> Markdown version of [/jobs/ext/1150234-information-security-analyst-grc](https://www.wearedevelopers.com/jobs/ext/1150234-information-security-analyst-grc). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Analyst (GRC) - **Company:** Boston Childrens Health Physicians LLP - **Location:** Valhalla, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $100,000.0 - $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Software System Penetration Testing, Cyber Security, Information Systems, Information Security Management, Information Technology Audit, Phishing, Information Technology, CIS Benchmarks, Servicenow - **Published:** July 2, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=492226fb8b81962c ## About the Role * Bachelor's degree in information security, Cybersecurity, Information Technology, Business, or related field (or equivalent experience). * 3+ years of experience in Information Security, IT Audit, Risk Management, Compliance, or Governance. * Knowledge of: + HIPAA Security Rule + NIST Cybersecurity Framework + CIS Controls + Security Risk Assessments + Vendor Risk Management + Security Policies and Procedures * Strong documentation, analytical, and organizational skills. * Excellent communication and presentation abilities. Preferred * Experience in healthcare, healthcare technology, or regulated environments. * Experience supporting security audits and regulatory assessments. * Familiarity with: + Microsoft 365 Security & Compliance + Microsoft Purview + Microsoft Defender + Sentinel + CrowdStrike + Proofpoint + ServiceNow or similar ticketing platforms Preferred Certifications * Security+ * GSEC * SSCP * CISA * CRISC * CGRC (formerly CAP) * CISSP (or pursuing) ## Description Boston Children's Health Physicians (BCHP) is seeking an experienced IT Security Analyst - Governance, Risk & Compliance (GRC) to support and mature our enterprise information security program. This position will play a key role in helping BCHP strengthen cybersecurity governance, manage risk, maintain regulatory compliance, oversee security assessments, support third-party risk management, and drive continuous improvement across our security program. The ideal candidate will serve as a bridge between Information Security, Compliance, Operations, and external service providers, helping ensure BCHP maintains a strong security posture while supporting the delivery of quality patient care. This role reports directly to the Senior Director, Information Systems & Information Security (Security Officer). Budget for position * $100,000-$140,000 per year based on qualifications. Role and Responsibilities Governance & Compliance * Support the development, maintenance, and continuous improvement of BCHP's Information Security Program. * Assist with security policy development, review, implementation, and lifecycle management. * Monitor compliance with HIPAA, HITECH, NIST Cybersecurity Framework, CIS Controls, and organizational security standards. * Track remediation efforts resulting from audits, assessments, and risk analyses. * Maintain security governance documentation, evidence repositories, and compliance records. Risk Management * Conduct and document security risk assessments. * Assist with enterprise risk identification, analysis, and mitigation planning. * Maintain risk registers and remediation tracking activities. * Participate in annual Security Risk Assessments (SRA) and third-party assessments. Vendor & Third-Party Risk Management * Perform security reviews of vendors, business associates, and service providers. * Review security questionnaires, SOC reports, penetration test summaries, and related documentation. * Track vendor remediation activities and ongoing monitoring requirements. * Support Business Associate Agreement (BAA) and security review processes. Audit & Assessment Support * Coordinate internal and external security audits. * Gather evidence and documentation for regulatory, compliance, and customer audits. * Assist with preparation for HIPAA, cybersecurity, and third-party assessments. * Monitor corrective action plans through completion. * Security Awareness & Training * Support enterprise security awareness initiatives. * Assist with phishing simulation programs and training campaigns. * Track workforce training completion and reporting metrics. Security Program Reporting * Develop security metrics, dashboards, and executive reports. * Monitor compliance with security policies and standards. * Provide recommendations for program improvements and risk reduction., This position offers significant visibility across the organization and the opportunity to directly influence the future direction of BCHP's security and compliance program. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)