Care New England Health System

Senior Security Analyst (GRC)

Care New England Health System$95K — $115K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Information Assurance, or related field required.
  • 5-7 years of experience in IT and/or information security with a focus on governance, risk, and compliance, preferably in a highly regulated environment like healthcare.
  • Certifications such as CISSP, CISM, IAM, or equivalent industry certification required.
  • Strong understanding of HIPAA, HITECH, RI state data protection laws, and PCI DSS compliance standards.
  • Proven ability to translate technical security issues into business risk terms.

Responsibilities

  • Develop and manage enterprise security policies, standards, and procedures Lifecycles.
  • Ensure compliance with HIPAA and other regulatory frameworks through effective controls.
  • Conduct annual enterprise risk assessments and maintain compliance documentation.
  • Manage the enterprise security risk register; facilitate remediation efforts with stakeholders.
  • Act as the main contact for internal and external audits and coordinate evidence collection.
  • Oversee third-party risk evaluations and Business Associate Agreement reviews.
  • Direct the security awareness program and phishing simulations while monitoring user risk metrics.

Benefits

  • Professional development opportunities to maintain industry knowledge.
  • Collaborative work environment engaging with both technical and non-technical teams.
  • Opportunities for executive-level reporting and influence on organizational policies.
  • Experience in a health care setting which is increasingly significant in compliance-related roles.
Full Job Description
Job Summary

As a member of the Information Security team, the Senior Security Analyst (GRC) is responsible for governance oversight, enterprise risk management, and compliance activities supporting the Care New England Health System.

This role ensures security programs are aligned with regulatory requirements, industry standards, and organizational risk tolerance. Primary areas of responsibility include policy governance, enterprise risk register management, audit coordination, third-party risk oversight, security awareness program management, phishing simulation oversight, and governance-level performance monitoring of security controls and tools.

The Senior Security Analyst does not perform direct engineering functions but provides oversight, performance validation, risk analysis, and executive-level reporting to ensure effective security control implementation and regulatory readiness.

Duties & Responsibilities

  • Develop, maintain, and manage lifecycle governance of enterprise security policies, standards, and procedures.
  • Ensure alignment of administrative, technical, and physical controls with HIPAA and other regulatory frameworks.
  • Support annual enterprise risk assessments and maintain required compliance documentation.
  • Maintain and track the enterprise security risk register; coordinate remediation efforts with IT and business stakeholders.
  • Serve as primary liaison for internal and external audits, coordinating evidence collection and corrective action plans.
  • Support third-party risk reviews and Business Associate Agreement (BAA) evaluations.
  • Oversee the security awareness and phishing simulation program; monitor user risk metrics and provide executive reporting.
  • Monitor governance performance of key security tools (EDR, email security, vulnerability management, SIEM); review findings and validate remediation tracking.
  • Support incident documentation, post-incident analysis, and governance-based corrective action tracking.
  • Provide security governance consultation for IT initiatives and third-party engagements.
  • Participate in professional development and maintain current industry knowledge.
  • Perform other related duties as assigned.


Requirements

Education:

Bachelor's degree in Information Technology, Cybersecurity, Information Assurance, or related field required.

Experience:

Minimum of five (5) to seven (7) years of IT and/or information security experience, including governance, risk, and compliance responsibilities. Experience in a highly regulated environment required; healthcare experience strongly preferred.

Licenses:N/A

Certifications:CISSP, CISM, IAM, or equivalent industry certification required.

Knowledge, Skills, & Abilities:

Strong knowledge of HIPAA §§164.308, 164.310, and 164.312, HITECH, RI state data protection laws, and PCI DSS.

Demonstrated experience managing governance frameworks and regulatory compliance initiatives.

Strong analytical and problem-solving abilities.

Ability to interpret technical security findings and translate them into business risk terms.

Experience maintaining and tracking enterprise risk registers.

Strong written and verbal communication skills with the ability to present to executive leadership.

Ability to manage multiple priorities and adjust based on risk impact and regulatory deadlines.

Familiarity with EDR, SIEM, vulnerability management, email security, and related platforms from a governance perspective.

Ability to coordinate audit evidence collection and corrective action tracking.

Strong collaboration skills across technical and non-technical teams.

About Care New England Health System

Care New England Health System is a non-profit health care system based in Providence, Rhode Island. It was founded in 1996 and is comprised of three hospitals: Kent Hospital, Women & Infants Hospital, and Butler Hospital. The system also includes a number of outpatient facilities and physician practices. Care New England Health System provides a wide range of medical services, including primary care, specialty care, and surgical services.
Learn more about Care New England Health System
Size
8,000 employees
Industry

Similar Jobs

More Jobs at Care New England Health System

More Healthcare Jobs

Find similar Senior Security Analyst (GRC) jobs: