BJC Healthcare

Sr Security Policy Analyst

BJC Healthcare$88K — $105K *
Healthcare
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree required;
  • 2-5 years experience in IT policy analysis;
  • Knowledge of compliance standards including NIST and HIPAA;
  • Strong writing skills with attention to detail;
  • Certifications such as CIA, CISA, or CPA are preferred.

Responsibilities

  • Present policy changes to senior management and committees both verbally and in writing;
  • Administer and support updates to the Governance Risk and Compliance tool;
  • Identify gaps in the current IT policy structure and implement necessary changes;
  • Ensure policies comply with NIST Cybersecurity framework and other regulatory requirements;
  • Develop a project plan to revise and consolidate existing policies to align with organizational objectives.

Benefits

  • Comprehensive medical, dental, vision, and life insurance from the first day of the month after hire;
  • Disability insurance fully paid by BJC;
  • Annual 4% automatic retirement contribution;
  • 401(k) plan with company match;
  • Tuition Assistance available from the first day of employment;
  • Access to BJC Institute for Learning and Development;
  • Flexible Spending Accounts for healthcare and dependents;
  • Paid Time Off that includes vacation, sick days, holidays, and personal time;
  • Adoption assistance.
Full Job Description
Additional Information About the Role

BJC is hiring for a Sr. Security Policy Analyst. We are looking for applicants in the St. Louis or Kansas City area. This role will be responsible for maintaining security policies and updating applications in the GRC system. The ideal candidate will have excellent writing skills, knowledge of compliance, and attention to detail.

Overview

IS Security Services serves as an independent, objective catalyst for implementing effective and efficient controls to protect BJC HealthCare (BJC) information resources through collaboration with customers. We provide value to our customers and the organization by: Ensuring compliance with internal policies and external regulations; evaluating information system and application controls; educating BJC employees and other strategic partners on information systems security practices and concepts; acting as a resource on security controls for new and existing information systems and applications; recovering mission critical applications and data vital to the organization and strategic partners; investigating practices not in compliance with established BJC Information Services security policies and standards.

Preferred Qualifications

Role Purpose

Senior technology role responsible for understanding the requirements of the organization and the desired audience evaluating different publishing methods and options, and their costs, features and benefits - including open source and proprietary options developing and overseeing the implementation and maintenance of revisions (as needed) of a framework for content publishing, including preferred media, overall information structure, and rules for formatting content converting content into a format suitable for publication delivering content to the user at the point of need managing copyright, data protection and other legal issues associated with publishing and reusing published information and data ensuring published material is in a form accessible to all potential users, including those with disabilities releasing or retiring content.

Responsibilities
  • Present proposed policy changes to Senior IT management, executive team members, Electronic Information Security Committee (EISC) and Information Security Operations Committee (ISOC) both in verbal and written form.Administer the policy management solution and support the Governance Risk and Compliance tool to include the following specific tasks:oUpdate and maintenance of existing policiesoProvisioning of policy administration accessoPeriodic validation policy administration accessoPolicy administration change management processes and monitoring
  • Identify gaps and redundancies in the current IT policy structure and responsible for the implementation of needed changes in policies.
  • Ensuring compliance of the mapping existing policies to the NIST Cybersecurity framework, NIST 800-53, and pertinent regulatory provisions (HIPAA, HITECH, PCI DSS) to ensure policies meet control best practice and regulatory requirements.
  • Implements and maintains a project plan for revising and consolidating the existing policy structure to incorporate the following objectives: oPolicies align with strategic clinical and business objectives.oPolicies appropriately address organizational risks.oPolicies address regulatory requirements. oPolicies clearly define scope, responsibilities, service levels, security requirements, and relevant technology standards.
  • Provides policy revision based on the monitored threats and regulatory environment. o Liaison to the BJC Compliance and Legal departments to incorporate required policy provisions into the existing policy structure.o Lead consultant to all IT Security teams to incorporate security and control requirements into the existing policy structure.

  • Minimum Requirements

    Education
  • Bachelor's Degree

  • Experience
  • 2-5 years

  • Supervisor Experience
  • No Experience

  • Preferred Requirements

    Experience
  • 5-10 years

  • Licenses & Certifications
  • CIA
  • CISA
  • Cert Info Systems Manager
  • CPA
  • Certified in Risk & IS Control

  • Benefits and Legal Statement

    BJC Total Rewards

    At BJC we're committed to providing you and your family with benefits and resources to help you manage your physical, emotional, social and financial well-being.
    • Comprehensive medical, dental, vison, life insurance, and legal services available first day of the month after hire date
    • Disability insurance* paid for by BJC
    • Annual 4% BJC Automatic Retirement Contribution
    • 401(k) plan with BJC match
    • Tuition Assistance available on first day
    • BJC Institute for Learning and Development
    • Health Care and Dependent Care Flexible Spending Accounts
    • Paid Time Off benefit combines vacation, sick days, holidays and personal time
    • Adoption assistance

    To learn more, go to our Benefits Summary

    *Not all benefits apply to all jobs

    The above information on this description has been designed to indicate the general nature and level of work performed by employees in this position. It is not designed to contain or be interpreted as an exhaustive list of all responsibilities, duties and qualifications required of employees assigned to this job.

    About BJC Healthcare

    BJC Healthcare is a healthcare services provider that operates hospitals and other healthcare facilities in the St. Louis, Missouri area. The company was founded in 1993 and is headquartered in St. Louis. BJC Healthcare is one of the largest employers in the region, with over 31,000 employees. The company's hospitals and clinics provide a wide range of medical services, including cancer treatment, heart care, and women's health. BJC Healthcare is committed to providing high-quality care to its patients and has received numerous awards and recognitions for its work.
    Learn more about BJC Healthcare
    Size
    31,000 employees
    Industry
    Founded
    1993

    Similar Jobs

    More Jobs at BJC Healthcare

    More Healthcare Jobs

    Find similar Sr Security Policy Analyst jobs: