Risk & Compliance Analyst

Sorry, this job was removed at 1:46 p.m. (CST) on Tuesday, January 21, 2020
Find out who's hiring in Austin.
See all Cybersecurity + IT jobs in Austin
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Working as part of the information security team within the technology office at Bright Health, the Risk & Compliance Analyst will report directly to the Director of Information Security and will be responsible for leading the day to day IT compliance, data governance, and IT risk management functions. The role will include primary responsibility for defining, creating, and managing IT and organizational policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational information security practices.

Specifically, the GRC (Governance, Risk and Compliance) Analyst will be maintaining day-to-day workstreams for the Bright Health security program. This position will be responsible for conducting vendor security reviews in the procurement system, updating risk registers and assisting with project managing audit requests across various business units. These workstreams will be executed under the systems that the Director of Information Security has architected and built. This position will also be responsible for assisting with annual risk assessments, business impact analysis and overhauling changes within the governance program, where needed. This role will be well supported by Bright Health’s Director of Information Security and Senior Security Engineer.

YOUR RESPONSIBILITIES

  • Collaborate to define IT security standards and develop supporting organizational policies.
  • Perform security and compliance assessments on new and existing systems, processes, technology.
  • Support vendor due-diligence process and help to lead and define overall third-party risk management efforts.
  • Work with various business units to ensure controls are adequate, appropriate, and effective.
  • Support internal and external audit process for relevant compliance concerns including SOC2, HIPAA requirements.
  • Participate in disaster recovery and business continuity planning.
  • Perform business impact analysis and assist with development of IT/InfoSec risk register.
  • Perform periodic gap assessments to validate compliance on an ongoing basis.
  • Stay up to date and informed on developing regulatory concerns and changing IT and information security trends.
  • Other duties or responsibilities as assigned

EDUCATION, TRAINING, AND PROFESSIONAL EXPERIENCE

  • High School Diploma or GED required; Bachelor’s degree in related field or equivalent work experience preferred.
  • Two (2) or more years of relevant in information security experience required
  • Experience in governance, risk management, and compliance within the cybersecurity realm including assisting with security and privacy audits, and managing risk management reports, highly preferred.
  • ISACA or (ISC)2 Certification is preferred.

PROFESSIONAL COMPETENCIES

  • Knowledge and experience in information security and privacy laws, access, release of information, and release control technologies.
  • Knowledge and experience in general electronic health information access, release of information, and release control technologies.
  • Able to analyze the nature and classification of health data and the status of the person or entity requesting the electronic health data. Determine which provisions in HIPAA or security policy apply to the data, determine if other state or federal laws, rules, or regulations are in conflict with the applicable provision of HIPAA or policy; Determine if there are court decisions that address the issue; and recommend procedures or processes that reduce or eliminate the conflicts in law and assure compliance with applicable statutes and/or regulations.
  • Demonstrated organizational, facilitation, presentation, and project management skills with excellent written and verbal communication skills.
  • Ability to develop and/or modify policies and procedures within the confines of current law and management objectives

ABOUT US

 

At Bright Health, we brought together the brightest minds from the health care industry and consumer technology and together we created Bright Health: a new, brighter approach to healthcare, built for individuals. Our plans are easy to manage, personalized and more affordable, giving people the quality care they deserve. Through our exclusive care partnerships with leading health systems in local communities we are reshaping how people and physicians achieve better health together.

 

We’re Making Healthcare Right. Together. 

We've won some fun awards like: Great Places to Work, Modern Healthcare, Forbes, etc. But more than anything, we're a group of people who are really dedicated to our mission in healthcare. Come join our growing team!

 

As an Equal Opportunity Employer, we welcome and employ a diverse employee group committed to meeting the needs of Bright Health, our consumers, and the communities we serve. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.

BRIGHT ON!

Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Location

We are downtown at 515 Congress Avenue, right in the heart of downtown! Tons of restaurants and close to public transportation.

Similar Jobs

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about Bright HealthFind similar jobs