Information Security Risk Analyst II - IT Risk

Remote Full-time
About the position Join Novant Health's Information Technology team as an Information Security Risk Analyst, on the IT Governance, Risk, and Compliance (IT GRC) team, where you'll play a critical role in safeguarding our information systems and supporting our mission to deliver remarkable care. Schedule: 8:00AM - 5:00PM (On call support required, as needed). Location: Remote Department: ETS - Information Security. Responsibilities β€’ Monitor and assess IT & security risks across information systems throughout their lifecycle. β€’ Perform ongoing assessment of IT controls to ensure they are operating effectively and efficiently. β€’ Identify and document sensitive data stored, transmitted, or processed within systems. β€’ Enforce security principles such as least privilege and least functionality. β€’ Provide actionable insights to senior leadership to support risk-informed decision-making. β€’ Develop and maintain risk management procedures, including evaluating the significance of identified risks, defining acceptable mitigation strategies and risk tolerance, establishing ongoing risk monitoring practices, and ensuring effective oversight of the risk management strategy. Requirements β€’ 4 Year / Bachelor's Degree, required. β€’ Minimum three years Information Security Risk Analysis, Information Security, required. β€’ (CRISC) and (CompTIA Security+ or CompTIA Healthcare IT Tech) or equivalent. (Two cert req), required. β€’ Intermediate knowledge of risk management processes. β€’ Intermediate knowledge of national laws, regulations, policies, and ethics as they relate to cybersecurity. β€’ Intermediate knowledge of cybersecurity principles. β€’ Intermediate knowledge of cyber threats and vulnerabilities. β€’ Basic knowledge of cyber defense mitigation techniques and vulnerability assessment tools. β€’ Intermediate knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins. β€’ Intermediate knowledge of information assurance (IA) principles. β€’ Intermediate knowledge of current industry methods for evaluating, implementing, and disseminating IT security assessment tools. β€’ Intermediate knowledge of new and emerging IT and cybersecurity technologies. β€’ Intermediate knowledge of the organization's enterprise IT goals and objectives. β€’ Intermediate knowledge of the organization's core business/mission processes. β€’ Intermediate knowledge of Personally Identifiable Information (PII) and Payment Card Industry (PCI) data security standards. β€’ Intermediate knowledge of applicable laws relevant to work performed. β€’ Basic knowledge of IT supply chain security and risk management policies. β€’ Intermediate skill in evaluating the trustworthiness of the supplier and/or product. β€’ Intermediate knowledge of relevant laws, policies, procedures, or governance related to work impacting critical infrastructure. β€’ Intermediate knowledge of information classification programs and procedures for information loss. β€’ Interpersonal communication skill, both written and oral. β€’ Attention to detail and organization skills. β€’ Analysis and critical thinking skills. β€’ Ability to develop productive working relationships with business and technical groups. β€’ Ability to effectively prioritize multiple responsibilities. β€’ Ability to take direction as well as work with a moderate degree of independence. β€’ Ability to work as a member of a team. β€’ Ability to eagerly seize responsibility and ownership for assigned tasks. β€’ Ability to drive/travel to multiple locations/facilities as needed. Nice-to-haves β€’ Basic knowledge of information security architecture principles. β€’ Basic knowledge of incident response methodologies. β€’ Basic knowledge of security tools (IDS, FIM, Vulnerability Scanner, SIEM, Forensics, Network Mapping, Penetration Testing, Encryption, etc.). β€’ Basic knowledge of penetration testing methods. β€’ Basic knowledge of systems testing and evaluation methods. Apply tot his job
Apply Now β†’

Similar Jobs

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote

USPS Office Helper

Remote

Remote Youth Market Research Associate – Flexible Online Survey & Product Testing Role for 16‑Year‑Olds

Remote

Asset Management - Real Estate Investing - Analyst

Remote

Experienced Customer Success Representative – Seasonal, Part-Time/Full-Time, Remote Opportunity to Drive Customer Happiness and Growth at arenaflex

Remote

Pharmacist, Clinical Outcomes

Remote

MDS Coordinator, Remote Days May Be Available

Remote

**Experienced Entry-level Virtual Data Entry Clerk – Remote Opportunity for Career Growth and Development at blithequark**

Remote

**Experienced Call Center Representative – Remote Data Entry Work Opportunity at blithequark**

Remote

[Remote] SMB Account Executive (Entry-Level)

Remote

**Experienced Client Success Associate – Live Chat Support From Home (Remote) – Part-Time at blithequark**

Remote

Data Entry Clerk in Monsey, NY in Community Medical and Dental Care Inc (job Id: 1680321133)

Remote
← Back