Talent.com
IS Security GRC Analyst
IS Security GRC AnalystBrown University Health • Providence, RI, United States
IS Security GRC Analyst

IS Security GRC Analyst

Brown University Health • Providence, RI, United States
1 day ago
Job type
  • Full-time
Job description

SUMMARY :

The IS Security Governance, Risk & Compliance (GRC) Analyst is a critical member of the Chief Information Security Officer's (CISO's) team and reports to the Director of Information Security. The IS Security GRC Analyst plays a pivotal role in the Information Security team, driving the development and implementation of the organization’s security governance framework. This position is responsible for creating and managing security metrics, facilitating exception requests, conducting vendor security risk assessments, and maintaining key documentation such as information security policies and the risk register. The role ensures that the healthcare organization maintains compliance with regulatory requirements, industry standards, and internal policies while proactively managing security risks.

PRINCIPAL DUTIES AND RESPONSIBILITIES :

Brown University Health employees are expected to successfully role model the organization’s values of Compassion, Accountability, Respect, and Excellence as these guide our everyday actions with patients, customers and one another.

Develop, review, and update information security policies, procedures, and standards to reflect best practices, regulatory requirements, and evolving threats.  Monitor regulatory changes and industry trends to ensure ongoing compliance and policy relevance. Maintain crosswalks between organization policies and regulatory standards.

Assist in ensuring compliance with relevant regulatory standards, including HIPAA, HITECH, PCI-DSS, NIST, and other applicable frameworks.

Design and implement metrics to measure the effectiveness of the information security program, including incident trends, security stack deployment, and risk levels.  Develop dashboards and reports for senior management, detailing the status of the information security program and highlighting areas for improvement.  Continuously refine metrics to provide meaningful insights into the organization’s security posture.

Facilitate the process for security policy exceptions, including reviewing requests, meeting with business owners, assessing risk, and documenting approvals.  Ensure that exception requests are properly tracked, periodically reviewed, and managed according to organizational policies.

Conduct and / or oversee vendor security risk assessments, evaluating third-party practices for alignment with the organization’s security requirements.  Monitor and reassess vendor risks regularly to account for changes in services, technology, or vendor practices.

Identify opportunities for improvement in governance, risk, and compliance practices, recommending updates to processes and controls.  Stay current with emerging security risks, regulatory requirements, and best practices to ensure the ongoing effectiveness of the GRC program.

Provides expert level guidance to IT staff and the business regarding all Information Security policies, standards, processes, and procedures.

Works with various infrastructure teams and business units to ensure policy compliance and adherence to security best practices.

Participates in security projects and provides expert guidance on security policy, process, and procedures for other IT projects.

Attends various IT meetings that require an IS Security representative.

Participates in compliance / audit activities as requested by internal and external auditors.

Supports Brown University Health’s Legal e-discovery processes to include identification, collection, preservation and processing of relevant data.

Manages Governance, Risk and Compliance platform.

Maintains work effort status within SLA’s on Brown University Health’s Service Desk and Task Management Platforms.

Performs other duties as assigned.

EXPERIENCE :

A minimum of 10 years of IS experience, with 5 years in an information security role.

A bachelor's degree in information systems or equivalent work experience; an M.B.A. or M.S. in information security is preferred.

Certifications Required (3 or more – Security+, CCSP, CISA, CISM, CRISC, CISSP, GIAC, Network+, ITIL, Project+)

Strong understanding of regulatory requirements, security frameworks, and risk management methodologies (e.g., HIPAA, HITECH, NIST, ISO 27001).

Experience with security metrics development, policy management, vendor risk assessments, and risk register maintenance.

Excellent written and verbal communication skills, with the ability to present complex security concepts to diverse audiences.

Working knowledge of IT / network and cloud architectures sufficient to map controls, evidence, and risks.

Proficiency with O365; advanced Excel and Power BI for dashboards; Visio for process & control maps.

Strong written and verbal communication skills.

Ability to communicate security guidance to a non-technical audience.

Experience in developing, documenting, and maintaining security policies, processes, procedures, and standards.

INDEPENDENT ACTION :

Functions independently within departmental policies and practices.  Must be able to work independently in a manner to achieve goals, objectives and productivity requirements.  Refers unresolved complex issues to director where clarification of department policies and procedures may be required.

SUPERVISORY RESPONSIBILITIES :

None.

Pay Range :

$113,519.22-$187,305.66

EEO Statement :

Brown University Health is committed to providing equal employment opportunities and maintaining a work environment free from all forms of unlawful discrimination and harassment.

Location :

BHCS 15 LaSalle Square - 15 LaSalle Square Providence, Rhode Island 02903

Work Type :

M-F 8 : 00am-4 : 30pm

Work Shift : Day

Daily Hours : 8 hours

Driving Required : Yes

Create a job alert for this search

Grc Analyst • Providence, RI, United States

Related jobs
Clinical Analyst Coord-EPIC

Clinical Analyst Coord-EPIC

Southcoast Health • New Bedford, MA, United States
Full-time
SC-DHS Ambulatory Applications.Join Southcoast Health, where your future is as promising as the care we provide.Our commitment to each other, our patients, and our community is more than a mission ...Show more
Last updated: 30+ days ago • Promoted
Travel Board Certified Behavioral Analyst (BCBA) - $503 per week

Travel Board Certified Behavioral Analyst (BCBA) - $503 per week

Princeton Staffing Solutions • New Bedford, MA, United States
Full-time +1
Princeton Staffing Solutions is seeking a travel Board Certified Behavioral Analyst (BCBA) for a travel job in New Bedford, Massachusetts. Job Description & Requirements.Board Certified Behavioral A...Show more
Last updated: 6 days ago • Promoted
Clinical Analyst Coordinator-EPIC

Clinical Analyst Coordinator-EPIC

Southcoast Health • New Bedford, MA, United States
Full-time
Clinical Analyst Coordinator-EPIC.Join Southcoast Health, where your future is as promising as the care we provide.Our commitment to each other, our patients, and our community is more than a missi...Show more
Last updated: 30+ days ago • Promoted
Security Guard - 3rd shift

Security Guard - 3rd shift

Adams and Associates, Inc. • Exeter, RI, US
Full-time
Are you tired of working for a company that promises upward mobility but never delivers? Are you looking for an employer that regularly promotes from within? Do you want to help guide and develop y...Show more
Last updated: 30+ days ago • Promoted
Travel Board Certified Behavioral Analyst (BCBA)

Travel Board Certified Behavioral Analyst (BCBA)

Princeton Staffing Solutions • New Bedford, MA, US
Full-time +1
Princeton Staffing Solutions is seeking a travel Board Certified Behavioral Analyst (BCBA) for a travel job in New Bedford, Massachusetts. Job Description & Requirements.Board Certified Behavior...Show more
Last updated: 5 days ago • Promoted
Armed Transport Guard

Armed Transport Guard

Brinks • Smithfield, RI, US
Full-time
The Brink's Company (NYSE : BCO) is a leading global provider of cash and valuables management, digital retail solutions, and ATM managed services. Our customers include financial institutions, re...Show more
Last updated: 16 hours ago • Promoted • New!
QA Specialist

QA Specialist

Cipla USA • Fall River, MA, United States
Full-time
General : 8 : 30AM - 5 : 00PM (may vary based on business needs).Salary Range : $74,984 - $96,408.This position requires a strong analytical chemistry / lab background and experience.The job du...Show more
Last updated: 29 days ago • Promoted
Head of Technology Strategy and Governance

Head of Technology Strategy and Governance

FM • Johnston, Rhode Island, United States
Full-time
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk manageme...Show more
Last updated: 12 hours ago • Promoted • New!
Sr Principal Product Manager - Cloud and Network Security

Sr Principal Product Manager - Cloud and Network Security

Oracle • Providence, RI, United States
Full-time
Oracle Cloud Infrastructure (OCI) is seeking an experienced Product Manager with deep expertise in network security and virtual networking to drive the development of innovative network security pr...Show more
Last updated: 2 days ago • Promoted
Postdoctoral Fellow (Interdisciplinary / Cyber Security)

Postdoctoral Fellow (Interdisciplinary / Cyber Security)

InsideHigherEd • Kingston, Rhode Island, United States
Full-time
Postdoctoral Fellow (Interdisciplinary / Cyber Security).Non-Union Non-Classified Staff.The search will remain open until the position has been filled. Work on interdisciplinary research opportuniti...Show more
Last updated: 2 days ago • Promoted
University Investigator (Civil)

University Investigator (Civil)

InsideHigherEd • Kingston, Rhode Island, United States
Temporary
University Investigator (Civil).Non-Union Non-Classified Staff.Anticipated Hiring Salary Range : $ 80,000 - $90,000.The search will remain open until the position has been filled.First consideration...Show more
Last updated: 30+ days ago • Promoted
Field Technician (CCTV Security Systems)

Field Technician (CCTV Security Systems)

Jobot • Canton, MA, US
Full-time +1
Field Technician (CCTV Security Systems) needed for a company that is a global technology powerhouse base in Canton, MA.This Jobot Job is hosted by : David Hyon. Are you a fit? Easy Apply now by clic...Show more
Last updated: 30+ days ago • Promoted
Business Intelligence Developer II

Business Intelligence Developer II

FM • Johnston, Rhode Island, United States
Full-time
Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk manageme...Show more
Last updated: 12 hours ago • Promoted • New!
Research Assistant III (NEMO)

Research Assistant III (NEMO)

InsideHigherEd • Kingston, Rhode Island, United States
Full-time
PTAA - Professional / Tech / Admin Assoc.Anticipated Hiring Range : $41,626 to $46,000.The search will remain open until the position has been filled. First consideration will be given to applications r...Show more
Last updated: 16 days ago • Promoted
Senior Programmer Analyst - (2 Positions)

Senior Programmer Analyst - (2 Positions)

InsideHigherEd • Kingston, Rhode Island, United States
Full-time
Senior Programmer Analyst - (2 Positions).PTAA - Professional / Tech / Admin Assoc.Anticipated Hiring Salary Range : $75,000 - $85,000. The search will remain open until the position has been filled.Firs...Show more
Last updated: 30+ days ago • Promoted
INTELLIGENCE ANALYST

INTELLIGENCE ANALYST

US Army • Providence, Rhode Island, United States
Full-time +1
THIS POSITION REQUIRES AN ENLISTMENT IN THE U.As an Intelligence Analyst, you’ll be responsible for providing the Army with crucial and reliable information about enemy forces and potential areas o...Show more
Last updated: 6 days ago • Promoted
HVAC Lead Installer

HVAC Lead Installer

ARS-Rescue Rooter • Brockton, MA, US
Full-time
Company Name : ARS-Rescue Rooter Overview : .Pay : $44-$53HR PLUS INCENTIVES .SIGN ON BONUS • based on skill / capabilities . Earning potential $100K+ / year based on performance.Join ARS, the na...Show more
Last updated: 30+ days ago • Promoted
Sr. Configuration Analyst

Sr. Configuration Analyst

Leidos Inc • Newport, RI, United States
Full-time
The Leidos National Security Sector has an opening for a Senior Configuration Analyst to support the Naval Array Technical Support Center (NATSC) located at Navy Undersea Warfare Center (NUWC), New...Show more
Last updated: 29 days ago • Promoted