehensive Health Benefits
Retirement Savings and Pension Plans
Loan Forgiveness Programs
Paid Holidays and Vacation
Tuition Assistance
Child Care Support
Disability Insurance

Qualifications

  • 5 years experience in data processing and applications.
  • Broad knowledge of security tools and compliance regulations.

Responsibilities

  • Support Information Security by maintaining risk management framework.
  • Conduct risk assessments and manage threat landscape.

Skills

Information Security
Risk Management
Data Privacy
HIPAA Compliance
Analytical Skills

Education

Baccalaureate Degree in Computer Science or related field
CISSP, CISA, CRISC or relevant security qualification

Tools

GRC Tool

Job description

NYC Health + Hospitals provided pay range

This range is provided by NYC Health + Hospitals. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.

Base pay range

$75,332.00/yr - $140,000.00/yr

Direct message the job poster from NYC Health + Hospitals

*****This position is 80% remote and 20% on-site *******

About NYC Health + Hospitals

Empower Every New Yorker — Without Exception — to Live the Healthiest Life Possible

NYC Health + Hospitals is the largest public health care system in the United States. We provide essential outpatient, inpatient and home-based services to more than one million New Yorkers every year across the city’s five boroughs. Our large health system consists of ambulatory centers, acute care centers, post-acute care/long-term care, rehabilitation programs, Home Care, and Correctional Health Services. Our diverse workforce is uniquely focused on empowering New Yorkers, without exception, to live the healthiest life possible.

At NYC Health + Hospitals, our mission is to deliver high quality care health services, without exception. Every employee takes a person-centered approach that exemplifies the ICARE values (Integrity, Compassion, Accountability, Respect, and Excellence) through empathic communication and partnerships between all persons.

Job Description

The Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the technology-focused analysts, engineers and administrators in the IT organization. The Security Risk Analyst must be able to translate the IT-risk requirements and constraints of the business into technical control requirements and specifications, as well as develop metrics for ongoing performance measurement and reporting. The Security Risk Analyst coordinates the IT organization's technical activities to implement and manage security.

The Security Risk Analyst is part of the Enterprise Information Technology Services, Information Security and Risk Management team and will work at an enterprise level to ensure a consistent delivery of information security and risk management services. This individual will act as a subject matter expert to the assigned business units on matters regarding information security and compliance with HIPAA, Joint Commission, DSRIP, COBIT, and state privacy laws.

Duties & Responsibilities

  • Support Information Security and Risk Management by maintaining and enforcing the Information Security and risk management framework/methodology, including execution of risk analysis and risk mitigation strategies.
  • Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the CISO with a realistic overview of risks and threats in the enterprise environment.
  • Exhibit best practice risk management skills through effective internal risk controls, risk monitoring, risk assessment and improvement of risk management processes.
  • Document and maintain the enterprise security risk governance methodology and risk management policy, process, and procedure.
  • Work with various stakeholders to identify information asset owners to classify data and systems as part of a control framework implementation.
  • Organize and perform the enterprise security risk assessment and gap analysis for all technologies, products, and functions introduced, including maintaining risk project work plans to measure and manage progress.
  • Track and document all internal risk reviews, assessments, risk acceptances, and security exceptions in a GRC tool.
  • Work with the enterprise architecture team to ensure that there is a convergence of business, technical and security requirements; liaise with IT management to align existing technical installed base and skills with future architectural requirements.
  • Develop a strong working relationship with the security engineering team to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirements
  • Serve as the information security liaison and subject matter expert for all relevant EMR and PHI related security risk.
  • Conduct or participate in all relevant audits and risk assessment activities (whether operational risk, legal/compliance risk, reputational risk, or information security risk).
  • Aid in the planning and execution of risk remediation activities including the identification of practical, cost effective solutions.
  • Facilitate team meetings between stakeholders, project leaders, and the Information Technology teams.
  • Attend regular team, management, and project meetings and provide both verbal and written reports to the Leadership Team as required. This may include coordination with and support of an Operational Risk Committee.
  • Keep informed on current threats and industry regulations.

Minimum Qualifications

1. A Baccalaureate Degree from an accredited college or university with a major in Computer Science, Systems Engineering, applied Mathematics, Business Administration, Economics/Statistics, Telecommunications, Data Communications, or a related field of study; and

2. Five (5) years of progressive, responsible experience in the field of data processing, computer systems and applications.

Operations Specialty requires supervisory experience (5 years).

Network Services requires a telecommunications background and experience.

3. Broad knowledge and expertise in the characteristics of computers, peripheral devices, communications systems and hardware capabilities, programming languages, E.D.P. applications, systems analysis methodology, data management and retrieval techniques; or

4. A satisfactory equivalent combination of training, education and experience.

Department Preferences

Certification(S)/NYS Licenses/Education:

  • A bachelor's degree in information systems or equivalent experience
  • CISSP, CISA, CRISC or other relevant security qualification

Knowledge, Skills, Abilities and other Requirements:

  • Healthcare industry experience required with understanding of EMR systems and data privacy issues related to PHI
  • Experience with reviewing IT solution requirements and security controls implementation
  • A strong understanding of the business impact of security tools, technologies and policies.
  • Knowledge and experience working with a GRC tool
  • Strong working knowledge of HIPAA, Joint Commission, CMS, and other regulatory frameworks pertinent to the healthcare industry
  • Working knowledge of information security frameworks such as NIST CSF, HITECH, ISO27001/27002, PCI DSS and COBIT
  • Experience in conducting and responding to information security assessments and audits.
  • Strong analytical skills and the ability to resolve complex security vulnerabilities and design compensating controls

Other Preferred Skills:

  • Must possess a high degree of integrity and trust along with the ability to work independently
  • Participate in special projects as needed and perform other duties as assigned
  • Must be able to work independently as well as work as part of a fast-moving team
  • Must be able to work at various locations, when necessary, along with working various shifts

Years of Experience:

  • A minimum of seven years of IT experience, least 5 years dedicated to IT Security Risk Management, Risk Audit/Assessment, and/or Security and/or Data Privacy Investigation least two years in a supervisory capacity.

How To Apply

If you wish to apply for this position, please apply online by clicking the "Apply for Job" button.

If applying online, please include your cover letter in the same file attachment with your uploaded resume.

NYC Health and Hospitals offers a competitive benefits package that includes:

  • Comprehensive Health Benefits for employees hired to work 20+ hrs. per week
  • Retirement Savings and Pension Plans
  • Loan Forgiveness Programs for eligible employees
  • Paid Holidays and Vacation in accordance with employees' Collectively bargained contracts
  • College tuition discounts and professional development opportunities
  • Multiple employee discounts programs

Note: Candidates selected for a position are required to come to NYC as part of their onboarding.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Hospitals and Health Care

Referrals increase your chances of interviewing at NYC Health + Hospitals by 2x

Inferred from the description for this job

Medical insurance

Vision insurance

401(k)

Pension plan

Child care support

Paid maternity leave

Paid paternity leave

Student loan assistance

Tuition assistance

Disability insurance

Get notified about new Risk Analyst jobs in New York City Metropolitan Area.

New York, NY $200,000.00-$250,000.00 3 weeks ago

Global Investment Research, Global Macro Research, Structured Credit Research, Analyst
Equity Research Analyst, Global Allocation – Associate

New York City Metropolitan Area $175,000.00-$250,000.00 2 weeks ago

Senior Manager, U.S. Counterparty Credit Risk - Hedge Funds

New York, NY $117,400.00-$224,700.00 1 week ago

Analyst - Finance (Financial Planning & Analysis)

New York City Metropolitan Area $100,000.00-$130,000.00 3 weeks ago

New York, NY $118,000.00-$172,000.00 1 week ago

New York, NY $190,000.00-$240,000.00 4 days ago

Portfolio Manager & Credit Analyst, Treasury

New York, NY $85,900.00-$179,500.00 4 days ago

New York, NY $150,000.00-$185,000.00 2 weeks ago

Manager, U.S. Leveraged Finance Credit Risk
Global Treasury – Treasury Capital Markets – Analyst (Fund Finance)
Credit Risk Manager, VP - Leveraged Finance

New York, NY $150,000.00-$200,000.00 1 week ago

New York, NY $170,000.00-$210,000.00 1 month ago

New York City Metropolitan Area $225,000.00-$275,000.00 3 days ago

New York City Metropolitan Area 1 day ago

VP/Director, Fintech Third-Party Risk Manager

New York City Metropolitan Area 1 week ago

New York City Metropolitan Area 5 days ago

New York City Metropolitan Area 6 days ago

New York, NY $163,300.00-$236,800.00 3 days ago

Oliver Wyman - Research Analyst Financial Services - NY

New York City Metropolitan Area 1 hour ago

New York, NY $150,000.00-$250,000.00 3 days ago

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Fraud Risk Analyst

Zip Co

New York

Remote

USD 108,000 - 130,000

4 days ago
Be an early applicant

Information Risk Analyst - GRC

MongoDB

New York

Remote

USD 76,000 - 149,000

Yesterday
Be an early applicant

RISK ADJUSTMENT CODING SPECIALIST, CONTRACTOR (WITH FULL-TIME HIRE POTENTIAL)

Yuvo Health

New York

Remote

USD 60,000 - 80,000

Yesterday
Be an early applicant

CREDIT RISK ANALYST, FINANCIAL INSTITUTIONS

AscendHire

New York

Hybrid

USD 70,000 - 80,000

Yesterday
Be an early applicant

Cyber Risk Analyst - Remote

501 CSAA Insurance Services, Inc.

Town of Texas

Remote

USD 80,000 - 110,000

Yesterday
Be an early applicant

Senior Information Security Risk Analyst

System One

Vienna

Remote

USD 80,000 - 120,000

2 days ago
Be an early applicant

Risk Analyst (Fraud Prevention)

Binance

Remote

USD 60,000 - 100,000

2 days ago
Be an early applicant

Senior Risk Analyst, Collections Strategy New Irving, Texas, United States New York, New York[...]

Octane Lending

New York

Remote

USD 60,000 - 80,000

30+ days ago

Privacy Analyst - Risk

Mayo Clinic Healthcare

Rochester

Remote

USD 78,000 - 111,000

Today
Be an early applicant