What are the responsibilities and job description for the Governance Risk and Compliance Analyst (On-Site) position at Ob Hospitalist Group?
Governance, Risk, and Compliance (GRC) Analyst Summary: A Cybersecurity Governance, Risk, and Compliance (GRC) Analyst is responsible for ensuring an organization adheres to industry best practices and regulatory requirements by identifying, assessing, and mitigating cybersecurity risks, developing and implementing compliance frameworks, and monitoring ongoing adherence to security policies, all while collaborating with various stakeholders to maintain a robust security posture.
Governance, Risk, and Compliance Analyst Essential Responsibilities:
Risk Assessment and Analysis:
-
- Conduct regular risk assessments to identify potential cybersecurity threats and vulnerabilities across the organization's systems, networks, and applications.
- Analyze risk factors and prioritize critical risks based on their potential impact and likelihood of occurrence.
- Develop mitigation strategies and action plans to address identified risks.
Compliance Management:
-
- Monitor adherence to relevant cybersecurity regulations and industry standards (e.g., GDPR, NIST, ISO 27001, PCI DSS).
- Conduct compliance audits and assessments to identify gaps and ensure necessary controls are in place.
- Develop and maintain compliance documentation, including policies, procedures, and control matrices.
Policy Development and Implementation:
-
- Collaborate with security teams to draft and implement cybersecurity policies and procedures aligned with risk assessments and compliance requirements.
- Communicate security policies and procedures to relevant stakeholders across the organization.
Vendor Risk Management:
-
- Evaluate the security posture of third-party vendors and suppliers to identify potential risks associated with data sharing and access.
- Implement vendor risk management processes to ensure third-party compliance with security standards.
Incident Response Support:
-
- Assist in incident response activities by analyzing security incidents, identifying root causes, and contributing to post-incident remediation plans.
Reporting and Communication:
-
- Prepare regular reports on cybersecurity risk assessments, compliance status, and mitigation efforts for senior management.
- Communicate key security risks and compliance concerns to relevant stakeholders across the organization.
Essential Skills/Credentials/Experience/Education
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or related field/equivalent experience
- 3 years of experience in cybersecurity, governance, risk management, and compliance.
- Knowledge of GRC platforms and tools (e.g., Archer, OneTrust, ZenGRC)
- Strong understanding of cybersecurity concepts, including network security, application security, identity and access management, data protection, and threat intelligence.
- Expertise in relevant compliance frameworks like NIST, ISO 27001, GDPR, HIPAA, and PCI DSS.
- Experience with risk assessment methodologies and tools
- Proven ability to analyze complex data and present findings effectively to both technical and non-technical audiences
- Excellent communication and collaboration skills to work with cross-functional teams
Preferred Skills/Credentials/Experience/Education
- Master's degree in Cybersecurity, Information Assurance or related field preferred
- Certifications in Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk, and Compliance (CGRC), and Certified Compliance & Ethics Professional (CCEP) preferred
Mental and Physical Demands (per ADA guidelines)
Physical Demands:
-
- Sitting for long periods of time. Occupation requires this activity more than 66% of the time (5.5 hrs/day) Travel Demands:
Travel Demands:
-
- Minimal travel, less than 5%
Annual Compensation: $80,000 - $115,000 (based on experience)
What We Offer - The Good Stuff:
- A mission based company with an amazing company culture.
- Paid time off & holidays so you can spend time with the people you love.
- Medical, dental, and vision insurance for you and your loved ones.
- Health Savings Account (with employer contribution) or Flexible Spending Account options.
- Paid Parental Leave
- Employer Paid Basic Life and AD&D Insurance.
- Employer Paid Short- and Long-Term Disability.
- Optional Short Term Disability Buy-up plan.
- 401(k) Savings Plan, with ROTH option.
- Legal Plan.
- Identity Theft Services.
- Mental health support and resources.
- Employee Referral program – join our team, bring your friends, and get paid.
Salary : $80,000 - $115,000