Information Security GRC Anyls

2 days ago


Houston TX, United States Houston Methodist Full time

At Houston Methodist, the Information Security Governance, Risk, and Compliance (GRC) Analyst is responsible for managing risks related to information security, privacy, and regulatory compliance within an organization. This role involves developing and implementing policies, assessing risks, ensuring compliance with industry standards and regulations, and implementing control measures to mitigate risks. Key responsibilities include conducting risk assessments, developing risk mitigation strategies, monitoring compliance with frameworks such as ISO 27001, GDPR, NIST, and SOX, conducting vendor risk assessments, and collaborating with different departments to manage risks and ensure compliance. The GRC Analyst also creates and maintains information security standards, conducts gap analyses, and prepares for regulatory examinations.

PEOPLE ESSENTIAL FUNCTIONS
  • Gathers feedback for continuous improvements on established employee and technology policies from IT and business partners.
  • Communicates risk findings and recommendations that are clear and actionable to all stakeholders.

SERVICE ESSENTIAL FUNCTIONS
  • Creates, maintains, and communicates information security standards.
  • Facilitates the remediation of control gaps and escalates critical issues to leadership.
  • Prepares for and facilitates examinations by security assessors for regulations.

QUALITY/SAFETY ESSENTIAL FUNCTIONS
  • Assesses and reports on the risks and benefits for the business, as well as the mandates for the supplier compliance.
  • Evaluates the effectiveness of the information security program by developing and analyzing compliance metrics.

FINANCE ESSENTIAL FUNCTIONS
  • Advises leadership on risk management strategies, including risk mitigation and risk transfer.
  • Maintains and registers relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities.

GROWTH/INNOVATION ESSENTIAL FUNCTIONS
  • Identifies, analyzes, evaluates, and documents information security risks and controls based on established risk criteria.
  • Conducts third-party risk assessments and recommends control to mitigate identified risks.
  • Coordinates architecture reviews as part of third-party risk assessments.
  • Designs and documents technical, administrative, and physical controls to ensure compliance.
  • Assists with the review of information security sections within supplier contract and recommends necessary changes.
  • Takes a best practice approach to information security to balance secure operations with innovation.

This job description is not intended to be all-inclusive; the employee will also perform other reasonably related business/job duties as assigned. Houston Methodist reserves the right to revise job duties and responsibilities as the need arises. EDUCATION
  • Bachelor's degree in information security, information technology, computer science or other related technology degree

WORK EXPERIENCE
  • Five years of Risk and/or Governance, Risk & Compliance experience. An additional three years of experience required in lieu of level 2 certification in assigned area of concentration
LICENSES AND CERTIFICATIONS - REQUIRED
  • CISSP - Certified Information Systems Security Professional (IISSCC) OR
  • CRISC - Certified Risk and Information Systems Control (ISACA)
KNOWLEDGE, SKILLS, AND ABILITIES
  • Demonstrates the skills and competencies necessary to safely perform the assigned job, determined through on-going skills, competency assessments, and performance evaluations
  • Sufficient proficiency in speaking, reading, and writing the English language necessary to perform the essential functions of this job, especially with regard to activities impacting patient or employee safety or security
  • Ability to effectively communicate with patients, physicians, family members and co-workers in a manner consistent with a customer service focus and application of positive language principles
  • Understanding of relevant laws, regulations, and standards
  • Knowledge of best practices for developing and implementing compliance programs
  • Ability to analyze complex data and identify trends or discrepancies related to compliance and risk
  • Proficient in both written and verbal communication to convey compliance issues and policies clearly

SUPPLEMENTAL REQUIREMENTS

WORK ATTIRE

  • Uniform No
  • Scrubs No
  • Business professional Yes
  • Other (department approved) No

ON-CALL*
*Note that employees may be required to be on-call during emergencies (ie. DIsaster, Severe Weather Events, etc) regardless of selection below.

  • On Call* No

TRAVEL**
**Travel specifications may vary by department**

  • May require travel within the Houston Metropolitan area Yes
  • May require travel outside Houston Metropolitan area Yes

Company Profile:

Houston Methodist is one of the nation’s leading health systems and academic medical centers. Houston Methodist consists of eight hospitals: Houston Methodist Hospital, its flagship academic hospital in the heart of the Texas Medical Center, and seven community hospitals throughout the greater Houston area. Houston Methodist also includes an academic institute, a comprehensive residency program, a global business division, numerous physician practices and several free-standing emergency rooms and outpatient facilities. Overall, Houston Methodist employs more than 27,000 employees and is supported by a wide variety of business functions that operate at the system level to help enable clinical departments to provide high quality patient care.

Houston Methodist is an Equal Opportunity Employer.

Equal employment opportunity is a sound and just concept to which Houston Methodist is firmly bound. Houston Methodist will not engage in discrimination against or harassment of any person employed or seeking employment with Houston Methodist on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or other characteristics protected by law. VEVRAA Federal Contractor – priority referral Protected Veterans requested.



  • Houston, United States Houston Methodist Full time

    Information Security GRC Anyls at Houston Methodist summary: The Information Security Governance, Risk, and Compliance (GRC) Analyst at Houston Methodist is tasked with managing information security risks and ensuring compliance with regulations. This role involves developing policies, conducting risk assessments, and collaborating across departments to...


  • Houston, United States Houston Methodist Full time

    At Houston Methodist, the Information Security Governance, Risk, and Compliance (GRC) Analyst is responsible for managing risks related to information security, privacy, and regulatory compliance within an organization. This role involves developing and implementing policies, assessing risks, ensuring compliance with industry standards and regulations, and...


  • Houston, United States Houston Methodist Full time

    At Houston Methodist, the Information Security Governance, Risk, and Compliance (GRC) Analyst is responsible for managing risks related to information security, privacy, and regulatory compliance within an organization. This role involves developing and implementing policies, assessing risks, ensuring compliance with industry standards and regulations, and...


  • Dallas, TX, United States Boys and Girls Country of Houston, Inc Full time

    At Bluebeam, we empower people to advance the way the world is built. We create smart software solutions that make construction sites more efficient, connected, and safe and improve the lives of design and construction professionals everywhere.This position will provide leadership and accountability for Bluebeam’s information security program. It is...


  • Houston, United States Search Services Full time

    SUMMARY: A well-known Houston entity is seeking an experienced Information Technology Security Manager to join their team.RESPONSIBILITIES: A well-known Houston entity is seeking an experienced Information Technology Security Manager to join their team. In this role, you will be responsible for cybersecurity programs and activities across the organization in...


  • Houston, United States Search Services Full time

    SUMMARY: A well-known Houston entity is seeking an experienced Information Technology Security Manager to join their team.RESPONSIBILITIES: A well-known Houston entity is seeking an experienced Information Technology Security Manager to join their team. In this role, you will be responsible for cybersecurity programs and activities across the organization in...


  • Houston, TX, United States NES Global Talent Full time

    CompetitiveUnited States Texas HoustonPermanent IT Job Description Primary Purpose: A Leading energy infrastructure company, is seeking an experienced and strategic Chief Information Security Officer (CISO) to join their mission-driven and innovative organization. The CISO will be responsible for creating and managing an enterprise-wide cybersecurity...


  • Houston, United States NES Fircroft Full time

    Job DescriptionPrimary Purpose: A Leading energy infrastructure company, is seeking an experienced and strategic Chief Information Security Officer (CISO) to join their mission-driven and innovative organization. The CISO will be responsible for creating and managing an enterprise-wide cybersecurity program, playing a crucial role in safeguarding Sempra...


  • Houston, United States NES Fircroft Full time

    Job DescriptionPrimary Purpose: A Leading energy infrastructure company, is seeking an experienced and strategic Chief Information Security Officer (CISO) to join their mission-driven and innovative organization. The CISO will be responsible for creating and managing an enterprise-wide cybersecurity program, playing a crucial role in safeguarding Sempra...


  • Houston, United States Sempra LNG Full time

    Primary Purpose: Sempra Infrastructure, a leading energy infrastructure company, is seeking an experienced and strategic Chief Information Security Officer (CISO) to join their mission-driven and innovative organization. The CISO will be responsible for creating and managing an enterprise-wide cybersecurity program which will play a crucial role in...


  • Houston, United States Sempra LNG Full time

    Primary Purpose: Sempra Infrastructure, a leading energy infrastructure company, is seeking an experienced and strategic Chief Information Security Officer (CISO) to join their mission-driven and innovative organization. The CISO will be responsible for creating and managing an enterprise-wide cybersecurity program which will play a crucial role in...


  • Houston, United States Sempra Services Corporation Full time

    Primary Purpose Sempra Infrastructure, a leading energy infrastructure company, is seeking an experienced and strategic Chief Information Security Officer (CISO) to join their mission-driven and innovative organization. The CISO will be responsible for creating and managing an enterprise-wide cybersecurity program which will play a crucial role in...


  • Houston, Texas, United States Vets Hired Full time

    About the RoleVets Hired is seeking a highly skilled Information Security Professional to join our team as a Cybersecurity Analyst II. This role will be responsible for protecting our computer networks and information by utilizing resources and tools.Key ResponsibilitiesWe are looking for someone with a willingness to exhibit Wellbys Core Values every day,...


  • Houston, United States EnerMech Full time

    At EnerMech, we're seeking a dedicated Information Security Manager to strengthen and oversee our cybersecurity strategy. Join us in protecting critical infrastructure and supporting secure operations across global projects in the energy and engineering sectors.Benefits401(k) matching to help secure your financial future10 paid holidays to enjoy throughout...


  • Houston, United States Raptor Technologies Full time

    Job DescriptionJob DescriptionAbout Us!Founded in 2002, Raptor has partnered with more than 60,000 schools in 55 different countries, including 5,300+ K-12 US school districts, to provide integrated visitor, volunteer, attendance, dismissal, emergency management, and safeguarding software and services covering the complete spectrum of school and student...


  • Houston, Texas, United States Bristow Group Full time

    Job OverviewWe are seeking an experienced Cybersecurity Analyst - IT Compliance to join our team at Bristow Group.About the RoleThis is a key position within our Information Technology department, responsible for supporting the implementation and oversight of cybersecurity programs and incident management. The successful candidate will work closely with our...


  • Houston, TX, United States BMC Software Full time

    Description and Requirements CareerArc Code CA-JR #LI-JR1 Remote: #LI-Remote "At BMC trust is not just a word - it's a way of life!" We are an award-winning, equal opportunity, culturally diverse, fun place to be. Giving back to the community drives us to be better every single day. Our work environment allows you to balance your priorities,...

  • Security Professional

    4 weeks ago


    Houston, Texas, United States iidon Security Associates Full time

    Job TitleSecurity ProfessionalAbout the RoleWe are seeking a skilled Security Professional to join our team at iidon Security Associates. As a key member of our team, you will play a vital role in maintaining a safe and secure environment for our customers and employees.Job SummaryThis is a full-time position that requires standing for long periods, climbing...


  • Houston, Texas, United States KPMG Full time

    About the JobAs a Director, Cyber at KPMG, you will be responsible for leading our clients' cybersecurity efforts, developing effective security strategies, and implementing cutting-edge solutions.About You:You have a minimum of 8 years of experience in information security or a related field.You possess exceptional leadership and communication skills, with...


  • Houston, Texas, United States Binary Defense Full time

    About the Cybersecurity Engineer RoleThe ideal candidate has hands-on experience with Cortex XSIAM, strong information security knowledge, and skills in system administration, scripting languages, and IT knowledge. They must be able to evaluate client environments, prioritize data sources, and provide log collection guidance. Additionally, they should have...