Jobs and Careers
TR
Senior Security Risk Analyst (REMOTE)
Trinity HealthUnited StatesRemotefull_timeVerifiedPosted 10 Jan 2025
About the role
Employment Type:
Full timeShift:
Day ShiftDescription:
POSITION SUMMARY
Provides information security risk knowledge and serves as a specialist to identify, prioritize, and collaboratively mitigate cyber risk enterprise-wide. Candidate maintains the ability to be an analytical thinker, collaborative team player, an effective, dynamic communicator, and able to bridge the gap between business demands and cybersecurity requirements.
- Assists and supports the Manager of Information Security Risk Management in ensuring all projects and services meet Trinity Health Information security and regulatory standards, policies and procedures while delivering business requirements. Performs risk analysis on new projects, security exceptions, and audit issues.
- Provides governance responsibilities over the security operations of outsourcer vendor(s), infrastructure Third Party Partners (TPP) and Cloud service providers.
- Acts as an advocate and resource on information security for various Regional Health Ministry areas and/or system-wide initiatives (EMR, patient satisfaction surveys, etc). Assists business owners of various information resources in fully addressing security issues.
Responsible for the following:
- Plan, coordinate and oversee security risk assessments for information systems and third parties
- Design and compose reports, assessments, and other documents to provide decision support on information security risks and controls for executives, system owners and management
- Aid the team in assessing the likelihood and impact of adverse events and recommend effective controls and mitigations to management
- Research, analyze and report on the cybersecurity risk of doing business with third parties
- Manage and facilitate the response and mitigation of third party security incidents
- Support the continuous improvement and implementation of Information Security Policies, Standards, Processes, and Procedures
- Contribute to the enhancement and implementation of the information security risks & controls library
- Design, implement and manage control assessments to determine if cybersecurity controls are effective and in compliance with applicable requirements
- Establish and implement effective security awareness practices across the System, including training, phishing, and communications.
- Keep pace with emerging technology, cyber threats, and industry trends around cybersecurity.
- Assists and supports the Enterprise Information Security (EIS) Managers, Directors and Health Ministry (HM) Information Security Managers in ensuring all projects and services meet Trinity Health Information Security and regulatory standards while delivering business requirements.
ESSENTIAL FUNCTIONS
- Knows, understands, incorporates and demonstrates the Trinity Health Mission, Vision and Values in behaviors, practices and decisions.
- Develops designs and operates one or more information security domains.
- Provides technical consultation and assistance in identifying, evaluating and documenting use of systems and other related services to ensure compliance with EIS policies.
- Resolves complex security issues, and mitigates threats and vulnerabilities across an Information Security service.
- Reviews various system and technical documents and applies security templates.
- Defines security configuration and operational standards for security systems and applications.
- Interacts with multiple vendors to ensure a cohesive client-vendor relationship that maintains and upholds services in the best interest of Trinity Health.
- Provides guidance and direction on enterprise security procedures, security technology, and security design work; works with business stakeholders to define Information Security processes.
- Works collaboratively with other security professionals and Security Managers to standardize information security industry best practices.
- Contributes to the creation of department procedures, standards and documentation for all information security services.
- Utilizes excellent verbal and written communication skills.
- Participates in the creation of annual objectives and tactical plans.
- Responsible for the prioritization of Infrastructure investments and maintenance involving IT security.
- Participates in the development and promotion of Information Security information for general awareness.
- Participates in site-specific meetings.
- Participates in the creation of the development and implementation of annual objectives and tactical plans to achieve strategic planning initiatives.
- Monitors or enforces security policies, procedures and standards to ensure conform
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s