What are the responsibilities and job description for the Senior Analyst, Risk & Security - FedRAMP position at Press Ganey?
The Security Analyst, Risk and Security is an individual contributor in Press Ganey's Information Security team and is responsible for reviewing and auditing controls that manage information risk and security. The duties of each member of the security team can fluctuate based on needs and risks, but this analyst will be primarily responsible for ensuring that the organization's security practices remain in compliance with all internal policies, pertinent laws and regulations, and client commitments. While this is not a primarily technical role, the analyst is expected to understand information security practices and technologies from an audit and compliance perspective.
All analysts in the Risk and Security team are expected to design, implement, govern, and evaluate security policies, technologies, solutions, and processes to secure corporate applications, data, computers, and networks. As a contributor to the team, this analyst will be expected to stay informed of information security practices, changes to the company environment and act as a trusted subject matter expert for the team.
The Security Analyst, Risk and Security is responsible for :
- Managing, triaging, and responding to third party auditor requests for artifacts related to the organization’s Information Security Management Program
- Requesting, submitting and filing artifacts related to the completion of third party audits
- The primary focus of this role is the project management and maintenance of FEDRAMP authorization and support work related to other audit frameworks in use at PG Forsta to include : HITRUST CSF, SOC 2, ISO 27001, and TX-RAMP authorization
The security team at Press Ganey has created a culture of growth and gratitude. Press Ganey has acquired more than 20 companies in the past 10 years, so the right candidate will be prepared to deal with a rapidly changing environment. For this role, we’re focused on finding someone with a passion for security with a background in FedRAMP authorization program maintenance and other activities in conjunction with other audit and governance practices. This job will involve meeting with all levels of the organization to measure compliance with security policies and working with a team of skilled security analysts.
This position will have no direct reports. This is a remote work position that will require occasional travel (1-2 times per year).In addition, working hours may vary and limited on-call time may be required.
Duties and Responsibilities
Audit and Internal Controls Monitoring
Policy and Governance
Data Protection and Risk Management
Qualifications
Education / training : Bachelor’s degree or equivalent experience.
Experience : 3 years
Minimum of 3 years’ experience directly related to the management and maintenance of a FedRAMP authorization program including the creation and submission of POAM artifacts, working with clients, 3PAOs, assessment firms and other program related entities.
Minimum 3 years’ of IT, audit, or risk management experience in one or more of the following frameworks : HITRUST CSF, SOC2, ISO 27001.
Minimum 3 years’ experience working in a government regulated industry, such as healthcare or finance.
Basic knowledge of and ability to use system security and controls including firewall and anti-virus software, identity management, and computer control environments.
Basic knowledge of business theory, business processes, management, budgeting, and business office operations.
Teamwork : An individual who can work effectively in a collaborative environment and foster teamwork across all levels of the organization and also work independently as required.
Technical Expertise : The job holder must have a background in information security, development, or networking.
Business Acumen : The job holder should possess intermediate analytical and process management skills and have a broad understanding of business strategy and operations.
Compliance & Ethics Expectations :
Special Working Conditions
If the job requires a person to work in special working conditions this should be stated in the job description. Special working conditions may include working outside of normal business hours, shift work, extensive travel, etc.
Special Physical Requirements
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.