Mercy Health

Cybersecurity GRC Analyst

Mercy Health$85K — $137K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Business Administration or related field
  • 3+ years experience in IT compliance, internal auditing or cybersecurity risk management preferred
  • Experience in a healthcare or highly regulated industry with HIPAA exposure preferred
  • Exposure to Identity and Access Management and Vulnerability Management programs preferred
  • CISA or CISSP certification is preferred

Responsibilities

  • Conduct internal and external audits for compliance with frameworks like HIPAA and NIST CSF
  • Assess security risks associated with third-party vendors
  • Maintain and track the internal risk register and corrective actions
  • Perform cybersecurity risk assessments to identify vulnerabilities and compliance gaps
  • Conduct phishing attack simulations to evaluate organizational readiness
  • Coordinate with IT, Privacy, Legal, and Compliance to meet governance objectives
  • Develop and maintain corporate security policies and standards

Benefits

  • Medical, Dental, Vision insurance
  • Life & Disability Insurance
  • Flexible Spending Account (FSA) and Health Savings Account (HSA) options
  • Generous paid time off that accrues over time
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement options
  • Well-being programs and employee discounts
  • On-Demand Pay and financial education resources
  • Annual recognition and awards events
Full Job Description
ESSENTIAL DUTIES AND RESPONSIBILITIES
  • Conducts and facilitates internal and external audits against established compliance requirements and frameworks (e.g. HIPAA, Security Operations Center (SOC) 2, National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
  • Assesses third-party vendors for security risks prior to and during business relationships
  • Maintains internal risk register and tracks corrective action plans
  • Performs targeted cybersecurity risk assessments to identify vulnerabilities, misconfigurations, and compliance deviations
  • Conducts phishing attack simulations across the organization
  • Coordinates between Information Technology (IT), Privacy, Legal and Compliance to enforce governance objectives
  • Develops and maintains corporate security policies, procedures and standards aligned with business objectives
  • Provides oversight for Disaster Recovery/Business Continuity programs
  • Creates, updates and maintains cybersecurity metrics and awareness training materials
  • Promotes awareness and understanding of security policies across the organization


EDUCATION AND/OR EXPERIENCE

Minimum Required:

Bachelor's degree in Computer Science, Information Security, Business Administration or related field

Preferred:
  • 3+ years experience in IT compliance, internal auditing or cybersecurity risk management
  • Prefer experience in a healthcare or other highly regulated industry with direct exposure to HIPAA compliance requirements
  • Exposure to Identity and Access Management programs
  • Exposure to Vulnerability Management programs


CERTIFICATION/LICENSURE

Minimum Required:

N/A

Preferred:
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)


OTHER SKILLS AND ABILITIES

Technical Skills:
  • Audit experience using HIPAA, Health Information Trust Alliance (HITRUST), NIST or similar frameworks
  • Experience with Governance, Risk and Compliance/ Integrated Risk Management (GRC/IRM) platforms (e.g. Apptega, Archer, ServiceNow)
  • Experience with email security platforms (e.g. Knowbe4, Proofpoint Zen)
  • Familiarity with vulnerability scanners and SOC solutions (Security Information and Event Management/Security Orchestration, Automation, and Response (SIEM/SOAR)
  • Familiarity with cloud environments (e.g. Azure, Amazon Web Services (AWS)
  • Excellent Microsoft Word, Excel and PowerPoint skills

Core Competencies:
  • Strong communication skills, both written and verbal.
  • Ability to follow instructions and procedures accurately.
  • Demonstrated problem-solving and critical-thinking abilities.
  • Ability to work independently and as part of a team.
  • Commitment to maintaining confidentiality and ethical standards.
  • Adaptability to changing priorities and environments.
  • Customer service orientation and cultural sensitivity.


PAY RANGE:

$85,657.09 - $137,051.35

Mercyhealth offers competitive pay and a comprehensive benefits package including:

  • Medical, Dental, Vision
  • Life & Disability Insurance
  • FSA/HSA Options
  • Generous, accruing paid time off
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement
  • Certification Reimbursement
  • Well-being Programs
  • Employee Discounts
  • On-Demand Pay
  • Financial Education
  • Annual recognition/awards events
  • Partner appreciation days
  • Family entertainment/attractions discount
  • Community service/improvement opportunities


Click here for more details regarding Mercyhealth Careers Benefit Information.

About Mercy Health

Mercy Health is a Catholic healthcare ministry serving Ohio and Kentucky. They offer a wide range of healthcare services, including primary care, specialty care, and hospital care. Mercy Health operates over 250 healthcare facilities, including hospitals, clinics, and outpatient centers. Their mission is to provide compassionate, quality healthcare to all who need it, regardless of their ability to pay.
Learn more about Mercy Health
Size
45,000 employees
Industry
Founded
1985

Similar Jobs

More Jobs at Mercy Health

More Healthcare Jobs

Find similar Cybersecurity GRC Analyst jobs: