Governance, Risk and Compliance Analyst Senior
Cone Health · Greensboro, NC · 3 wk ago
LegalFull-time
About the role
The Governance, Risk & Compliance (GRC) Analyst - Senior collaborates with process owners, internal auditors, external auditors, and other stakeholders to review, monitor, and resolve cybersecurity risk. This includes managing HITRUST, HIPAA, and NIST Common Security Framework (CSF) audits and attestations, supporting internal and external assessments, and ensuring compliance with regulations and standards such as SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities.
Responsibilities
- Lead the execution and reporting of outcomes derived from Third Party Risk Assessments.
- Manage the completion of risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with NIST and HITRUST standards.
- Manage and monitor a central repository for all security risks and audit evidence.
- Maintain security standards, policies, and practices on an annual basis to ensure they meet organizational and regulatory requirements.
- Manage a security awareness training program to educate associates about security compliance standards, risk management practices, and ethical behavior.
- Collaborate with legal and compliance teams to ensure policies and security controls align with regulatory requirements.
- Conduct internal audits to assess the effectiveness of security controls and identify areas for improvement.
- Perform other duties as assigned.
Requirements
- Bachelor's Degree and/or equivalent experience.
- 7 years of relevant experience.
- Certified Information Security Manager (CISM) certification.