Healthcare Information Security departments must monitor risk every day. The Lead Governance Risk Compliance Analyst creates audit plans and methodologies, as well as conduct audits and risk assessments. This position requires the ability to analyze audit data, create reports, and track the resolution of negative audit findings.
WHAT YOU CAN EXPECT
Schedule and conduct internal and external audits and assessments.
Create audit reports; peer reviews audit reports written by GRC Analysts or other Senior GRC Analysts for accuracy, completeness and other criteria.
Create audit methodologies and templates used by the GRC Team to conduct audits and assessments.
Analyze audit data to identify risks and complex relationships between threats, controls and vulnerabilities.
Formulate prioritized action plans based on audit findings.
Track the resolution of negative audit findings and helps remediate findings where appropriate.
Understand how to translate compliance requirements into technology functions and how to translate compliance requirements into business impacts.
Create and review GRC policies, procedures, and standards.
Develop and deliver information security training, education and awareness content to Franciscan’s workforce.
Mentor GRC Analysts and Sr. Analysts.
Conduct vendor risk assessments, maintain vendor tiering, and review third party contracts for security requirements
ServiceNow Platform Ownership - Maintain workflows and control monitoring in ServiceNow IRM and provide metrics and reporting over remediation efforts
Maintain control mappings across NIST CSF 2.0, HITRUST, HIPPA, and other security frameworks