Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Security Analyst, GRC image - Rise Careers
Job details

Security Analyst, GRC - job 1 of 2

Company Description

At Northwestern Medicine, every patient interaction makes a difference in cultivating a positive workplace. This patient-first approach is what sets us apart as a leader in the healthcare industry. As an integral part of our team, you'll have the opportunity to join our quest for better healthcare, no matter where you work within the Northwestern Medicine system. At Northwestern Medicine, we pride ourselves on providing competitive benefits: from tuition reimbursement and loan forgiveness to 401(k) matching and lifecycle benefits, we take care of our employees. Ready to join our quest for better?

Job Description

The Security Analyst reflects the mission, vision, and values of NM, adheres to the organizations Code of Ethics and Corporate Compliance Program, and complies with all relevant policies, procedures, guidelines and all other regulatory and accreditation standards.

Responsibilities:

  Perform third party risk management including cybersecurity risk assessments to ensure third party partners meet NM requirements.

· Collaborate with third party partners and internal departments to ensure NM security requirements are being adhered to.

· Examine third party contracts to ensure the accuracy of cybersecurity language and provisions.

· Perform annual third party partner cybersecurity assessments and create accompanying reports and audits.

· Participate in HIPAA, PCI and security assessments.

· Analyze archectual diagrams and recommend security measures to safeguard valuable information assets including third party solution diagrams.

· Perform risk assessments on cloud services, applications, servers, mobile devices, medical devices and IT resources.

· Perform annul security policy reviews to keep policies up to date with the changing technologoies and services.

· Follow up with IS teams to ensure risk assessments are updated in the GRC tracking tool.

· Perform daily operational tasks required for the department to protect NM’s assets. Tasks range from (but are not limited to):

o Respond to daily security tickets / requests

o On call rotation

· AA/EOE.

 

COMPETENCIES / PERFORMANCE EXPECTATIONS

Third party risk management proficiency

·Famaliarity of HIPAA Security and Privacy Rules

·Understanding of cybersecurity contract language

·Security operations experience

 PCI

QUA

Qualifications

Required:

  • Bachelors degree or equivalent work experience
  • Two or more years of professional IT experience, including Cyber Security
  • Working knowledge of the following subjects:
    • Network (protocols, topologies)
    • Security controls (proxies, IPS, IDS, Firewall and packet analyzers)
    • Systems (Windows, Linux/UNIX)
    • Software development (development / scripting langages)
    • Incident Response
    • Threat and Vulnerability Management
  • Experience and knowledge of at least two of the major security vendors relevant to the position.
  • Working knowledge of Security Standards/Controls specified under various IT governance and compliance models (NIST, HIPAA, PCI, ISO 27001&27002, ITIL).
  • Excellent problem solving skills
  • Demonstrated timely task completion involving solid organizational skills, task tracking, follow-up, and productive peer interaction.
  • Excellent verbal and written communication skills.

Preferred:

  • Certification or courses: Associate of (ISC)/CISSP, GSEC, GCWN, GCED or CEH a plus

Additional Information

Northwestern Medicine is an affirmative action/equal opportunity employer and does not discriminate in hiring or employment on the basis of age, sex, race, color, religion, national origin, gender identity, veteran status, disability, sexual orientation or any other protected status.

Average salary estimate

$80000 / YEARLY (est.)
min
max
$70000K
$90000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Security Analyst, GRC, Northwestern Memorial Healthcare

At Northwestern Medicine, we’re on a mission to cultivate a positive workplace through excellent patient interactions, and we're excited to announce an opportunity for a Security Analyst in the GRC team! This vital role not only reflects our values and commitment to ethical practices but also provides the chance to make a difference in healthcare security. As a Security Analyst, your focus will be on third-party risk management, performing detailed cybersecurity risk assessments to ensure our partners align with Northwestern Medicine's high standards. You’ll collaborate closely with various internal departments and external partners, ensuring that cybersecurity requirements are met and effectively communicated. Enjoy the challenge of reviewing contracts, analyzing architectural diagrams, and conducting thorough assessments of our diverse IT resources, from cloud services to medical devices. You’ll also stay on top of evolving technologies by performing annual policy reviews and operational tasks to protect our assets. If you have a knack for problem-solving, a solid grounding in cybersecurity, and a willingness to engage with our teams, this could be your next rewarding career step. Join us in our quest for better healthcare and make a lasting impact at Northwestern Medicine!

Frequently Asked Questions (FAQs) for Security Analyst, GRC Role at Northwestern Memorial Healthcare
What are the main responsibilities of a Security Analyst at Northwestern Medicine?

As a Security Analyst at Northwestern Medicine, your core responsibilities include performing third-party risk management through comprehensive cybersecurity risk assessments. You'll collaborate with internal departments and external partners to ensure compliance with security requirements. Additional tasks involve scrutinizing third-party contracts for cybersecurity provisions, conducting annual cybersecurity assessments, and analyzing architectural diagrams to recommend security measures.

Join Rise to see the full answer
What qualifications are needed to become a Security Analyst at Northwestern Medicine?

To qualify for the Security Analyst position at Northwestern Medicine, candidates should hold a bachelor's degree or possess equivalent work experience, along with a minimum of two years in professional IT or Cyber Security roles. Familiarity with multiple operating systems, incident response, risk management, and relevant security standards like NIST and HIPAA is essential. Certifications like CISSP, GSEC, or CEH are advantageous.

Join Rise to see the full answer
How does Northwestern Medicine ensure compliance with HIPAA for Security Analysts?

Northwestern Medicine emphasizes the importance of compliance with HIPAA regulations in the role of a Security Analyst. Responsibilities include participating in HIPAA assessments and consulting on security measures aligned with HIPAA's security and privacy rules to protect sensitive patient information and ensure data integrity.

Join Rise to see the full answer
What skills are important for a Security Analyst working in GRC at Northwestern Medicine?

Key skills for a Security Analyst in the GRC team at Northwestern Medicine include problem-solving abilities, strong communication skills, and a robust understanding of network protocols and security controls. Experience with incident response and familiarity with security standards such as PCI and ISO 27001 are critical for success in the role.

Join Rise to see the full answer
What are the daily tasks of a Security Analyst at Northwestern Medicine?

Daily tasks for a Security Analyst at Northwestern Medicine involve responding to security tickets and requests, performing daily operational tasks necessary to protect the organization's assets, and ensuring risk assessments are current. These tasks are supplemented by participation in follow-up activities to maintain the integrity of the GRC tracking tool.

Join Rise to see the full answer
Common Interview Questions for Security Analyst, GRC
What is your experience with third-party risk management?

When answering this question, discuss specific instances where you have assessed third-party vendors for compliance with security requirements. Highlight any frameworks you used, like NIST or HIPAA, and emphasize the importance of maintaining organizational standards.

Join Rise to see the full answer
Can you explain your understanding of HIPAA regulations?

Demonstrate your knowledge by outlining key HIPAA security and privacy rules, and how they apply to your role as a Security Analyst. Share any relevant experiences you've had in ensuring compliance within an organization.

Join Rise to see the full answer
What security assessment tools do you have experience with?

List the security assessment tools you have used, connecting each tool's capabilities back to your key contributions in previous roles. Mention how these tools helped identify vulnerabilities and improve compliance.

Join Rise to see the full answer
Describe your approach to conducting a cybersecurity risk assessment.

Outline your structured approach to risk assessments, including identifying assets, evaluating potential threats, assessing existing controls, and providing recommendations. Specific examples of previous assessments will add value to your response.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats?

Discuss your strategies for staying informed about the cybersecurity landscape, such as following industry publications, participating in relevant forums, or attending conferences. Highlight any certifications you maintain that require ongoing education.

Join Rise to see the full answer
What is your experience with security frameworks like NIST or ISO?

Speak about any direct experience using these frameworks for risk assessments or compliance audits. If possible, mention specific projects where applying these frameworks made a significant impact.

Join Rise to see the full answer
How do you communicate complex security concepts to non-technical stakeholders?

Address this question by sharing an example of how you have effectively communicated complex information to non-technical teammates or executives. Highlight your ability to simplify jargon while ensuring they understand the risks involved.

Join Rise to see the full answer
What methodologies do you follow for conducting security audits?

Explain the methodologies you’ve employed while conducting security audits, emphasizing any standards or best practices you adhered to. Discuss how these methodologies helped in aligning security practices with organizational goals.

Join Rise to see the full answer
How do you handle critical security incidents?

Share your incident response approach, detailing your problem-solving skills during critical security situations. Mention the importance of cross-departmental collaboration and how you prioritize incidents based on severity.

Join Rise to see the full answer
Why do you want to work as a Security Analyst at Northwestern Medicine?

Express your enthusiasm for being part of an organization dedicated to healthcare and patient safety. Position your skills and experiences in alignment with Northwestern Medicine's mission, reinforcing your commitment to contributing to its cyber resilience.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 9 days ago
Posted 9 days ago
Photo of the Rise User
Vector Limited Remote 110 Carlton Gore Road, Newmarket, Auckland 1023, New Zealand
Posted 10 days ago
Photo of the Rise User
DRC Systems Remote No location specified
Posted 3 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Customer-Centric
Collaboration over Competition
Growth & Learning
Take Risks
Medical Insurance
Dental Insurance
Vision Insurance
Flex-Friendly
Equity
Learning & Development
Photo of the Rise User
Inclusive & Diverse
Collaboration over Competition
Fast-Paced
Growth & Learning
Empathetic

Northwestern Medicine is the collaboration between Northwestern Memorial HealthCare and Northwestern University Feinberg School of Medicine. The entities involved in Northwestern Medicine remain separate organizations. Northwestern Medicine is a t...

547 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 25, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!