Jobs and Careers
SU

Senior Information Security Compliance Analyst

Surescripts
United States, United States, United StatesRemotefull_timeVerifiedPosted 25 Mar 2025
💰 $123,100/yr($100,700/yr$123,100/yr)

About the role

Surescripts serves the nation through simpler, trusted health intelligence sharing, in order to increase patient safety, lower costs and ensure quality care. We deliver insights at critical points of care for better decisions — from streamlining prior authorizations to delivering comprehensive medication histories to facilitating messages between providers.
 

Job Summary 

The Senior Information Security Compliance Analyst manages and leads the coordination of internal and external audit activities integral to audit success, including the collection of evidence artifacts. They will assist with maturing the enterprise risk program. The Senior Information Security Compliance Analyst has a thorough understanding of common security frameworks and practices. They will lead the update and maintenance of information security policies, standards, & procedure documents. The individual assists in the management of the Customer Security Response service by providing responses to customer requests on behalf of Surescripts security. The Senior Information Security Compliance Analyst assists with the management, execution, and development of information security awareness content to improve employee information security awareness and understanding of security policies to reduce company risk.  

 

Responsibilities 

  • Lead the coordination of internal and external assessments & certification activities integral to audit success.  

  • Participate in information security compliance assessments such as HIPAA & HITRUST. Catalog evidence in the GRC system for new requirements.  

  • Manage and maintain the evidence locker in the GRC tool. Ensure all artifacts are updated by evidence owners. 

  • Track and ensure all compliance Gaps and Corrective Action Plan (CAPs) are addressed in a timely manner. 

  • Review & update information security procedures, controls, and related evidence with stakeholders for completeness. 

  • Assist with maturing the enterprise risk program across Surescripts. 

  • Work with risk champions on developing and attaining POAMs.  

  • Maintain enterprise risk reporting.  

  • Provide enterprise risk training and guidance.  

  • Utilize enterprise risk playbook & add to it as appropriate. 

  • Independently manage customer requests for information on Surescripts Information Security. 

  • Provide outstanding customer service to internal stakeholders by answering questionnaires submitted by customers within 7 business days. 

  • Understand the complex set of Surescripts customer solutions and security controls to synthesize the knowledge into clear and simplified answers. 

  • Analyze new requests and collaborate with internal teams to provide succinct answers. 

  • Assist in the management and development of information security awareness materials and campaigns. 

  • Present security awareness content that targets improving employee 

understanding of information security and their role to help keep       Surescripts secure. 

    <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Surescripts

View company profile →