Enter a job title or keyword

Sr. Third Party Cybersecurity GRC Analyst

Elevance Health


Job Location:

Atlanta, GA - USA

Monthly Salary: Not provided by the employer
Posted: 5 June 2026 (30+ days ago)
Application Deadline: 2 September 2026
Vacancies: 1 Vacancy
The job posting is outdated and position may be filled

Job Summary

Anticipated End Date:

Position Title:

Sr. Third Party Cybersecurity GRC Analyst

Job Description:

Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst)

Information Security Risk Management

Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis IN or Atlanta GA office fostering collaboration and connectivity while providing flexibility to support productivity and work-life balance. This approach combines structured office engagement with the autonomy of virtual work promoting a dynamic and adaptable workplace.

  • Please note that per our policy on hybrid/virtual work candidates not within a reasonable commuting distance from the posting location(s) will not be considered for employment unless an accommodation is granted as required by law.

The Security Analyst Sr. is responsible for independently assessing documenting and monitoring cybersecurity risks associated with third-party vendors service providers and business partners. This role evaluates vendor security controls reviews assurance evidence identifies control gaps supports remediation and risk acceptance decisions and provides subject matter expertise throughout the vendor lifecycle.

How you will make an impact:

  • Support internal and external audit and compliance activities including HIPAA HITRUST NIST PCI DSS SOC 2 and other healthcare or cybersecurity-related assessments.
  • Lead cybersecurity risk assessments and due diligence reviews for third-party vendors service providers SaaS platforms cloud providers and other external business partners including high-risk and critical vendors.
  • Evaluate vendor security documentation including SOC reports ISO certifications HITRUST certifications penetration test summaries security questionnaires policies data flow diagrams and remediation evidence.
  • Communicate directly with vendors to clarify questionnaire responses request supporting evidence validate remediation status and coordinate risk mitigation activities.
  • Provides trouble resolution on complex problems and leads implementations for system and network security technologies.
  • Develops testing plans to ensure quality of implementation; coordinates and prepares the reporting of data security events and incidents; provides system and network architecture support for information and network security technologies
  • Provides technical support to business and technology associates in risk assessments and implementation of appropriate information security procedures standards and technologies
  • Represents major upgrades and reconfigurations in change control
  • Design & analyze mix of vendor services meeting business and information security requirements
  • Determine and perform complex configuration changes to meet business and information security requirements
  • Serve as the technical escalation for results of preventative maintenance routines
  • Participate in metrics development trend analysis quality reviews and program maturity initiatives to strengthen Elevance Healths third-party cybersecurity risk management program.
  • Represents infrastructure security support in significant projects and performs the most complex operations and administration tasks
  • Respond to level 3 & 4 change and problem requests without supervision
  • Lead level 1 & 2 incident recoveries and root cause analysis.

Minimum Requirements:

  • Requires a bachelors degree or equivalentcombination of education and experience that would provide the knowledge to perform such work.
  • Experience must include a minimum of 3 years experience in a support & operations or design & engineering role in any of the following areas: access management or network security technologies servers networks Network communications telecommunications operating systems middleware disaster recovery collaboration technologies hardware/software support or other infrastructure services role; or any combination of education and experience which would provide an equivalent background.
  • Requires experience providing top-tier support for 3 or more of the information security technology areas: 1) Access Control 2) Application Security 3) Business Continuity and Disaster Recovery Planning 4) Cryptography 5) Information Security and Risk Management 6) Legal Regulations 7) Compliance and Investigations 8) Operations Security 9) Physical (Environmental) Security 10) Security Architecture and Design 11) Telecommunications and Network Security.

Preferred Skills Capabilties and Experiences

  • Technical security certifications ( Security Certified Practitioner) strongly degree in Information System and Computer Science or related field of study strongly preferred.
  • 35 years of experience in cybersecurity third-party risk management IT risk GRC IT audit regulatory compliance vendor risk management or a related field.
  • Familiarity with common cybersecurity frameworks standards and assurance reports such as NIST CSF NIST SP 800-53 NIST SP 800-161 ISO 27001/27002 SOC 2 CIS Controls Shared Assessments SIG CSA CAIQ or CSA CCM.
  • Experience with ServiceNow GRC/IRM Vendor Security Risk Management or similar third-party risk management workflows.
  • Experience performing third-party cybersecurity assessments in healthcare insurance financial services or another regulated industry.
  • Familiarity with HIPAA HITRUST NIST PCI DSS SOC 2 ISO 27001 cloud security and privacy/data protection control expectations.
  • Experience reviewing SOC 2 Type II reports ISO 27001 certificates HITRUST reports PCI Attestations of Compliance penetration test summaries vendor security questionnaires data flow diagrams and technical remediation evidence.
  • Relevant certification such as CISA CRISC CISSP CISM Security CCSK CCSP ISO 27001 Lead Auditor/Implementer AWS Certified Cloud Practitioner or PCI DSS-related experience

Job Level:

Non-Management Exempt

Workshift:

Job Family:

IFT > IT Security & Compliance

Please be advised that Elevance Health only accepts resumes for compensation from agencies that have a signed agreement with Elevance Health. Any unsolicited resumes including those submitted to hiring managers are deemed to be the property of Elevance Health.


Who We Are

Elevance Health is a health company dedicated to improving lives and communities and making healthcare simpler. We are a Fortune 25 company with a longstanding history in the healthcare industry looking for leaders at all levels of the organization who are passionate about making an impact on our members and the communities we serve.


How We Work

At Elevance Health we are creating a culture that is designed to advance our strategy but will also lead to personal and professional growth for our associates. Our values and behaviors are the root of our culture. They are how we achieve our strategy power our business outcomes and drive our shared success - for our consumers our associates our communities and our business.


We offer a range of market-competitive total rewards that include merit increases paid holidays Paid Time Off and incentive bonus programs (unless covered by a collective bargaining agreement) medical dental vision short and long term disability benefits 401(k) match stock purchase plan life insurance wellness programs and financial education resources to name a few.


Elevance Health operates in a Hybrid Workforce Strategy. Unless specified as primarily virtual by the hiring manager associates are required to work at an Elevance Health location at least once per week and potentially several times per week. Specific requirements and expectations for time onsite will be discussed as part of the hiring process.


The health of our associates and communities is a top priority for Elevance Health. We require all new candidates in certain patient/member-facing roles to become vaccinated against COVID-19 and Influenza. If you are not vaccinated your offer will be rescinded unless you provide an acceptable explanation. Elevance Health will also follow all relevant federal state and local laws.


Elevance Health is an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to age citizenship status color creed disability ethnicity genetic information gender (including gender identity and gender expression) marital status national origin race religion sex sexual orientation veteran status or any other status or condition protected by applicable federal state or local laws. Applicants who require accommodation to participate in the job application process should submit the following form: Accessibility Accommodation Request Form and a member of the team will be in contact. Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal state and local laws including but not limited to the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.


Prospective employees required to be screened under Florida law should review the education and awareness resources at HB531 Florida Agency for Health Care Administration.


NOTE: Workday keeps job postings active through 11:59:59 PM on the day before the listed end date. Example: If the end date is 3/13 the posting will automatically come down on 3/12 at 11:59:59 other words the job is posted until 3/13 not through 3/13.


Required Experience:

Senior IC


About Company

Company Logo

Elevance Health, formerly Anthem, Inc., serves people across their entire health journey taking an integrated whole-health approach.

View Profile View Profile