Cottage Health

Governance Risk & Compliance Analyst Senior

Cottage Health$90K — $120K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science or related field, or 8 years of equivalent experience
  • One or more industry certifications such as CISA, CISM, CISSP, or similar
  • Working knowledge of HIPAA, PCI, and cybersecurity governance frameworks
  • 3-5 years of experience in IT audit, risk management, or information security compliance
  • Ability to operate independently with limited supervision

Responsibilities

  • Lead and maintain security governance, risk, and compliance initiatives
  • Conduct security risk assessments and manage the enterprise Security Risk Register
  • Support HIPAA, PCI, and other regulatory compliance activities
  • Assess third-party vendors and monitor compliance with security requirements
  • Develop security metrics and report risk and compliance status to leadership
  • Create and maintain security policies, standards, and governance processes
  • Recommend risk mitigation strategies and drive remediation efforts

Benefits

  • Comprehensive Total Rewards offerings
  • Eligible for additional forms of compensation such as shift differentials and on-call pay
  • Incentive pay and bonus opportunities for eligible employees
  • Participation in annual management incentive program for managerial positions
  • Support for professional certifications and continuous learning opportunities
Full Job Description
Job Description

Cottage Health seeks a Governance Risk & Compliance Analyst Senior for their CH ITS Security department. This position will lead security governance, risk management, and compliance activities across the organization. This role partners with IT, business, and vendor stakeholders to identify security risks, ensure regulatory compliance, and strengthen Cottage Health's overall security program and risk management capabilities. Key responsibilities include:
  • Lead and maintain security governance, risk, and compliance initiatives.
  • Conduct security risk assessments and manage the enterprise Security Risk Register.
  • Support HIPAA, PCI, and other regulatory compliance activities.
  • Assess third-party vendors and monitor compliance with security requirements.
  • Develop security metrics and report risk and compliance status to leadership.
  • Create and maintain security policies, standards, and governance processes.
  • Recommend risk mitigation strategies and drive remediation efforts.


Qualifications

All job qualifications listed indicate the minimum level necessary to perform this job proficiently.

LEVEL OF EDUCATION

Minimum: Bachelor's Degree in Computer Science or related field; or equivalent experience (8 years)

CERTIFICATIONS, LICENSES, REGISTRATIONS

Minimum: One or more of the following industry certifications: Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP),Certified in Risk and Information Systems Control (CRISC), SANS Security Awareness Professional, CompTIA Security+, CompTIA CySA+ Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Security Essentials (GSEC), Certified Cloud Security Professional (CCSP), Systems Security Certified Practitioner (SSCP), Advanced in AI Audit (AAIA), Certified Data Privacy Solutions Engineer (CDPSE), Certified in the Governance of Enterprise IT (CGEIT), Certified Cybersecurity Operations Analyst (CCOA)

TECHNICAL REQUIREMENTS

Minimum: Working knowledge of HIPAA, PCI, and cybersecurity governance frameworks

YEARS OF RELATED WORK EXPERIENCE

Minimum: 3-5 years of IT audit, risk management, or information security compliance experience, operating independently with limited supervision

*Pay for non-physician positions is determined based on related years of experience and internal equity. Eligible employees may also receive additional forms of compensation, including shift differentials, on-call pay, incentive pay, and bonus opportunities, where applicable. Manager and above positions may participate in Cottage Health's annual management incentive program. Physician compensation is determined based upon specialty and may include bonus potential. For more information on our comprehensive Total Rewards offerings, please visit https://cottagehealth.org/careers/total-rewards.

If you're already a Cottage Health employee, please apply on this link only.

About Cottage Health

Cottage Health is a not-for-profit health care system that operates hospitals, clinics, and other health care facilities in the Santa Barbara area. The system includes three hospitals: Santa Barbara Cottage Hospital, Goleta Valley Cottage Hospital, and Santa Ynez Valley Cottage Hospital. Cottage Health also operates a network of primary care and specialty clinics throughout the region. The system is committed to providing high-quality, compassionate care to its patients, and has been recognized for its excellence in clinical outcomes and patient satisfaction. Cottage Health is a major employer in the Santa Barbara area, with more than 4,000 employees.
Learn more about Cottage Health
Size
4,000 employees
Industry
Net Income
$50 million
5 Year Trend
+5%
Revenue
$800 million

Similar Jobs

More Jobs at Cottage Health

More Healthcare Jobs

Find similar Governance Risk & Compliance Analyst Senior jobs: