The Senior Analyst, Information Security Governance, Risk, & Compliance will be responsible for the corporate-wide Information Security GRC program. This person will work closely with Information Services, Office of Compliance and Risk Management (OCRM), Legal, HR, and Procurement to ensure reasonable and appropriate IT controls are in place to minimize risk and ensure compliance with AltaMed’s Information Security Policy and Standards, the HIPAA Security Rule, Data Privacy regulations and the Payment Card Industry – Data Security Standards (PCI-DSS). This person will assist with the development, implementation, and maintenance of AltaMed’s Information Security Policies, standards, and guidelines, and be an SME for HIPAA, PCI, and Privacy. Additionally, this person will also be responsible for leading vulnerability management efforts, and vendor and risk management programs, including leading the risk-based change management program, liaising with internal/external auditors to ensure audits lead to a successful outcome, and being responsible for the Security Exception/Risk Acceptance process. The position will also manage, maintain, and administer the company’s IT Risk Register and Information Security Awareness Training program.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level