Jobs and Careers
NR

Corporate Security and Privacy Analyst

NRC Health
United Statesfull_timeVerifiedPosted 12 Sept 2024
💰 $121,500/yr($90,000/yr$121,500/yr)

About the role

At NRC Health, we promise to help our customers bring Human Understanding to healthcare for their patients and communities. Our associates are at the heart of delivering that promise, so we promise that same Human Understanding to each other. Come where culture is everything.

 

Our associates. . .

 

Have Purpose we do work that matters for our partners, the community, and the healthcare industry.

  Innovate with us to move healthcare forward.

  Give back to the community with paid volunteer time off.

 

Think Boldly – we have big ideas and are empowered to “think like an owner.”

  Fit your role and do what you love.

  Grow and develop along a career path designed by you.

 

Feel Connected – our favorite thing about our workday is each other.

  Support one another – no one says, “That’s not my job.”

  Celebrate with each other at beer:30, virtual events, and company gatherings.

 

Be Understood – we are each unique and want to live our best lives at work and home.

Let life happen with My Time Off, a form of unlimited vacation, and up to 12 weeks paid for parental and emergency leave.

Live healthy with complimentary lifestyle and financial coaches, a wellness program, and a comprehensive insurance plan.

 

Who we want

  • Do you have a strong focus on accuracy and thoroughness?
  • Are you able to manage multiple projects and deadlines simultaneously?
  • Do you have strong interpersonal skills with the ability to work collaboratively across teams?
  • Do you act proactively with a strong sense of ownership and accountability?

 

What you will do

The Corporate Security and Privacy Analyst will be responsible for coordinating and managing IT audits related to HITRUST, SOC2 and SOX, organizing KnowBe4 training sessions and phishing campaigns, facilitating HITRUST certification processes, and conducting ongoing policy audits and assessments. This role ensures that the organization complies with industry standards and regulatory requirements, enhancing overall security posture and minimizing risks.

Key Responsibilities:

  1. SOC2/SOX IT Audits:
    • Coordinate and manage SOC2 and SOX IT audits, including planning, execution, and follow-up.
    • Collaborate with internal teams and external auditors to gather necessary documentation and evidence.
    • Identify and address audit findings, implementing corrective actions as needed.
    • Maintain up-to-date knowledge of SOC2 and SOX requirements and ensure compliance.
  2. KnowBe4 Training and Phishing Campaigns:
    • Plan, organize, and execute KnowBe4 training sessions for employees.
    • Develop and manage phishing campaigns to assess and improve employee awareness and response to security threats.
    • Analyze campaign results and provide recommendations for improvement.
    • Ensure training materials are current and align with industry best practices.
  3. HITRUST Certification:
    • Coordinate  HITRUST certification process, including initial assessments, gap analysis, and remediation efforts.
    • Work closely with cross-functional teams to ensure compliance with HITRUST CSF requirements.
    • Maintain documentation and evidence required for HITRUST certification.
    • Monitor changes in HITRUST requirements and adjust internal processes accordingly.
  4. Policy Audits and Assessments:
    • Conduct regular policy audits and assessments to ensure compliance with internal policies and regulatory standards.
    • Identify areas for improvement and recommend policy updates or new policies as needed.
    • Collaborate with stakeholders to implement and communicate policy changes.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

NRC Health

View company profile →