Senior Cybersecurity Analyst (GRC)
Boston Medical CenterAbout the role
POSITION SUMMARY:
The Senior Cybersecurity Analyst (Governance, Risk, and Compliance) plays an important role in building and maturing Boston Medical Center Health System’s GRC program. This role will be key to developing and improving human-driven processes before enterprise tooling is in place, and will make that work visible, auditable, and ready to scale.
Position: Senior Cybersecurity Analyst
Department: Information Security
Schedule: Full Time
ESSENTIAL RESPONSIBILITIES / DUTIES:
Lead execution of GRC program initiatives, contributing design input on processes, workflows, and work products as the program matures toward enterprise tooling adoption.
Maintain and operationalize risk registers, control frameworks, and maturity assessments aligned to NIST CSF 2.0, HIPAA/HITECH, and applicable federal and state security and privacy regulations.
Drive compliance monitoring activities and recommend updates to security policies, standards, and procedures that balance regulatory rigor with operational practicality.
Coordinate the third-party risk management process, including vendor risk assessments and ongoing vendor risk workflows.
Apply risk scoring methodologies to support framework maturity tracking and quantified risk metrics, incorporating business continuity and disaster recovery considerations.
Manage structured GRC work products in spreadsheet and document-based environments (e.g., Excel, SharePoint), keeping them accurate, accessible, and audit-ready on an ongoing basis.
Translate technical findings into clear, actionable written and verbal reporting for executive and non-technical audiences.
Partner with stakeholders across IT and non-IT business functions to advance new standards and workflows, influencing adoption without direct authority.
Prioritize multiple concurrent workstreams to deliver accurate results on schedule in a fast-paced, evolving environment.
(The above statements in this job description are intended to depict the general nature and level of work assigned to the employee(s) in this job. The above is not intended to represent an exhaustive list of accountable duties and responsibilities required)
JOB REQUIREMENTS
REQUIRED EDUCATION AND EXPERIENCE:
Bachelor's degree in Cybersecurity, Computer Science, Information Management, or a related field preferred
A minimum of six years of experience in information security or related discipline, with a strong focus on governance, risk, and compliance programs in complex or regulated environments.
Or equivalent combination of education and experience.
PREFERRED EDUCATION AND EXPERIENCE:
Demonstrated experience building or significantly maturing a GRC function, including the design of processes and workflows prior to enterprise tooling adoption.
CERTIFICATIONS, LICENSES, REGISTRATIONS PREFERRED:
Professional certifications such as CISA, CRISC, CISSP, or equivalent are highly desirable.
KNOWLEDGE, SKILLS & ABILITIES (KSAs):
Demonstrated experience in data mining, analysis and report development required.
Strong knowledge of information systems security concepts and current information security/privacy trends and practices.
Knowledge of Federal and State security and privacy-related regulatory requirements.
Excellent written and oral communication skills, interpersonal skills, and effective leadership skills to support privacy programs.
Must be able to prepare formal reports and presentations as needed.
Must be detailed oriented and possess the ability to prioritize tasks so work is completed in an accurate, timely manner.
Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management.
Self-starter with the ability to work independently, prioritize, multi-task, and maintain flexibility in fast-paced, changing environment.
Ability to confront conflict and difficult issues in a professional, assertive, and proactive manner.
Ability to build strong working relationships at all levels, internal and/or external to the organization.
Knowledge about medical records and other medical information, patient privacy and confidentiality, and release of information. Academic medical center and/or health care consulting experience preferre
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s