Information Security Analyst 2 - Bright Health Austin, Texas, United States Bookmark Share Print 120 0 0

Listing Description

SCOPE OF ROLE 


Working as part of the information security team within the technology office at Bright Health, the Security Analyst 2 will report directly to the Information Security Manager, GRC and will be responsible for leading the day to day IT compliance, data governance, and IT risk management functions. The role will include primary responsibility for defining, creating, and managing IT and organizational policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational information security practices.


ROLE RESPONSIBILITIES



  • Collaborate to define IT security standards and develop supporting organizational policies.

  • Perform security and compliance assessments on new and existing systems, processes, technology.

  • Support vendor due-diligence process and help to lead and define overall third-party risk management efforts.

  • Work with various business units to ensure controls are adequate, appropriate, and effective.

  • Support internal and external audit process for relevant compliance concerns including SOC2, SOX, HIPAA requirements.

  • Perform business impact analysis and assist with management of IT/InfoSec risk register. Perform periodic gap assessments to validate compliance on an ongoing basis.

  • Stay up to date and informed on developing regulatory concerns and changing IT and information security trends.


EDUCATION, TRAINING, AND PROFESSIONAL EXPERIENCE



  • High school diploma or GED required; Bachelor’s degree in related field or equivalent work experience preferred.

  • Three (3) or more years of relevant information security experience required

  • Experience in governance, risk management, and compliance within the cybersecurity realm including assisting with security and privacy audits, and managing risk management reports, highly preferred.

  • Knowledge and experience in information security and privacy laws, access, release of information, and release control technologies.

  • Knowledge and experience in general electronic health information access, release of information, and release control technologies.

  • Able to analyze the nature and classification of health data and the status of the person or entity requesting the electronic health data. Determine which provisions in HIPAA, SOC2 or security policy apply to the data, determine if other state or federal laws, rules, or regulations are in conflict with the applicable provision of HIPAA, SOC2 or policy; Determine if there are court decisions that address the issue; and recommend procedures or processes that reduce or eliminate the conflicts in law and assure compliance with applicable statutes and/or regulations.

  • Demonstrated organizational, facilitation, presentation, and project management skills with excellent written and verbal communication skills.

  • Ability to develop and/or modify policies and procedures within the confines of current law and management objectives.

  • ISACA, GIAC or (ISC)2 Certification preferred.


Listing Details

  • Citizenship: Not Provided
  • Incentives: Not Provided

 

  • Education: Not Provided
  • Travel: Not Provided
  • Telework: Not Provided



About Us

NinjaJobs is a community-run job platform developed by information security professionals. Our unique approach of focusing strictly on cybersecurity positions allows us to personalize the user experience.

Our Contacts

1765 Greensboro Station Pl.
Suite 900
Tysons Corner Va 22102

(703) 594-7765