Healthmap Solutions logo

Senior Security Analyst, Compliance

Healthmap Solutions

On-siteseniorPosted 6h ago

Job description

Description

Position at Healthmap Solutions

Company Background

Healthmap Solutions is the future of specialty health management that focuses on progressive diseases, with a particular expertise in kidney health populations. Healthmap Solutions uses clinical big data resources and high-powered analytics to power complex specialty health management programs. Healthmap Solutions is a diverse, growing company committed to our clients and our employees. We are champions for better health, for those who need us most.

Position Summary

Healthmap Solutions is seeking a Governance, Risk, and Compliance (GRC) Senior Analyst to drive the day-to-day activity in our information security governance, risk, and compliance program. The ideal candidate will be responsible for driving risk management and assessment efforts ensuring the integrity of PHI and adherence to information security policies, procedures, and control systems among Healthmap Solutions’ employees, associates, contractors, and business partners. This candidate will be tasked with creating IS GRC process, leveraging the in-place foundation to construct a solid and efficient program.

The Governance, Risk, and Compliance (GRC) Senior Analyst will work closely with IT, Privacy, Compliance, business clients, and external auditors to ensure Healthmap Solutions data control standards are met. The applicant chosen will be responsible for the completion of our HITRUST and SOC2 reports on an annual basis, management of the risk register, and corresponding remediation of risks identified within the register.

Responsibilities

  • Mature and lead Healthmap Solutions’ Information Security Risk Management program and performance metrics reporting

  • Advance the existing assessment reporting program while driving audits such as SOC2, HITRUST, and Client requests

  • Lead Healthmap Solutions use of HITRUST Common Security Framework to measure and maintain the maturity of the company’s security program

  • Mature and manage Healthmap Solutions’ Information Security Risk Management program and performance metrics reporting

  • Respond to client assessment ad hoc questionnaires and track this effort

  • Collaborate with other Healthmap Solution teams to conceptualize and create document control content and ensure compliance with the HITRUST security framework

  • Other related duties as assigned

Requirements

  • Bachelor’s degree in Cyber Security (or) related degree and experience

  • Hands-on security professional

  • Healthcare and HITRUST experience

  • Five (5) + years’ experience in Information Security

  • Three (3) + years managing Information Security audit activities both as assessor and/or as assessed

  • Proven ability to create process for programmatic work

  • Experience managing risk scoring methodologies to establish baseline risk scores against risk appetite

  • Effective at performing Information Security/Information Technology risk assessments

  • Experience with regulatory controls and industry best practice frameworks such as HIPAA, ISO27001/2, PCI, NIST, etc.

  • Experience with GRC tools such as Archer

  • Security GRC professional

  • HITRUST certification, preferred

  • Contract review experience, preferred

  • CISSP, CISM, GIAC, or other information related certifications, preferred

Skills

  • Calm and confident under pressure

  • Collaboration and Conflict management

  • Proven critical thinking/critical assessment capabilities

  • Demonstrated experience in the third-party risk management line of work

  • Ability to effectively prioritize and execute tasks in a high-pressure environment

  • Ability to manage multiple work streams simultaneously

  • Proven ability to work independently and as part of a team

  • Strong verbal and written communications skills

  • Excellent Customer service skills

Travel

Limited Travel, Scheduled per needs of the business

Americans with Disability Specifications

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

As an Equal Opportunity Employer, we will not discriminate against any job candidate or employee due to age, race, religion, ethnicity, national origin, gender, gender identity/expression, sexual orientation, disability, familial status, veteran status, marital status, parental status, or pregnancy. In our innovative and inclusive workplace, we prohibit discrimination and harassment of any kind.