Information Security Risk Analyst - Intermediate

Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Technology, or related field; master's preferred.
  • 3+ years of experience in cybersecurity, risk management, or audit, preferably in healthcare.
  • Familiarity with risk assessment methodologies and risk management platforms.
  • Strong understanding of HIPAA, NIST, and other healthcare regulations.
  • Certification in CRISC, CISM, CISA, or other relevant certification is required within 12 months.
  • Ability to lead risk assessments with minimal supervision.
  • Proven experience in preparing technical and executive-level risk reports.

Responsibilities

  • Lead comprehensive information security risk analysis for IT assets, applications, and medical devices.
  • Evaluate vulnerabilities affecting electronic protected health information (ePHI) and ensure regulatory compliance.
  • Manage risk initiatives and maintain the organization's risk register.
  • Oversee corrective action plans and penetration testing results.
  • Collaborate with IT and stakeholders to track remediation efforts.
  • Monitor industry threats and regulatory changes to recommend mitigation strategies.
  • Support risk reporting, including executive dashboards and governance reviews.

Benefits

  • Flexible work-from-home opportunities with requirement to be onsite as needed in the greater Chicagoland area.
  • Engagement in a world-class academic healthcare environment at UChicago Medicine.
  • Opportunities for professional growth within a strong cybersecurity culture.
  • Collaborative work in a multidisciplinary team environment.
Full Job Description
Job Description

Join a world-class academic healthcare system, UChicago Medicine, as an Information Security Risk Analyst - Intermediate in our Information Security and Privacy GRC department. This position will be primarily a work-from-home opportunity with the requirement to come onsite as needed. You will need to be based in the greater Chicagoland area.

The Information Security Risk Analyst - Intermediate plays a critical role within the Governance, Risk and Compliance (GRC) team in executing and enhancing the organization's information security risk management program. The analyst will independently conduct risk analysis on information systems, platforms, and processes in accordance with established regulatory requirements, organizational policies, and industry standards. The analyst will lead and contribute to the identification, assessment, documentation, mitigation, and communication of information security risks across the organization.

This position supports risk-driven decision-making by collaborating with stakeholders, managing risk treatment plans, and ensuring compliance with HIPAA, NIST, and other applicable healthcare cybersecurity regulations and frameworks. The analyst is expected to operate with moderate independence, assist in maturing risk workflows, and contribute to strategic improvements in governance, risk, and compliance activities.

The ideal candidate will have a strong understanding of security frameworks, risk assessment methodologies, risk assessments, risk registers, and the management of audit and penetration testing findings. The ideal candidate should be adept at monitoring regulatory developments while promoting a culture of risk awareness across the organization.

Essential Job Functions
  • Lead and conduct comprehensive information security risk analysis for IT assets, applications, processes, medical devices and third-party vendors.
  • Evaluate threats and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information (ePHI) and any other confidential or sensitive information, ensuring alignment with HIPAA Security Rule requirements and other applicable regulatory frameworks (e.g., NIST,).
  • Lead and manage risk management initiatives based on analysis of outcomes, including maintaining the organization's risk register and scoring methodology.
  • Oversee corrective action plans (CAPs), penetration testing results, audit findings, and risk treatment outcomes.
  • Collaborate with IT partners and key stakeholders to prioritize, implement, and track remediation efforts.
  • Monitor regulatory changes and industry threats to proactively identify emerging risks, recommend mitigation strategies, and document findings.
  • Contribute to risk reporting, including executive dashboards, and participate in risk acceptance processes and governance reviews.
  • Contribute to the development, review, and improvement of cybersecurity policies, standards, and procedures.
  • Evaluate policy exceptions and assist in documenting decisions for governance committees.
  • Enhance the organization's cybersecurity awareness and training efforts by communicating risk insights to technical and non-technical audiences.
  • Other duties as assigned


Required Qualifications
  • Bachelor's degree required in Information Security, Computer Science, Engineering, Information Technology, or a related field; master's degree preferred
  • 3+ years of experience in cybersecurity, information security risk management, audit; healthcare industry experience strongly preferred
  • Demonstrated experience with risk assessment methodologies, auditing, information security practices, and familiarity with risk management platforms and risk registers
  • Strong understanding of regulatory compliance and industry best practices towards maintaining compliance with HIPAA, NIST and other relevant healthcare regulations and standards
  • One or more of the following certifications are required or must be obtained within 12 months of hire: CRISC, CISM, CISA or any other applicable certification
  • Ability to lead and structure risk assessments with limited supervision
  • Ability to manage multiple concurrent assessments and projects in a fast-paced healthcare setting
  • Experience preparing both detailed technical risk reports and executive-level summaries, tailored to varied audiences to support informed decision-making and governance oversight
  • Ability to build strong cross-functional relationships and collaboration across departments, including IT, Legal, Compliance, Clinical Operations, and Privacy, to support a collaborative approach to risk management and governance
  • Strong written and verbal communication and interpersonal skills, including ability to translate technical findings into business-relevant language for leadership audiences
  • Experience tracking audit findings, third party vendor risks, and remediation efforts
  • Familiarity with security platforms and tools
  • Ability to analyze contractual security language to identify risk exposure and recommend controls
  • Ability to learn quickly and work effectively in a team environment
  • Ability to understand and work with healthcare professionals, educators, and researchers
  • Ability to integrate cybersecurity risk management with business operations, healthcare delivery, and IT services


Position Details
  • Job Type/FTE: Full Time
  • Shift: Days
  • Location: Flexible (Hyde Park; Darien)
  • Unit/Department: Information Security Office
  • CBA Code: Non-Union


Compensation & Benefits Overview

UChicago Medicine is committed to transparency in compensation and benefits. The pay range provided reflects the anticipated wage or salary reasonably expected to be offered for the position.

The pay range is based on a full-time equivalent (1.0 FTE) and is reflective of current market data, reviewed on an annual basis. Compensation offered at the time of hire will vary based on candidate qualifications and experience and organizational considerations, such as internal equity. Pay ranges for employees subject to Collective Bargaining Agreements are negotiated by the medical center and their respective union.

Review the full complement of benefit options for eligible roles at Benefits - UChicago Medicine.

About The University of Chicago Medicine

The University of Chicago Medicine Careers

There has never been a better time to explore the diverse job opportunities at The University of Chicago Medicine. This esteemed institution is renowned for its commitment to innovation, leadership in medical science, and a culture that champions diversity and professional growth.

Work You’ll Do

Join The University of Chicago Medicine team to contribute to a pioneering organization that sets the standards in healthcare. The University of Chicago Medicine offers a unique environment where the convergence of research, education, and patient care fosters the next generation of industry leaders.

Transform Your Career

The University of Chicago Medicine is not just a healthcare institution; it's a vibrant community of scholars, clinicians, and healthcare professionals dedicated to improving human health through innovation in research and patient care. The team at The University of Chicago Medicine leads with a commitment to excellence and a passion for growth and development.

Innovative Work Environment

Engage in groundbreaking work with a team that is equipped with the skills to make significant advancements in medicine. The University of Chicago Medicine is home to more than just healthcare professionals; it is a hub of continuous innovation and problem-solving prowess.

Career Development Opportunities

Whether looking for an internship, a full-time position, or leadership roles, The University of Chicago Medicine provides an array of career paths to suit various professional aspirations. With robust training programs and diversity initiatives, employees are equipped to thrive both personally and professionally.

Benefits and Culture

The University of Chicago Medicine is committed to fostering a workplace culture that promotes the well-being and development of its staff. Employees enjoy a comprehensive benefits package that supports both their professional careers and personal lives.

Join a Team of Experts

By joining The University of Chicago Medicine, professionals become part of a team that is deeply committed to delivering quality healthcare. The collaborative environment ensures that everyone’s voice is heard and valued, contributing to a culture of respect and mutual support.

Networking and Professional Growth

The University of Chicago Medicine encourages its team to engage in various networking and professional development activities. These opportunities enhance skills and allow individuals to stay at the forefront of the healthcare industry.

Explore Job Opportunities

The University of Chicago Medicine is continuously hiring and looking for individuals who are passionate about making a difference in healthcare. Explore the various positions available and find where your skills and interests align with the needs of this dynamic organization.

Stay Connected

Join the Team

Search open positions that match your skills and interests. The University of Chicago Medicine seeks passionate, curious, and solution-driven team players.

SEARCH JOBS AT THE UNIVERSITY OF CHICAGO MEDICINE

Keep Up to Date

Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work at The University of Chicago Medicine.

READ CAREERS BLOG

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at The University of Chicago Medicine.
Learn more about The University of Chicago Medicine

Similar Jobs

More Jobs at The University of Chicago Medicine

More Healthcare Jobs

Find similar Information Security Risk Analyst - Intermediate jobs: