Company

SurescriptsSee more

addressAddressUnited States
type Form of workFull-time
salary Salary$79,800 - $97,600 a year
CategoryInformation Technology

Job description

Surescripts serves the nation through simpler, trusted health intelligence sharing, in order to increase patient safety, lower costs and ensure quality care. We deliver insights at critical points of care for better decisions — from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between providers.

Job Summary:
The Information Security Risk Analyst will be part of the Governance, Risk, & Compliance team and will be responsible for performing risk assessments for applications, solutions, projects and third parties. This role reports to the Director, Governance, Risk, & Compliance and will work closely with the Senior Information Security Compliance Analyst. As part of this role, the Information Security Risk Analyst will identify risks, provide recommended remediation plans, and maintain a register of identified risks. The Information Security Risk Analyst will ensure that patient health information remains secure and identify ways to improve the risk assessment workflow.
Responsibilities:
  • Assess Security Risks, create written security requirements, and recommendations for use by product, project management, and technical teams:
    • Assist with assessment of the risks of applications (internally and externally developed), solutions, projects, and third parties – using best practices for threat modeling and security, as well as Surescripts policies and standards.
    • Aid with providing security requirements that mitigate risks.
    • Document all requirements and recommendations clearly so that product, development, and project management teams can understand responsibilities.
    • Participate in providing additional security guidance as needed and requested by stakeholders as they implement the security requirements.
    • Maintain process and documentation for Security Risk assessment methodology and steps.
    • Utilize risk assessment software to assess risk.
    • Follow-up as needed for additional details to finalize Security Risk assessment.
    • Document gaps and risk mitigation plans.
  • Assist with periodic risk reporting as directed by the Director, Governance, Risk, and Compliance.
  • May assist with business continuity planning.
  • Other duties could include supporting security awareness training, customer inquiries, and security certification activities (HITRUST, SOC2, HIPAA).
Qualifications:
Basic Requirements:
  • Bachelor’s degree in a related field, or equivalent experience.
  • 2+ years of experience in Information Security and performing risk assessments.
  • Knowledge of formal risk methodologies.
  • Familiarity with access control systems.
  • Knowledge of information technology such as Windows, macOS, Linux, Unix, networks, and endpoints.
  • Demonstrated effective critical thinking to extract essential information about potential risk including assessing what are the risks, what do we have in place to mitigate risks, and documentation of residual risk.
  • Exceptional written and verbal communication skills for documentation and information gathering.
  • Ability and experience conducting interviews with team members and/or vendors to uncover potential risk.
  • Solid cross-team collaboration and influencing skills to gain the required information for a proper risk assessment.
  • Exposure and/or knowledge of system configuration, vulnerability management and hardening guidelines.
  • Remain current with Information Security trends and threats.
Preferred Qualifications:
  • Experience using Information Security Risk assessment software such as OnSpring GRC.
  • ISACA certifications or similar.
  • Familiarity with HIPAA, HITRUST, and other healthcare related standards and regulations.
  • Familiarity with Business Continuity Planning.
Location:
  • Flexible hybrid or remote.
  • Must be willing to travel for required meetings.
Keywords: risk, risk assessment, Information Security
#LI-REMOTE
Surescripts embraces flexibility through its Flexible Hybrid Work model for most positions. This model allows employees to work virtually while still utilizing our offices as collaboration centers. With alignment and agreement from your leadership, you can come and go from the office as needed.

What You’re Like
You’re technical. Analytical. Imaginative. Maybe you’re building your own crypto-mining rig—or not. Either way, your mind works to anticipate vulnerabilities and protect the company and its information against those vulnerabilities. You do the right thing because it’s the right thing without seeking to point fingers or brag. And of course, you’re always willing to keep learning.

What We’re Like
We’re a team of friendly folks who do serious work. Our best work is done by rising to the occasion under stress, but we keep each other cool under pressure. We’re a tight team but we also look for ways to partner across the business. Our style is casual and laid back, but we shoulder our responsibility to protect patient data from sophisticated adversaries, which sometimes means delivering a difficult truth.

What the Work is Like
Our challenge is to protect our customers’ data and our company. This requires anomaly analysis, risk reviews, pen testing of our controls, red-teaming and tabletops, policy and procedure work, documentation, and audits. We also engineer and maintain our security products and tools. It’s not always a typical 9-to-5 gig, of course, but then again, you work in Information Security, so you already know that.

Why Wait? Apply Now
We’re a midsize company. This means you’re not just another employee ID number. Here, you can build real relationships and feel supported by truly awesome people with diverse backgrounds and talents in an innovative and collaborative work culture. We strive to create an environment where you can be yourself, share your ideas and work your way. We offer opportunities for employee development, as well as competitive compensation packages and extensive benefits.

At Surescripts, base pay is one part of our Total Rewards Package (which may also include bonus, benefits etc.) and is determined within a range. The base pay range for this position is $79,800 - $97,600 per year. Your base pay may vary within or outside of this range depending on a number of factors, including (but not limited to) your qualifications, skills, experience, and location.

Benefits include, but are not limited to, comprehensive healthcare (including infertility coverage), generous paid time off including paid childbirth and parental leave and mental health days, pet insurance, and 401(k) with company match and immediate vesting.

This role requires critical thinking and strong communication skills both written and verbal.
Physical and Mental Requirements
While performing duties of this job, an employee may be required to perform any, or all of the following: attend meetings in and out of the office, travel, communicate effectively (both orally and in writing), and be able to effectively use computers and other electronic and standard office equipment with, or without, a reasonable accommodation. Additionally, this job requires certain mental demands, including the ability to use judgement, withstand moderate amounts of stress and maintain attention to detail with, or without, a reasonable accommodation.
Surescripts is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate on the basis of race, color, religion, age, national origin, ancestry, disability, medical condition, marital status, pregnancy, genetic information, gender, sexual orientation, parental status, gender identity, gender expression, veteran status, or any other status protected under federal, state, or local law.

Benefits

Health insurance, Paid time off, Parental leave, 401(k) matching, Pet insurance
Refer code: 8465239. Surescripts - The previous day - 2024-03-06 00:29

Surescripts

United States
Jobs feed

Financial Sales - Own a Franchise

Pix11

New York, NY

Manufacturing Engineer

Luxottica

Groveport, OH

CFO - Own your own franchise

Pix11

New York, NY

Regional CDL A Truck Driver

Atg Recruiting

Sayreville, NJ

Sales Manager - Own a Franchise

Pix11

New York, NY

CDL A Regional Truck Driver

Hmd Trucking

Chicago, IL

Management Leaders - Own a Franchise

Pix11

New York, NY

Share jobs with friends

Security Analyst – Risk Management

The University Of Tennessee, Knoxville

Knoxville, TN

6 days ago - seen

JJT Finance Senior Analyst – Information Security & Risk Management

Johnson & Johnson

Raritan, NJ

a week ago - seen

Information Security Cyber Risk Analyst

Intel

Chandler, AZ

a week ago - seen

Senior Information Security Analyst - Insider Risk Team Lead

Western Digital

Milpitas, CA

2 weeks ago - seen

Sr. Analyst, Cyber Security Governance, Risk & Compliance

The Azek Company

Chicago, IL

3 weeks ago - seen

Sr Analyst, Information Security- Risk Analytics

Lowe's

Charlotte, NC

4 weeks ago - seen

Senior Security Analyst (Governance, Risk, and Compliance)

Oracle

United States

4 weeks ago - seen

Senior Data Security Risk Analyst

Cargurus

Cambridge, MA

4 weeks ago - seen

Part-Time Security Risk Analyst (Weekends)

Allied Universal

Atlanta, GA

4 weeks ago - seen

Information Security Analyst - Risk & Compliance

California State University

$4,912 - $12,124 a month

Long Beach, CA

4 weeks ago - seen

Security Analyst 2 - Risk

Enterprise Holdings

Missouri, United States

a month ago - seen

Security Third Party Risk Management Analyst

Pan-American Life Insurance Group

New Orleans, LA

a month ago - seen

Senior Security Analyst - Cybersecurity Risk Management

Blackbaud

Baton Rouge, LA

a month ago - seen

Senior Security Analyst - Cybersecurity Risk Management

Blackbaud

Dover, DE

2 months ago - seen

Senior Security Analyst - Cybersecurity Risk Management

Blackbaud

Jackson, MS

2 months ago - seen

Senior Security Analyst - Cybersecurity Risk Management

Blackbaud

Montpelier, VT

2 months ago - seen

Senior Security Analyst - Cybersecurity Risk Management

Blackbaud

Denver, CO

2 months ago - seen

Senior Security Analyst - Cybersecurity Risk Management

Blackbaud

Santa Fe, NM

2 months ago - seen