Information Security Governance Analyst
Role details
Job location
Tech stack
Job description
The Governance, Risk, and Compliance Analyst will play a key role in facilitating the development and maintenance of the organization's global governance, risk management, and compliance programs. This position will support a broad range of activities across the organization., * Facilitates the development, implementation, and maintenance of an information security framework aligned with industry best practices.
- Facilitates the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations.
- Provides advice & counsel as directed within IT and information security initiatives to ensure the delivery of compliant and risk-appropriate solutions following existing department policies, standards, and procedures.
- Facilitate examinations by security assessors and auditors for compliance obligations, such as HIPAA and ISO 27001.
- Facilitates security risk assessments and recommends controls to mitigate identified security risks.
- Communicates risk findings and recommendations to business stakeholders.
- Facilitates the development and deployment of workforce security training and awareness.
- Facilitates the development and implementation of global cybersecurity policies, standards, and procedures aligned with industry best practices, including NIST CSF and 800-series publications.
- Facilitates the lifecycle management of information security policies.
Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions.
Requirements
Do you have experience in Regulatory compliance?, Do you have a Bachelor's degree?, * Bachelor's Degree or an equivalent combination of education and experience, * 2+ years' related experience in cybersecurity governance, risk, compliance, information security, and/or other related roles.
- Advanced knowledge of internal control structure, data, and technology
- Advanced knowledge of NIST CSF, NIST SP 800-series, HIPAA, FIPS, and ISO 27001:2022, and other industry best standards and requirements.
- Excellent verbal and written communication skills.
- Excellent organizational skills.
- CISSP, CRISC, CISA, CISM, or other related certifications are preferred.
- Demonstrated experience with ServiceNow IRM or a similar tool is preferred.
The rate of pay for this position will depend on the successful candidate's work location and qualifications, including relevant education, work experience, skills, and competencies.
Benefits & conditions
3.33.3 out of 5 stars Waltham, MA 02451 Hybrid work $72,000 - $121,000 a year - Full-time, Pulled from the full job description
- Parental leave
- Health insurance
- 401(k) matching
- Paid time off
- Vision insurance
- Dental insurance, * The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions., Annual Rate: $72,000.00 - $121,000.00
Benefit Overview: This position offers a comprehensive benefits package including medical, dental, and vision insurance, a 401(k) with company match, paid time off, parental leave.
Fresenius Medical Care maintains a drug-free workplace in accordance with applicable federal and state laws.