> Markdown version of [/jobs/ext/3057539-information-security-risk-analyst](https://www.wearedevelopers.com/jobs/ext/3057539-information-security-risk-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Risk Analyst - **Company:** TalentFish LLC - **Location:** Chicago, IL, United States (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Security Management, Information Technology - **Published:** September 24, 2026 - **Apply:** https://www.juju.com/job/16_b79c16d9 ## About the Role * Bachelor's degree required in Information Security, Computer Science, Engineering, Information Technology, or a related field; master's degree preferred. * 3+ years of experience in cybersecurity, information security risk management, or audit; healthcare industry experience strongly preferred. * Demonstrated experience with risk assessment methodologies, auditing, information security practices, and familiarity with risk management platforms and risk registers. * Strong understanding of regulatory compliance and industry best practices for maintaining compliance with HIPAA, NIST, and other relevant healthcare regulations and standards. * One or more of the following certifications required, or must be obtained within 12 months of hire: CRISC, CISM, CISA, or any other applicable certification. * Ability to lead and structure risk assessments with limited supervision, and manage multiple concurrent assessments and projects in a fast-paced healthcare setting. * Experience preparing both detailed technical risk reports and executive-level summaries tailored to varied audiences. * Strong written, verbal, and interpersonal communication skills, with the ability to translate technical findings into business-relevant language for leadership audiences. * Experience tracking audit findings, third-party vendor risks, and remediation efforts, and analyzing contractual security language to identify risk exposure. ## Description * Lead and conduct comprehensive information security risk analysis for IT assets, applications, processes, medical devices, and third-party vendors. * Evaluate threats and vulnerabilities affecting the confidentiality, integrity, and availability of ePHI and other confidential or sensitive information, ensuring alignment with HIPAA Security Rule requirements and other applicable regulatory frameworks (e.g., NIST). * Lead and manage risk management initiatives based on analysis of outcomes, including maintaining the organization's risk register and scoring methodology. * Oversee corrective action plans (CAPs), penetration testing results, audit findings, and risk treatment outcomes. * Collaborate with IT partners and key stakeholders to prioritize, implement, and track remediation efforts. * Monitor regulatory changes and industry threats to proactively identify emerging risks, recommend mitigation strategies, and document findings. * Contribute to risk reporting, including executive dashboards, and participate in risk acceptance processes and governance reviews. * Contribute to the development, review, and improvement of cybersecurity policies, standards, and procedures, and evaluate policy exceptions for governance committees. * Enhance the organization's cybersecurity awareness and training efforts by communicating risk insights to technical and non-technical audiences. ## Related Videos - [Don't Be A Naive Developer: How To Avoid Basic Cybersecurity Mistakes](https://www.wearedevelopers.com/videos/498-don-t-be-a-naive-developer-how-to-avoid-basic-cybersecurity-mistakes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)