Mercy Health

Cybersecurity GRC Analyst

Mercy Health$85K — $137K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Business Administration, or related field
  • 3+ years experience in IT compliance, internal auditing, or cybersecurity risk management
  • Experience in a healthcare or highly regulated industry, directly related to HIPAA compliance
  • Experience with Governance, Risk and Compliance (GRC) platforms
  • Familiarity with cloud environments like Azure or AWS

Responsibilities

  • Conduct audits for compliance against standards like HIPAA and NIST CSF
  • Assess third-party vendors for security risks
  • Maintain internal risk register and track corrective actions
  • Perform targeted cybersecurity risk assessments
  • Conduct phishing simulations across the organization
  • Coordinate with IT, Legal, and Compliance teams to enforce governance
  • Develop and maintain corporate security policies and procedures

Benefits

  • Medical, Dental, Vision insurance
  • Life & Disability Insurance
  • Generous paid time off
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement
  • Well-being programs
  • Employee discounts and financial education
Full Job Description
ESSENTIAL DUTIES AND RESPONSIBILITIES
  • Conducts and facilitates internal and external audits against established compliance requirements and frameworks (e.g. HIPAA, Security Operations Center (SOC) 2, National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
  • Assesses third-party vendors for security risks prior to and during business relationships
  • Maintains internal risk register and tracks corrective action plans
  • Performs targeted cybersecurity risk assessments to identify vulnerabilities, misconfigurations, and compliance deviations
  • Conducts phishing attack simulations across the organization
  • Coordinates between Information Technology (IT), Privacy, Legal and Compliance to enforce governance objectives
  • Develops and maintains corporate security policies, procedures and standards aligned with business objectives
  • Provides oversight for Disaster Recovery/Business Continuity programs
  • Creates, updates and maintains cybersecurity metrics and awareness training materials
  • Promotes awareness and understanding of security policies across the organization


EDUCATION AND/OR EXPERIENCE

Minimum Required:

Bachelor's degree in Computer Science, Information Security, Business Administration or related field

Preferred:
  • 3+ years experience in IT compliance, internal auditing or cybersecurity risk management
  • Prefer experience in a healthcare or other highly regulated industry with direct exposure to HIPAA compliance requirements
  • Exposure to Identity and Access Management programs
  • Exposure to Vulnerability Management programs


CERTIFICATION/LICENSURE

Minimum Required:

N/A

Preferred:
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)


OTHER SKILLS AND ABILITIES

Technical Skills:
  • Audit experience using HIPAA, Health Information Trust Alliance (HITRUST), NIST or similar frameworks
  • Experience with Governance, Risk and Compliance/ Integrated Risk Management (GRC/IRM) platforms (e.g. Apptega, Archer, ServiceNow)
  • Experience with email security platforms (e.g. Knowbe4, Proofpoint Zen)
  • Familiarity with vulnerability scanners and SOC solutions (Security Information and Event Management/Security Orchestration, Automation, and Response (SIEM/SOAR)
  • Familiarity with cloud environments (e.g. Azure, Amazon Web Services (AWS)
  • Excellent Microsoft Word, Excel and PowerPoint skills

Core Competencies:
  • Strong communication skills, both written and verbal.
  • Ability to follow instructions and procedures accurately.
  • Demonstrated problem-solving and critical-thinking abilities.
  • Ability to work independently and as part of a team.
  • Commitment to maintaining confidentiality and ethical standards.
  • Adaptability to changing priorities and environments.
  • Customer service orientation and cultural sensitivity.


PAY RANGE:

$85,657.09 - $137,051.35

Mercyhealth offers competitive pay and a comprehensive benefits package including:

  • Medical, Dental, Vision
  • Life & Disability Insurance
  • FSA/HSA Options
  • Generous, accruing paid time off
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement
  • Certification Reimbursement
  • Well-being Programs
  • Employee Discounts
  • On-Demand Pay
  • Financial Education
  • Annual recognition/awards events
  • Partner appreciation days
  • Family entertainment/attractions discount
  • Community service/improvement opportunities


Click here for more details regarding Mercyhealth Careers Benefit Information.

About Mercy Health

Mercy Health is a Catholic healthcare ministry serving Ohio and Kentucky. They offer a wide range of healthcare services, including primary care, specialty care, and hospital care. Mercy Health operates over 250 healthcare facilities, including hospitals, clinics, and outpatient centers. Their mission is to provide compassionate, quality healthcare to all who need it, regardless of their ability to pay.
Learn more about Mercy Health
Size
45,000 employees
Industry
Founded
1985

Similar Jobs

More Jobs at Mercy Health

More Healthcare Jobs

Find similar Cybersecurity GRC Analyst jobs: