Senior Analyst, GRC

Jefferson Health System

$90K — $110K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a science, technology, engineering, or math discipline or equivalent certifications
  • 5 years of related work experience

Responsibilities

  • Implement an integrated Governance, Risk, and Compliance (GRC) program and tools
  • Develop and enforce enterprise-wide information security policies and procedures
  • Perform risk assessments, including business impact and third-party risk assessments
  • Prioritize and deploy risk mitigation strategies across business units
  • Conduct information security awareness and resilience training campaigns
  • Collaborate with cross-functional teams on best practices and compliance
  • Mentor and coach GRC analysts for operational excellence
  • Develop executive dashboards and data pipelines for risk and compliance metrics

Benefits

  • Comprehensive medical, dental, and vision insurance
  • Life and AD&D insurance
  • Short- and long-term disability coverage
  • Flexible spending accounts
  • Retirement plans
  • Tuition assistance and discounts after service period
  • Access to group rates on insurance and discounts
Full Job Description
Number of Positions In Requisition
1
Job Details
Responsible for effective management of information security and resilience risks through domain expertise in areas such as regulatory compliance, risk management, security data engineering, or organizational resilience. This position develops and enforces information security policies, performs advanced risk assessments, and ensures alignment with regulatory requirements. Uses data driven decision making to protect assets by identifying vulnerabilities, measuring risks, improving resilience, and promoting compliance through security awareness.

Job Description

Summary
Responsible for effective management of information security and resilience risks through domain expertise in areas such as regulatory compliance, risk management, security data engineering, or organizational resilience. This position develops and enforces information security policies, performs advanced risk assessments, and ensures alignment with regulatory requirements. Uses data driven decision making to protect assets by identifying vulnerabilities, measuring risks, improving resilience, and promoting compliance through security awareness.

Job Duties
  • Contribute to the implementation of an integrated Governance, Risk, and Compliance (GRC) program and tools to support GRC workflows, which align with organizational objectives and regulatory requirements.
  • Develop and enforce enterprise-wide information security policies, standards, and procedures to support robust information security and operational resilience, including processes to manage exceptions to policies and standards.
  • Perform risk assessments, including business impact assessments, third party risk assessments, and assessments of cloud systems. Synthesize data to inform senior leadership on security posture, resilience gaps, and emerging threats.
  • Contribute to the prioritization and deployment of risk mitigation strategies using risk quantification methodologies, ensuring a coordinated response across business units and with external partners.
  • Advance the culture of compliance and resilience by conducting enterprise-level information security awareness and business resilience training campaigns and tabletop exercises.
  • Collaborate with cross-functional teams to integrate information security best practices and regulatory requirements into operational policies and procedures both within and beyond the immediate job area.
  • Mentor and coach GRC analysts, fostering operational excellence and professional growth within the GRC organization.
  • Develop executive dashboards and data pipelines to measure and communicate risk trends, compliance metrics, and strategic security objectives to senior stakeholders.

Minimum Qualifications
  • Bachelor's Degree in a science, technology, engineering, or math discipline or
  • High School Diploma/GED and preferred certifications.
  • 5 years related work experience

Physical Demands
Lift and carry 25 lbs. frequent sitting/standing, frequent keyboard use, *patient care providers may be required to perform activities specific to their role including kneeling, bending, squatting and performing CPR.

Job Description Disclaimer: This position description provides the major duties/responsibilities, requirements and working conditions for the position. It is intended to be an accurate reflection of the current position, however management reserves the right to revise or change as necessary to meet organizational needs. Other responsibilities may be assigned when circumstances require.

Work Shift
Workday Day (United States of America)

Worker Sub Type
Regular

Employee Entity
Thomas Jefferson University
Primary Location Address
1100 Virginia Drive, Fort Washington, Pennsylvania, United States of America

Benefits

Jefferson offers a comprehensive package of benefits for full-time and part-time colleagues, including medical (including prescription), supplemental insurance, dental, vision, life and AD&D insurance, short- and long-term disability, flexible spending accounts, retirement plans, tuition assistance, as well as voluntary benefits, which provide colleagues with access to group rates on insurance and discounts. Colleagues have access to tuition discounts at Thomas Jefferson University after one year of full time service or two years of part time service. All colleagues, including those who work less than part-time (including per diem colleagues, adjunct faculty, and Jeff Temps), have access to medical (including prescription) insurance.

For more benefits information, please click here

Similar Jobs

More Jobs at Jefferson Health System

More Information Technology Jobs

Find similar Senior Analyst, GRC jobs: