Jobs and Careers
CO
Governance Risk & Compliance Analyst Senior
Cottage HealthUnited States, United Statesfull_timeVerifiedPosted 5 Feb 2026
About the role
Responsible for developing, implementing and assisting in managing critical enterprise-wide Security Governance, Risk and Compliance programs to identify and mitigate security risks and protect valuable information and assets within the organization.
This is not an exhaustive statement of duties, responsibilities, or requirements. Employees will be required to perform any job, with related instruction given by their supervisor, subject to reasonable accommodation.
LEVEL OF EDUCATION
Minimum:
CERTIFICATIONS, LICENSES, REGISTRATIONS
Minimum:
TECHNICAL REQUIREMENTS
Minimum:
KNOWLEDGE, SKILLS, and ABILITIES
All knowledge, skills, and abilities listed indicate the minimum level deemed necessary to perform this job proficiently.
Cottage Health is an Equal Opportunity Employer. Cottage Health applicants are considered solely based on their qualifications, without regard to race, color, ethnicity, religion, age, gender, transgender, gender expression and identity, national origin, ancestry, disability, sexual orientation, marital status, military status or any other classification protected by law. This policy applies to all aspects of the relationship between Cottage Health and an appl
- Risk Management ProgramAssists in the execution of the enterprise-wide Security Risk Management Program to ensure critical security risks are identified, reported, and remediated in a timely manner. Meets with various IT teams and perform security assessments and audits to ensure that issues are included on the Security Risk Register.Ensures Security Risk Register items are remediated in a timely and appropriate manner. (5%)
- Compliance & Regulatory KnowledgeEnsures compliance with HIPAA Security requirements, Meaningful Use regulations, Payment Card Industry (PCI) requirements, and other compliance requirements for healthcare IT systems. (30%)
- Security Compliance ProgramSupports the development and maintenance of the Security Governance, Risk and Compliance Strategy to ensure HIPAA Security requirements, PCI requirements, Privacy Policy and other audit compliance requirements are met.Meets with external 3rd party suppliers to ensure that suppliers meet the 3rd Party Compliance Standards and include any issues on the Security Risk Register.Assists with the HIPAA/PCI Compliance Program to assess and report on the state of compliance and to ensure remediation is prioritized appropriately.Develops, implement and report on key security compliance metrics to ensure leadership is aware of regulatory security compliance posture. (15%)
- Assists with the development and maintenance of the Security Policy and Standards. (35%)
- Assists with the development and maintenance of the Security Policy and Standards. (20%)
- (5%)
LEVEL OF EDUCATION
Minimum:
- Bachelor's Degree in Computer Science or related field; or equivalent experience (8 years).
CERTIFICATIONS, LICENSES, REGISTRATIONS
Minimum:
- One of the following: Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP),Certified in Risk and Information Systems Control (CRISC), SANS Security Awareness Professional, CompTIA Security+, CompTIA CySA+ Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Security Essentials (GSEC), Certified Cloud Security Professional (CCSP), Systems Security Certified Practitioner (SSCP), Advanced in AI Audit (AAIA), Certified Data Privacy Solutions Engineer (CDPSE), Certified in the Governance of Enterprise IT (CGEIT), Certified Cybersecurity Operations Analyst (CCOA).
TECHNICAL REQUIREMENTS
Minimum:
- Working knowledge or HIPAA, Meaningful Use and Payment Card Industry (PCI).
KNOWLEDGE, SKILLS, and ABILITIES
All knowledge, skills, and abilities listed indicate the minimum level deemed necessary to perform this job proficiently.
- The ability to take technical topics and convey them into business level, risk based discussions with a variety of individuals ranging from management to technical teams.
- The employee communicates effectively.
- The ability to take on a project, task with instruction and work through milestones, with management guidance, to completion.
Cottage Health is an Equal Opportunity Employer. Cottage Health applicants are considered solely based on their qualifications, without regard to race, color, ethnicity, religion, age, gender, transgender, gender expression and identity, national origin, ancestry, disability, sexual orientation, marital status, military status or any other classification protected by law. This policy applies to all aspects of the relationship between Cottage Health and an appl
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s