Sr Security Policy Analyst

BJC HealthCareSt. Louis, MO
Remote

About The Position

BJC is hiring for a Sr. Security Policy Analyst. We are looking for applicants in the St. Louis or Kansas City area. This role will be responsible for maintaining security policies and updating applications in the GRC system. The ideal candidate will have excellent writing skills, knowledge of compliance, and attention to detail. Overview BJC HealthCare is one of the largest nonprofit health care organizations in the United States, delivering services to residents primarily in the greater St. Louis, southern Illinois and southeast Missouri regions. With net revenues of $6.3 billion and more than 30,000 employees, BJC serves patients and their families in urban, suburban and rural communities through its 14 hospitals and multiple community health locations. Services include inpatient and outpatient care, primary care, community health and wellness, workplace health, home health, community mental health, rehabilitation, long-term care and hospice. BJC is the largest provider of charity care, unreimbursed care and community benefits in the state of Missouri. BJC and its hospitals and health service organizations provide $785.9 million annually in community benefit. That includes $410.6 million in charity care and other financial assistance to patients to ensure medical care regardless of their ability to pay. In addition, BJC provides additional community benefits through commitments to research, emergency preparedness, regional health care safety net services, health literacy, community outreach and community health programs and regional economic development. BJC’s patients have access to the latest advances in medical science and technology through a formal affiliation between Barnes-Jewish Hospital and St. Louis Children’s Hospital with the renowned Washington University School of Medicine, which consistently ranks among the top medical schools in the country. IS Security Services serves as an independent, objective catalyst for implementing effective and efficient controls to protect BJC HealthCare (BJC) information resources through collaboration with customers. We provide value to our customers and the organization by: Ensuring compliance with internal policies and external regulations; evaluating information system and application controls; educating BJC employees and other strategic partners on information systems security practices and concepts; acting as a resource on security controls for new and existing information systems and applications; recovering mission critical applications and data vital to the organization and strategic partners; investigating practices not in compliance with established BJC Information Services security policies and standards.

Requirements

  • Bachelor's Degree
  • 2-5 years experience
  • Excellent writing skills
  • Knowledge of compliance
  • Attention to detail

Nice To Haves

  • 5-10 years experience
  • CIA
  • CISA
  • Cert Info Systems Manager
  • CPA
  • Certified in Risk & IS Control

Responsibilities

  • Present proposed policy changes to Senior IT management, executive team members, Electronic Information Security Committee (EISC) and Information Security Operations Committee (ISOC) both in verbal and written form.
  • Administer the policy management solution and support the Governance Risk and Compliance tool to include the following specific tasks:oUpdate and maintenance of existing policiesoProvisioning of policy administration accessoPeriodic validation policy administration accessoPolicy administration change management processes and monitoring
  • Identify gaps and redundancies in the current IT policy structure and responsible for the implementation of needed changes in policies.
  • Ensuring compliance of the mapping existing policies to the NIST Cybersecurity framework, NIST 800-53, and pertinent regulatory provisions (HIPAA, HITECH, PCI DSS) to ensure policies meet control best practice and regulatory requirements.
  • Implements and maintains a project plan for revising and consolidating the existing policy structure to incorporate the following objectives: oPolicies align with strategic clinical and business objectives.oPolicies appropriately address organizational risks.oPolicies address regulatory requirements. oPolicies clearly define scope, responsibilities, service levels, security requirements, and relevant technology standards.
  • Provides policy revision based on the monitored threats and regulatory environment. o Liaison to the BJC Compliance and Legal departments to incorporate required policy provisions into the existing policy structure.o Lead consultant to all IT Security teams to incorporate security and control requirements into the existing policy structure.

Benefits

  • Comprehensive medical, dental, vison, life insurance, and legal services available first day of the month after hire date
  • Disability insurance paid for by BJC
  • Annual 4% BJC Automatic Retirement Contribution
  • 401(k) plan with BJC match
  • Tuition Assistance available on first day
  • BJC Institute for Learning and Development
  • Health Care and Dependent Care Flexible Spending Accounts
  • Paid Time Off benefit combines vacation, sick days, holidays and personal time
  • Adoption assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service