Enable job alerts via email!

Senior Cybersecurity Risk Governance Analyst Hyderabad, Telangana, India

Ghx Llc

Louisville (KY)

On-site

USD 90,000 - 130,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in healthcare technology is seeking a Senior Cybersecurity Risk Governance Analyst to provide expertise in compliance and risk management. This role involves advising IT leadership, managing audits, and ensuring adherence to industry standards. The ideal candidate will have substantial experience in information security and IT controls, with a focus on optimizing processes and technology.

Qualifications

  • 5-8 years of experience in information security and IT audit facilitation.
  • Working knowledge of NIST, ISO 27001, and HIPAA standards.
  • Experience in cloud environments like AWS and Azure is preferred.

Responsibilities

  • Advise leadership on compliance with laws and regulations.
  • Facilitate IT audits and assessments, coordinating with teams.
  • Perform risk assessments and develop operational metrics.

Skills

Analytical skills
Problem-solving
Communication
Project management

Education

Bachelor's degree in Information Technology or related field
CISSP, CISM, CISA, CCSA or equivalent certification

Tools

Microsoft Office
Power BI
Power Automate

Job description

Senior Cybersecurity Risk Governance Analyst

Job Summary:

Provide professional expertise and advise IT and senior leadership in matters relating to technology-related compliance with all applicable laws, regulations, industry standards and corporate compliance requirements. Assess changes in the regulatory, business and technology environment and recommend and implement or guide appropriate changes to IT policies, controls, and processes to address security and technology issues. Manage and coordinate IT audit activities by working with IT leaders, team members, external auditors, regulators, and other organizations that review and assess IT processes and controls. Lead and execute cybersecurity risk management activities include internal compliance and risk management activities as well as third-party vendor security oversight and response to customer security inquiries.

Responsibilities:

  • Provide professional expertise and advise leadership in complying with all applicable laws, regulations, and accreditations, including Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI-DSS), FedRAMP, HITRUST, ISO 27001, and EU General Data Protection Regulation (GDPR).
  • Facilitate, oversee, and provide point of contact for all IT audits, assessments, and other reviews of processes and technology. Work with teams to coordinate schedules for activity. Work with IT teams to deliver requested evidence, documentation, conduct interviews, walk through processes, test controls, and negotiate issues. Manage and monitor development and execution of action plans by reviewing and evaluating reports for trends, working with leadership to prioritize findings, and track progress toward agreed upon timeframes. Ensure issues are appropriately documented, relevant, and understood.
  • Perform IT risk and controls assurance assessments of internal and third-party technology-related processes and solutions, working with IT leaders, security architects, Procurement, and other subject matter experts.
  • Perform recurring assessments of information security and technology functions to measure maturity against industry standard baselines, identifying improvement areas, registering risks, and assisting with action plans to move processes to a higher level of maturity.
  • Develop and maintain operational metrics to ensure information security and technology risk and the performance of the IT risk and compliance program is measured sufficiently to enable success.
  • Mentor and coach team members through risk assessments, including scoping of an assessment, resolving conflict, and prioritization of issues. Perform peer review of work product and deliverables.
  • Continuously look to optimize processes, technology and capabilities through tactical and strategic development.
  • Other duties as assigned.

Knowledge and Skills:

  • Strong analytical skills;
  • Demonstration of ability to solve problems using best practices and systematic approach
  • Relationship builder; able to create and maintain a trusted network on all levels;
  • Good communication, influencing and negotiating skills;
  • Written and oral communication skills including the ability to communicate complex technical issues to non-technical staff;
  • Project management and organizational skills;
  • Tactful and diplomatic when engaging with all levels of management always maintaining a
    professional demeanor.

Required Experience:

  • 5-8 years direct experience with information security, IT controls assurance and IT audit facilitation
  • Working knowledge of industry standards such as NIST Cybersecurity Framework, FedRAMP, NIST SP 800-53, ISO 27001, Sarbanes-Oxley, SOC1, SOC2, HIPAA, HITRUST and other similar frameworks.

Preferred Experience:

  • Experience in cloud-based environments for production applications, including Amazon Web Services, Microsoft Azure, GCP or other large-scale cloud deployment.
  • Understanding of attack vectors and methodologies.
  • Ability to weigh business risks and enforce appropriate information security measures.
  • CISSP, CISM, CISA, CCSA or equivalent certification preferred.

Proficient in the use of Microsoft Office (Excel and PowerPoint), Power BI and Power Automate.

GHX: It's the way you do business in healthcare
Global Healthcare Exchange (GHX) enables better patient care and billions in savings for the healthcare community by maximizing automation, efficiency and accuracy of business processes.

GHX is a healthcare business and data automation company, empowering healthcare organizations to enable better patient care and maximize industry savings using our world class cloud-based supply chain technology exchange platform, solutions, analytics and services. We bring together healthcare providers and manufacturers and distributors in North America and Europe - who rely on smart, secure healthcare-focused technology and comprehensive data to automate their business processes and make more informed decisions.

It is our passion and vision for a more operationally efficient healthcare supply chain, helping organizations reduce - not shift - the cost of doing business, paving the way to delivering patient care more effectively. Together we take more than a billion dollars out of the cost of delivering healthcare every year. GHX is privately owned, operates in the United States, Canada and Europe, and employs more than 1000 people worldwide. Our corporate headquarters is in Colorado, with additional offices in Europe.

Disclaimer
Global Healthcare Exchange, LLC and its North American subsidiaries (collectively, “GHX”) provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. All qualified applicants will receive consideration for employment without regard to any status protected by applicable law. This EEO policy applies to all terms, conditions, and privileges of employment, including hiring, training and development, promotion, transfer, compensation, benefits, educational assistance, termination, layoffs, social and recreational programs, and retirement.


GHX believes that employees should be provided with a working environment which enables each employee to be productive and to work to the best of his or her ability. We do not condone or tolerate an atmosphere of intimidation or harassment based on race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. GHX expects and requires the cooperation of all employees in maintaining a discrimination and harassment-free atmosphere. Improper interference with the ability of GHX’s employees to perform their expected job duties is absolutely not tolerated.

Create a Job Alert

Interested in building your career at GHX? Get future opportunities sent straight to your email.

Apply for this job

indicates a required field

First Name *

Last Name *

Email *

Phone

Resume/CV

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

Enter manually

Accepted file types: pdf, doc, docx, txt, rtf

LinkedIn Profile

Website

Candidate Location *

Website

Current CTC *

Expected CTC *

Notice Period *

Current Location *

What city do you live in? *

When you apply to a job on this site, the personal data contained in your application will be collected by the GHX Compliance & Privacy Officer (CPO), which is located at 1315 W Century Dr., STE 100, Louisville, CO 80027 and can be contacted by emailing compliance@ghx.com . Your personal data will be processed for the purposes of managing GHX's recruitment related activities, which include setting up and conducting interviews and tests for applicants, evaluating and assessing the results thereto, and as is otherwise needed in the recruitment and hiring processes. Such processing is legally permissible under Art. 6(1)(f) of Regulation (EU) 2016/679 (General Data Protection Regulation) as necessary for the purposes of the legitimate interests pursued by the CPO, which are the solicitation, evaluation, and selection of applicants for employment.Your personal data will be shared with Greenhouse Software, Inc., a cloud services provider located in the United States of America and engaged by GHX to help manage its recruitment and hiring process on the CPO's behalf. Accordingly, if you are located outside of the United States, your personal data will be transferred to the United States once you submit it through this site. Because the European Union Commission has determined that United States data privacy laws do not ensure an adequate level of protection for personal data collected from EU data subjects, the transfer will be subject to appropriate additional safeguards. You can obtain a copy of the standard contractual clauses by contacting us at humanresources@ghx.com.Your personal data will be retained by GHX as long as GHX determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have to right to data portability. In addition, you may lodge a complaint with an EU supervisory authority. * Select...

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.