IT Security Risk Management Analyst (Policy Reviewer & Policy Writer) SOC or ISO or NIST + Audit
Job Summary
THE POSITION:
The IT Security Risk Management Analyst is a key contributor to EVERSANAs IT Risk & Compliance team placed within EVERSANAs Information Security service line. This person will be responsible for performing security focused evaluations of governance risk and compliance of EVERSANAs Information Assets.
This rewarding position will also help with the continued development and operations of several IT governance and compliance activities. These are oriented towards objectively evaluating security control performance across the enterprise and alignment of security controls with business objectives. Further this role will assist other team members on the IT Risk & Compliance team and EVERSANAs Security Operations team to evaluate risks threats and opportunities for mitigation strategies in support of sound security practices.
Critical RESPONSIBILITIES:
Business Partner Support 40%
- Support internal business partners with information and responses in requests from EVERSANA clients exploring security and general IT capabilities.
- Perform security focused assessments on EVERSANAs third party suppliers and vendors to assess potential risks and communicate impacts to IT and business leaders.
- Perform security focused assessments on EVERSANAs clients to assess potential risks and communicate impacts to IT and business leaders.
Policy Governance and Review- 10%
- Review analyze and maintain Information Security policies standards procedures and guidelines to ensure alignment with business objectives regulatory requirements and industry best practices.
- Conduct periodic reviews of existing security policies and recommend updates based on changes in regulations emerging threats technology implementations and organizational requirements.
- Coordinate policy review cycles with stakeholders control owners and business leaders to ensure timely approval and implementation of policy updates.
- Evaluate policy exceptions and deviations assess associated risks and provide recommendations for risk treatment and management approval.
Policy Development and Writing- 10%
- Draft develop and maintain Information Security policies standards procedures and supporting documentation in accordance with frameworks such as ISO 27001 NIST HIPAA and applicable regulatory requirements.
- Collaborate with technical and business stakeholders to translate security compliance and operational requirements into clear and actionable policy documentation.
- Ensure policy documentation is written in a consistent format understandable to both technical and non-technical audiences and supports organizational compliance objectives.
- Monitor changes in regulatory legal and industry requirements and update policy documentation to address evolving compliance obligations.
- Risk Management Operations 10%
- Support and perform various risk assessment processes to develop threat models for various EVERSANA business lines as well as improving awareness of financial and operational impacts identified risks posed to EVERSANA.
- Develop review and maintain Information Security policies standards and procedures to ensure alignment with organizational risk management objectives regulatory requirements and industry best practices while facilitating stakeholder review approval and compliance monitoring.
Security Control Audit Support 30%
- Monitor and facilitate audit activities for SOC 1 SOC 2 HIPAA risk assessments and follow up activities of remediation for issues / findings identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place.
- Monitor and facilitate audit remediation activities identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place.
- Work with IT Risk & Compliance team members to identify security controls applicable to various service lines.
- Support the draft and creation of reporting to senior leadership.
- Conduct periodic internal testing and auditing to support security control compliance.
- Support internal and external audits by providing policy documentation evidence of policy reviews approval records and demonstrating compliance with applicable security frameworks and regulatory requirements.
- Four or more years of experience in an auditing role (Information Technology OR Compliance) OR two or more years of experience with risk management practices.
- Two or more years of experience with third party risk assessments.
- Experience in creating summary reports for a broad range of audiences including senior leadership.
- Competent understanding of auditing practices (ex. SOC1 or SOC2 ISO27000)
- Understanding of Security Standards like ISO27001 PCI DSS HIPAA NIST 800-53
- Experience with risk management methodologys (quantitative assessments FAIR HIPAA security assessment) and their utilization.
- Excellent analytical project management and problem-solving skills
- Experience in drafting reviewing and maintaining Information Security policies standards procedures and governance documentation.
- Strong understanding of policy lifecycle management document governance and regulatory compliance requirements.
- Excellent technical writing documentation management and stakeholder communication skills.
Qualifications :
Preferred qualifications:
- required- 2-5
Industry Certification such as CISA CIA CRISC TPCRA ISO 27000 Internal Auditor or Open FAIR
Additional Information :
All your information will be kept confidential according to EEO guidelines.
Our team is aware of recent fraudulent job offers in the market misrepresenting EVERSANA. Recruitment fraud is a sophisticated scam commonly perpetrated through online services using fake websites unsolicited e-mails or even text messages claiming to be a legitimate company. Some of these scams request personal information and even payment for training or job application fees. Please know EVERSANA would never require personal information nor payment of any kind during the employment process. We respect the personal rights of all candidates looking to explore careers at EVERSANA.
From EVERSANAs inception Diversity Equity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths experiences and backgrounds who share a passion for improving the lives of patients and leading innovation within the healthcare industry. Diversity not only includes race and gender identity but also age disability status veteran status sexual orientation religion and many other parts of ones identity. All of our employees points of view are key to our success and inclusion is everyones responsibility.
Remote Work :
No
Employment Type :
Full-time
About Company
At EVERSANA, we are proud to be certified as a Great Place to Work across the globe. We’re fueled by our vision to create a healthier world. How? Our global team of more than 7,000 employees is committed to creating and delivering next-generation commercialization services to the life ... View more