Risk Analysis Specialist (NIST SP 800-30)
Xtreme Solutions Inc · San Bernardino, CA · 3 wk ago
RemoteRemoteAnalystContract
About the role
Conducts the formal HIPAA Risk Analysis required under 45 CFR 164.308(a)(1)(ii)(A), identifying threats and vulnerabilities to ePHI, scoring likelihood and impact, and assigning risk levels using NIST SP 800-30 methodology.
Responsibilities
- Identify and document reasonably anticipated threats and vulnerabilities unique to each department.
- Assess likelihood of threat occurrence and magnitude of potential impact (qualitative and/or quantitative).
- Assign and document risk levels for all threat/vulnerability combinations.
- Recommend security controls to mitigate identified risks.
Requirements
- 4+ years of IT risk analysis experience using NIST SP 800-30 or comparable frameworks.
- Strong quantitative and qualitative risk-modeling skills.
- Experience producing formal risk analysis reports for regulated industries.
Qualifications
- Preferred: CRISC or GRCP certification.
- Preferred: Healthcare-sector risk analysis experience.
Schedule
Fully remote; must remain within the continental United States.