Security Risk Analyst
2 weeks ago
Position: Security Risk Analyst Location: Onsite at 55 Water Street, NYC Position Type: Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc. Minimum Qualifications: The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the technology-focused analysts, engineers and administrators in the IT organization. The Security Risk Analyst must be able to translate the IT-risk requirements and constraints of the business into technical control requirements and specifications, as well as develop metrics for ongoing performance measurement and reporting. The Security Risk Analyst coordinates the IT organization's technical activities to implement and manage security. The EITS Security Risk Analyst is part of the Enterprise Information Technology Services, Information Security and Risk Management team and will work at an enterprise level to ensure a consistent delivery of information security and risk management services. This individual will act as a subject matter expert to the assigned business units on matters regarding information security and compliance with HIPAA, Joint Commission, DSRIP, COBIT, and state privacy laws. General Tasks and Responsibilities Will Include: • Support Information Security and Risk Management by maintaining and enforcing the Information Security and risk management framework/methodology, including execution of risk analysis and risk mitigation strategies. • Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the CISO with a realistic overview of risks and threats in the enterprise environment. • Exhibit best practice risk management skills through effective internal risk controls, risk monitoring, risk assessment and improvement of risk management processes. • Document and maintain the enterprise security risk governance methodology and risk management policy, process, and procedure. • Work with various stakeholders to identify information asset owners to classify data and systems as part of a control framework implementation. • Organize and perform the enterprise security risk assessment and gap analysis for all technologies, products, and functions introduced, including maintaining risk project work plans to measure and manage progress. • Track and document all internal risk reviews, assessments, risk acceptances, and security exceptions in a GRC tool. • Work with the enterprise architecture team to ensure that there is a convergence of business, technical and security requirements; liaise with IT management to align existing technical installed base and skills with future architectural requirements. • Develop a strong working relationship with the security engineering team to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirements • Serve as the information security liaison and subject matter expert for all relevant EMR and PHI related security risk. • Conduct or participate in all relevant audits and risk assessment activities (whether operational risk, legal/compliance risk, reputational risk, or information security risk). • Aid in the planning and execution of risk remediation activities including the identification of practical, cost effective solutions. • Facilitate team meetings between stakeholders, project leaders, and the Information Technology teams. • Attend regular team, management, and project meetings and provide both verbal and written reports to the Leadership Team as required. This may include coordination with and support of an Operational Risk Committee. • Keep informed on current threats and industry regulations. Knowledgeable In: • Healthcare industry experience required with understanding of EMR systems and data privacy issues related to PHI • Experience with reviewing IT solution requirements and security controls implementation • A strong understanding of the business impact of security tools, technologies and policies. • Knowledge and experience working with a GRC Software tool • Strong working knowledge of HIPAA, Joint Commission, CMS, and other regulatory legislation pertinent to the healthcare industry • Working knowledge of information security frameworks such as NIST CSF, HITECH, ISO27001/27002, PCI DSS and COBIT • Experience in conducting and responding to information security assessments and audits. • Strong analytical skills and the ability to resolve complex security vulnerabilities and design compensating controls Other Preferred Skills: • Must possess a high degree of integrity and trust along with the ability to work independently • Participate in special projects as needed and perform other duties as assigned • Must be able to work independently as well as work as part of a fast-moving team • Must be able to work at various locations when necessary along with working various shifts Educational Level: • A bachelor's degree in information systems • CISSP, CISA, CRISC or other relevant security qualification Years Of Experience: • A minimum of seven years of IT experience, least 5 years dedicated to IT Security Risk Management, Risk Audit/Assessment, and/or Security and/or Data Privacy Investigation least two years in a supervisory capacity. Minimum Qualifications: The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the technology-focused analysts, engineers and administrators in the IT organization. The Security Risk Analyst must be able to translate the IT-risk requirements and constraints of the business into technical control requirements and specifications, as well as develop metrics for ongoing performance measurement and reporting. The Security Risk Analyst coordinates the IT organization's technical activities to implement and manage security. The EITS Security Risk Analyst is part of the Enterprise Information Technology Services, Information Security and Risk Management team and will work at an enterprise level to ensure a consistent delivery of information security and risk management services. This individual will act as a subject matter expert to the assigned business units on matters regarding information security and compliance with HIPAA, Joint Commission, DSRIP, COBIT, and state privacy laws. General Tasks and Responsibilities Will Include: • Support Information Security and Risk Management by maintaining and enforcing the Information Security and risk management framework/methodology, including execution of risk analysis and risk mitigation strategies. • Manage the process of gathering, analyzing and assessing the current and future threat landscape, as well as providing the CISO with a realistic overview of risks and threats in the enterprise environment. • Exhibit best practice risk management skills through effective internal risk controls, risk monitoring, risk assessment and improvement of risk management processes. • Document and maintain the enterprise security risk governance methodology and risk management policy, process, and procedure. • Work with various stakeholders to identify information asset owners to classify data and systems as part of a control framework implementation. • Organize and perform the enterprise security risk assessment and gap analysis for all technologies, products, and functions introduced, including maintaining risk project work plans to measure and manage progress. • Track and document all internal risk reviews, assessments, risk acceptances, and security exceptions in a GRC tool. • Work with the enterprise architecture team to ensure that there is a convergence of business, technical and security requirements; liaise with IT management to align existing technical installed base and skills with future architectural requirements. • Develop a strong working relationship with the security engineering team to develop and implement controls and configurations aligned with security policies and legal, regulatory and audit requirements • Serve as the information security liaison and subject matter expert for all relevant EMR and PHI related security risk. • Conduct or participate in all relevant audits and risk assessment activities (whether operational risk, legal/compliance risk, reputational risk, or information security risk). • Aid in the planning and execution of risk remediation activities including the identification of practical, cost effective solutions. • Facilitate team meetings between stakeholders, project leaders, and the Information Technology teams. • Attend regular team, management, and project meetings and provide both verbal and written reports to the Leadership Team as required. This may include coordination with and support of an Operational Risk Committee. • Keep informed on current threats and industry regulations. Knowledgeable In: • Healthcare industry experience required with understanding of EMR systems and data privacy issues related to PHI • Experience with reviewing IT solution requirements and security controls implementation • A strong understanding of the business impact of security tools, technologies and policies. • Knowledge and experience working with a GRC Software tool • Strong working knowledge of HIPAA, Joint Commission, CMS, and other regulatory legislation pertinent to the healthcare industry • Working knowledge of information security frameworks such as NIST CSF, HITECH, ISO27001/27002, PCI DSS and COBIT • Experience in conducting and responding to information security assessments and audits. • Strong analytical skills and the ability to resolve complex security vulnerabilities and design compensating controls Other Preferred Skills: • Must possess a high degree of integrity and trust along with the ability to work independently • Participate in special projects as needed and perform other duties as assigned • Must be able to work independently as well as work as part of a fast-moving team • Must be able to work at various locations when necessary along with working various shifts Educational Level: • A bachelor's degree in information systems • CISSP, CISA, CRISC or other relevant security qualification Years Of Experience: • A minimum of seven years of IT experience, least 5 years dedicated to IT Security Risk Management, Risk Audit/Assessment, and/or Security and/or Data Privacy Investigation least two years in a supervisory capacity.
-
Security Risk Analyst
2 weeks ago
New York, NY, United States RIT Solutions, Inc. Full timePosition: Security Risk Analyst Location: Onsite at 55 Water Street, NYC Position Type: Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc. Minimum Qualifications: The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the...
-
Security Risk Analyst
1 week ago
New York, NY, United States RIT Solutions, Inc. Full timePosition: Security Risk Analyst Location: Onsite at 55 Water Street, NYC Position Type: Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc. Minimum Qualifications: The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the...
-
Security Risk Analyst
21 hours ago
New York, NY, United States RIT Solutions, Inc. Full timePosition: Security Risk Analyst Location: Onsite at 55 Water Street, NYC Position Type: Long Term Contract / Potential several years with Right to Hire GRC focused Security role / Risk management, etc. Minimum Qualifications: The EITS Security Risk Analyst will interface between the CISO's strategic and process-based activities and the work of the...
-
Cyber Security Risk Analyst
2 weeks ago
New York, United States S&P Global Full timeAbout the Role :Grade Level (for internal use):10S&P Dow Jones Indices The Role: Cyber Security EngineerThe Team: Are you passionate about cyber security? Do you enjoy solving complex problems and collaborating with diverse teams? The Cyber Security Risk Analyst will support and help coordinate activities across the department to drive process improvement....
-
Lead Security Risk Analyst
2 days ago
New York, United States Justworks Full timeWho We AreAt Justworks, you’ll enjoy a welcoming and casual environment, great benefits, wellness program offerings, company retreats, and the ability to interact with and learn from leaders in the startup community. We work hard and care about our most prized asset - our people. We’re helping businesses get off the ground by enabling them to focus on...
-
Asset-Backed Securities Risk Analyst- VP
3 weeks ago
New York, United States Barclays Full timeAsset Backed Securities Risk Analyst- VPTo independently assess and make credit decisions for complex financing transactions within the LevFin, SLF, and Hedge Funds sectors, ensuring alignment with the bank's credit risk appetite and regulatory requirements and contribute to the development and implementation of credit risk policies and procedures for the...
-
Risk Analyst
5 days ago
New York, NY, United States Columbia University Full timeJob Type: Officer of Administration Regular/Temporary: Regular Hours Per Week: 35 Salary Range: $80,000 - $85,000 The salary of the finalist selected for this role will be set based on a variety of factors, including but not limited to departmental budgets, qualifications, experience, education, licenses, specialty, and training. The above hiring range...
-
Physical Security GSOC Manager
2 days ago
New York, New York, United States Insite Risk Management Full timeThe GSOC Manager is responsible for supervising threat detection and reporting, incident response, travel risk management, and protective intelligence workstreams in our 24/7 security operations center. The person in this position aligns daily operations with company standards while managing the team of GSOC analysts working around the clock. Importantly,...
-
Risk Analyst
4 weeks ago
New York, United States Tiplink, Inc Full timeAbout the Company TipLink is a company merging the world of crypto and payments. Crypto rails can be cheaper, faster, and more global than traditional finance, enabling new products that couldn't otherwise exist. TipLink is leading the charge with innovation at this intersection. The company is backed by investors including Sequoia, Multicoin, Circle, Solana...
-
Cyber Risk Analyst, AVP
3 weeks ago
New York, United States Apple Inc. Full timeCyber Risk Analyst, AVP page is loaded## Cyber Risk Analyst, AVPremote type: Hybridlocations: New York, NYtime type: Full timeposted on: Posted Yesterdayjob requisition id: 2025-1036New York, NY (Hybrid) Salary Range: $110,000 - $130,000 The Cyber Risk Analyst acts as a subject matter expert in vulnerability management and plays a key role in...