Smith & Nephew

Senior Information Security Analyst (HIPAA / GRC ) (US, Field)

Smith & Nephew$111K — $167K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related field preferred
  • Minimum 5 years in Information Security with compliance experience
  • 2 years of direct experience with HIPAA compliance
  • 3 years in Program or Project Management
  • Experience with Privacy Law related Security Controls compliance is a plus
  • Familiarity with information security frameworks (HIPAA, ISO27001, etc.)

Responsibilities

  • Drive the annual HIPAA programme initiatives
  • Plan and coordinate the programme's schedule
  • Oversee the annual Security Risk Assessment process
  • Conduct security assessments on IT systems and track outcomes
  • Monitor changes in HIPAA law and update internal policies
  • Translate security controls into actionable tasks and improve operational processes

Benefits

  • Medical, dental, and vision coverage
  • 401(k) plan
  • Tuition reimbursement program
  • Generous paid time off (PTO)
  • Paid company holidays and parental leave
  • 8 hours of volunteer time annually
  • Employee Assistance Program (EAP) offerings
Full Job Description
Join us as an Information Security Compliance Analyst and play a key role in shaping and delivering our annual HIPAA programme. This is an opportunity to work closely with leaders across Governance Risk and Compliance, with support and guidance from senior experts while owning essential programme activities that help protect our patients, people and systems.

What will you be doing?
  • In this role, you will become the driving force behind the annual HIPAA programme.
  • You will plan the programme's schedule, coordinate with a wide range of partners, and keep everything running smoothly throughout the year.
  • You will oversee the annual Security Risk Assessment, shaping its scope and collaborating with third party specialists to ensure it is delivered effectively.
  • You will also carry out security assessments on IT systems, follow a structured process to record outcomes and track actions, and keep our documentation and workflows in OneTrust consistently updated.
  • Along the way, you will monitor changes in HIPAA law, support updates to internal policy, and bring insights and recommendations forward to leadership and the Steering Committee.
  • Success in this position comes from blending hands-on security experience with strong organisation and leadership skills.
  • You enjoy helping a programme run on schedule, working with multiple teams, and being trusted by stakeholders to keep things moving.
  • You can translate security controls into clear activities, understand how they are applied in practice, and turn complex challenges into structured actions. You bring a continuous improvement mindset and a readiness to contribute to the growth of the HIPAA programme year after year.


What will you need to be successful?

Education: Bachelor's degree in Computer Science or related subject preferred.

Certifications: Privacy or Security certifications would be advantageous but are not essential e.g. any HIPAA certification (CHPS, CHSE, CHPSE, CIPP/US), CISA, CISSP, ISO27001 or equivalent.

Experience:
  • At least 5 years in Information Security, some of which should be in a compliance function.
  • At least 2 years working on HIPAA compliance is required.
  • At least 3 years in Program or Project Management.
  • Prior experience of Privacy Law related Security Controls compliance would be very well received.
  • Experience deploying and assessing Information Security controls, ideally aligned to frameworks such as HIPAA, GDPR TOMS, ISO27001, HiTrust or NIST.
  • Familiarity with tools such as OneTrust or IT risk management platforms, or the ability to learn them quickly.


Travel Requirements:
The anticipated base compensation range for this position is $111,750 to $167,500 USD annually.

The actual base pay offered to the successful candidate will be based on multiple factors, including but not limited to job-related knowledge/skills, experience, and geographic location. Compensation decisions are dependent upon the facts and circumstances of each position and candidate.

In addition to base pay, we offer competitive bonus and benefits, including medical, dental, and vision coverage, 401(k), tuition reimbursement, medical leave programs, parental leave, generous PTO, paid company holidays, 8 hours of volunteer time annually, and a variety of wellness offerings such as EAP.

#LI-REMOTE

#LI-MA1

About Smith & Nephew

Smith & Nephew is a global medical technology company headquartered in London, England. The company designs, manufactures, and sells medical devices and products for orthopedic reconstruction, sports medicine, and trauma. Smith & Nephew operates in more than 100 countries and employs over 17,500 people worldwide. The company was founded in 1856 by Thomas James Smith and his nephew, Horatio Nelson Smith, and has grown through a series of mergers and acquisitions. Smith & Nephew's products include joint replacement systems, wound care products, and surgical instruments. The company is listed on the London Stock Exchange and is a constituent of the FTSE 100 Index.
Learn more about Smith & Nephew
Size
17,500 employees
Market Cap
$11.5 billion
Industry
Net Income
$448 million
5 Year Trend
+2.2%
Revenue
$4.5 billion

Similar Jobs

More Jobs at Smith & Nephew

More Healthcare Jobs

Find similar Senior Information Security Analyst (HIPAA / GRC ) (US, Field) jobs: