Senior Security Analyst

Care New England

Warwick (RI)

On-site

USD 110,000 - 150,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Care New England Health System is seeking a Senior Security Analyst (GRC) to provide governance oversight, enterprise risk management, and compliance activities supporting the health system.

This role ensures alignment with regulatory requirements and industry standards and focuses on policy governance, risk register management, audit coordination, third‑party risk oversight, security awareness programs, phishing oversight, and executive risk reporting.

Qualifications

  • Bachelor’s degree in IT, cybersecurity, information assurance, or related field.
  • 5–7 years IT/security experience with governance, risk, and compliance responsibilities.
  • Healthcare/regulatory environment experience preferred.
  • CISSP, CISM, IAM, or equivalent certification required.
  • Strong HIPAA, HITECH, and PCI DSS knowledge.
  • Excellent written and verbal communication for executive reporting.

Responsibilities

  • Develop, maintain, and manage lifecycle governance of enterprise security policies, standards, and procedures.
  • Ensure alignment of controls with HIPAA and other regulatory frameworks.
  • Support annual enterprise risk assessments and maintain compliance documentation.
  • Maintain and track the enterprise security risk register; coordinate remediation with IT and business stakeholders.
  • Serve as primary liaison for audits, coordinating evidence collection and corrective action plans.
  • Support third-party risk reviews and BAAs.
  • Oversee security awareness and phishing simulation programs; monitor risk metrics and provide executive reporting.
  • Monitor governance performance of tools (EDR, email security, vulnerability management, SIEM); review findings and remediation tracking.
  • Provide incident documentation, post-incident analysis, and governance-based corrective action tracking.
  • Provide security governance consultation for IT initiatives and third-party engagements.
  • Participate in professional development and maintain current industry knowledge.

Skills

Governance & risk management
Regulatory compliance
Policy governance
Executive reporting
Audits coordination
Third-party risk oversight
Security awareness

Education

Bachelor’s degree in IT / Cybersecurity / Information Assurance

Tools

SIEM
EDR
Vulnerability management
Audit tools

Job description

Job Summary

As a member of the Information Security team, the Senior Security Analyst (GRC) is responsible for governance oversight, enterprise risk management, and compliance activities supporting the Care New England Health System.

This role ensures security programs are aligned with regulatory requirements, industry standards, and organizational risk tolerance. Primary areas of responsibility include policy governance, enterprise risk register management, audit coordination, third-party risk oversight, security awareness program management, phishing simulation oversight, and governance-level performance monitoring of security controls and tools.

The Senior Security Analyst does not perform direct engineering functions but provides oversight, performance validation, risk analysis, and executive-level reporting to ensure effective security control implementation and regulatory readiness.

Duties & Responsibilities
  • Develop, maintain, and manage lifecycle governance of enterprise security policies, standards, and procedures.
  • Ensure alignment of administrative, technical, and physical controls with HIPAA and other regulatory frameworks.
  • Support annual enterprise risk assessments and maintain required compliance documentation.
  • Maintain and track the enterprise security risk register; coordinate remediation efforts with IT and business stakeholders.
  • Serve as primary liaison for internal and external audits, coordinating evidence collection and corrective action plans.
  • Support third-party risk reviews and Business Associate Agreement (BAA) evaluations.
  • Oversee the security awareness and phishing simulation program; monitor user risk metrics and provide executive reporting.
  • Monitor governance performance of key security tools (EDR, email security, vulnerability management, SIEM); review findings and validate remediation tracking.
  • Support incident documentation, post-incident analysis, and governance-based corrective action tracking.
  • Provide security governance consultation for IT initiatives and third-party engagements.
  • Participate in professional development and maintain current industry knowledge.
  • Perform other related duties as assigned.
Requirements

Education:

Bachelor’s degree in Information Technology, Cybersecurity, Information Assurance, or related field required.

Experience:

Minimum of five (5) to seven (7) years of IT and/or information security experience, including governance, risk, and compliance responsibilities. Experience in a highly regulated environment required; healthcare experience strongly preferred.

Licenses:N/A

Certifications:CISSP, CISM, IAM, or equivalent industry certification required.

Knowledge, Skills, & Abilities:

Strong knowledge of HIPAA §§164.308, 164.310, and 164.312, HITECH, RI state data protection laws, and PCI DSS.

Demonstrated experience managing governance frameworks and regulatory compliance initiatives.

Strong analytical and problem-solving abilities.

Ability to interpret technical security findings and translate them into business risk terms.

Experience maintaining and tracking enterprise risk registers.

Strong written and verbal communication skills with the ability to present to executive leadership.

Ability to manage multiple priorities and adjust based on risk impact and regulatory deadlines.

Familiarity with EDR, SIEM, vulnerability management, email security, and related platforms from a governance perspective.

Ability to coordinate audit evidence collection and corrective action tracking.

Strong collaboration skills across technical and non-technical teams.

About Us

Care New England Health System (CNE)and its member institutions, Butler Hospital, Women & Infants Hospital, Kent Hospital, VNA of Care New England, Integra, The Providence Center, and Care New England Medical Group, is a trusted, integrated health care organization that fuels the latest advances in medical research, attracts the nation’s top specialty-trained doctors, hones renowned services and innovative programs, and engages in the important discussions people need to have about their health and end-of-life wishes. Care New England is helping to transform the future of health care, providing a leading voice in the ongoing effort to ensure the health of the individuals and communities we serve.

EEO Statements

Americans with Disability Act Statement: External and internal applicants, as well as position incumbents who become disabled must be able to perform the essential job-specific functions either unaided or with the assistance of a reasonable accommodation, to be determined by the organization on a case-by-case basis.

EEOC Statement: Care New England is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status

Ethics Statement: Employee conducts himself/herself consistent with the ethical standards of the organization including, but not limited to hospital policy, mission, vision, and values.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Officer PD
Security Officer PD

Women & Infants Hospital • Providence (RI)

On-site
USD 42,000 - 54,000
Security Officer 24D
Security Officer 24D

Care New England • Providence (RI), Northern (KY)

On-site
USD 42,000 - 52,000
Security Officer 24E
Security Officer 24E

Care New England • Providence (RI), Northern (KY)

On-site
USD 42,000 - 56,000
Security Officer 32E
Security Officer 32E

Women & Infants Hospital • Providence (RI)

On-site
USD 36,000 - 48,000
Sr Clinical Data Analyst
Sr Clinical Data Analyst

Care New England • Warwick (RI)

On-site
USD 95,000 - 125,000
Security Officer 24E
Security Officer 24E

Women & Infants Hospital • Providence (RI)

On-site
USD 40,000 - 52,000
Security Officer 32E
Security Officer 32E

Care New England • Providence (RI), Northern (KY)

On-site
USD 42,000 - 54,000
Security Officer 32N
Security Officer 32N

Women & Infants Hospital • Providence (RI)

On-site
USD 25,000 - 34,000
Clinical Practice Mgr/Clinical Nurse Specialist Mother Baby
Clinical Practice Mgr/Clinical Nurse Specialist Mother Baby

Women & Infants Hospital • Providence (RI)

On-site
USD 110,000 - 150,000
Patient Access Operational Support/Data
Patient Access Operational Support/Data

Care New England Health System • Warwick (RI)

On-site
USD 65,000 - 90,000