Cyber Security GRC Analyst

$56,200 - $90,000/Yr

MVP Health Care - Rochester, NY

posted 18 days ago

Full-time - Mid Level
Rochester, NY
Insurance Carriers and Related Activities

About the position

The Cyber Security GRC Analyst at MVP Health Care plays a crucial role in ensuring compliance with cybersecurity standards and regulations, particularly focusing on HIPAA and HITRUST. This position involves developing and implementing security policies, conducting assessments, and collaborating with various teams to manage risks effectively. The role is designed for individuals passionate about cybersecurity and risk analytics, offering opportunities for growth within a supportive and diverse work environment.

Responsibilities

  • Develop, implement, and communicate IT and Corporate security policy, standards, best practices, guidance, and procedures.
  • Draft, review, and comment on translating federal requirements into Department policies and requirements, including NIST publications, DFS guidance, and HIPAA.
  • Implement HIPAA and HITRUST assessments and implement CSF framework controls to ensure compliance.
  • Work with Risk Management team to ensure Business Continuance plans are up to date.
  • Assist with regular table-top exercises.
  • Support annual recertification of accounts, ensuring new accounts have appropriate access and inactive accounts are deactivated.
  • Provide hands-on assistance to Business Units as necessary.
  • Create Cybersecurity dashboard and presentations for Board Risk and Compliance Committee.
  • Manage and maintain IT security Risk Register.
  • Coordinate with Enterprise Risk Team to ensure all risks are tracked and actively worked on for remediation.
  • Provide third party oversight including review of contracts, Business Associate Agreements, Information Security Questionnaires, and other artifacts such as SOC2 and HITRUST reports.

Requirements

  • Bachelor's Degree or an equivalent combination of formal education and experience.
  • Working understanding of HIPAA compliance and requirements of all phases of Certification and Accreditation (C&A).
  • Knowledge of NIST standards and their impact on system security.
  • Experience with risk management and SDLC processes.
  • Ability to work virtually with occasional travel requirements.

Nice-to-haves

  • Curiosity to foster innovation and pave the way for growth.
  • Humility to play as a team.
  • Commitment to being the difference for customers in every interaction.

Benefits

  • Competitive compensation and comprehensive benefits focused on well-being.
  • Growth opportunities to advance your career.
  • A people-centric culture embracing diverse perspectives.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service