Cybersecurity GRC Analyst

Mercyhealth Wisconsin and IllinoisJanesville, WI
$85,657 - $137,051Onsite

About The Position

Mercyhealth is seeking a Cybersecurity GRC Analyst to join their team. This role is responsible for ensuring compliance with various security frameworks, assessing vendor risks, managing the internal risk register, and conducting cybersecurity risk assessments. The analyst will also coordinate with IT, Privacy, Legal, and Compliance departments, develop security policies, oversee Disaster Recovery/Business Continuity programs, and create cybersecurity metrics and training materials. A key aspect of the role is promoting security awareness across the organization.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Business Administration or related field
  • Audit experience using HIPAA, Health Information Trust Alliance (HITRUST), NIST or similar frameworks
  • Experience with Governance, Risk and Compliance/ Integrated Risk Management (GRC/IRM) platforms (e.g. Apptega, Archer, ServiceNow)
  • Experience with email security platforms (e.g. Knowbe4, Proofpoint Zen)
  • Familiarity with vulnerability scanners and SOC solutions (Security Information and Event Management/Security Orchestration, Automation, and Response (SIEM/SOAR)
  • Familiarity with cloud environments (e.g. Azure, Amazon Web Services (AWS)
  • Excellent Microsoft Word, Excel and PowerPoint skills
  • Strong communication skills, both written and verbal.
  • Ability to follow instructions and procedures accurately.
  • Demonstrated problem-solving and critical-thinking abilities.
  • Ability to work independently and as part of a team.
  • Commitment to maintaining confidentiality and ethical standards.
  • Adaptability to changing priorities and environments.
  • Customer service orientation and cultural sensitivity.

Nice To Haves

  • 3+ years experience in IT compliance, internal auditing or cybersecurity risk management
  • Experience in a healthcare or other highly regulated industry with direct exposure to HIPAA compliance requirements
  • Exposure to Identity and Access Management programs
  • Exposure to Vulnerability Management programs
  • Certified Information Systems Auditor (CISA)
  • Certified Information Systems Security Professional (CISSP)

Responsibilities

  • Conducts and facilitates internal and external audits against established compliance requirements and frameworks (e.g. HIPAA, Security Operations Center (SOC) 2, National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
  • Assesses third-party vendors for security risks prior to and during business relationships
  • Maintains internal risk register and tracks corrective action plans
  • Performs targeted cybersecurity risk assessments to identify vulnerabilities, misconfigurations, and compliance deviations
  • Conducts phishing attack simulations across the organization
  • Coordinates between Information Technology (IT), Privacy, Legal and Compliance to enforce governance objectives
  • Develops and maintains corporate security policies, procedures and standards aligned with business objectives
  • Provides oversight for Disaster Recovery/Business Continuity programs
  • Creates, updates and maintains cybersecurity metrics and awareness training materials
  • Promotes awareness and understanding of security policies across the organization

Benefits

  • Medical, Dental, Vision
  • Life & Disability Insurance
  • FSA/HSA Options
  • Generous, accruing paid time off
  • Paid Parental and caregiver leave
  • Career advancement and educational opportunities
  • Tuition and certification reimbursement
  • Certification Reimbursement
  • Well-being Programs
  • Employee Discounts
  • On-Demand Pay
  • Financial Education
  • Annual recognition/awards events
  • Partner appreciation days
  • Family entertainment/attractions discount
  • Community service/improvement opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service