IT Risk & Controls Analyst

Prime TherapeuticsEagan, MN
41d$74,000 - $118,000Remote

About The Position

The Risk & Controls Analyst is responsible for executing processes that ensure IT's compliance with regulatory, industry and client security requirements. This role is responsible for working with cross-functional teams on the day to day operational activities needed to support the Security Governance Risk and Compliance program.

Requirements

  • Bachelor's degree in an analytical discipline such as Computer Science, Finance, or Sciences or related area of study, or equivalent combination of education and/or related work experience; HS diploma or GED is required
  • 2 years of experience in Information Security, Information Technology, Risk Management, Audit or Finance
  • Must be eligible to work in the United States without need for work visa or residency sponsorship
  • Must be eligible to work in the United States without the need for work visa or residency sponsorship
  • Ability to conduct meetings and give presentations
  • Good analytical and critical thinking skills
  • Ability to multi-task and manage multiple priorities
  • Knowledge of Governance, Risk and Compliance area topics
  • Basic understanding of regulatory and/or compliance requirements and frameworks (PCI, HIPAA, SOC1, SOC2, HITRUST, NIST, etc.)
  • Basic working knowledge of security solutions and controls
  • Every employee must understand, comply with and attest to the security responsibilities and security controls unique to their job, and comply with all applicable legal, regulatory, and contractual requirements and internal policies and procedures
  • Every employee must be able to perform the essential functions of the job and, if requested, reasonable accommodations will be made to enable employees with disabilities to perform the essential functions, absent undue hardship.
  • In addition, Prime retains the right to change or assign other duties to this job.

Nice To Haves

  • Experience producing metrics reporting, writing and presenting communications
  • Experience in a regulated industry, health care preferred

Responsibilities

  • Update and publish organization wide security standards, policies and procedures
  • Test and collect evidence that controls are designed and operating effectively, including evidence needed to verify compliance to security requirements to HITRUST, SOC 2, HIPAA, and client contracts
  • Collect metrics to monitor risk and compliance status, assist in vendor and system security risk assessments, including drafting responses to client RFP and assessment requests
  • Work with IT to coordinate audit testing and track audit remediation
  • Other duties as assigned
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service