Senior Cybersecurity Policy & Compliance Analyst (Remote Available)
Vanderbilt University Medical CenterAbout the role
Discover Vanderbilt University Medical Center: Located in Nashville, Tennessee, and operating at a global crossroads of teaching, discovery, and patient care, VUMC is a community of diverse individuals who come to work each day with the simple aim of changing the world. It is a place where your expertise will be valued, your knowledge expanded, and your abilities challenged. Vanderbilt Health recognizes that diversity is essential for excellence and innovation. We are committed to an inclusive environment where everyone has the chance to thrive and where your diversity of culture, thinking, learning, and leading is sought and celebrated. It is a place where employees know they are part of something that is bigger than themselves, take exceptional pride in their work and never settle for what was good enough yesterday. Vanderbilt’s mission is to advance health and wellness through preeminent programs in patient care, education, and research.
Organization:
VEC Policy & ComplianceJob Summary:
The Senior Cybersecurity Analyst assists in the creation, coordination and execution of policy & privacy/security compliance programs across VUMC. The Senior Cybersecurity Analyst assists leadership in supporting these compliance programs that are expected to experience significant change, expansion or evolution over time.(Note: This role is available for remote work from most parts of the US and with this role we are targeting a salary range of $110k - $140k.)
.
KEY RESPONSIBILITIES:
Assist in conducting cybersecurity compliance reviews and tracking compliance gaps to remediation.
Assist in development/review of cybersecurity policies and procedures.
Consult with workforce members on regulatory and policy requirements.
Act as cybersecurity compliance representative on cross-functional work teams.
Assist with project/organizational risk assessments.
Develop, implement and monitor security compliance work plans for the organization.
Develop/improve processes for evaluating/documenting security compliance.
Assist in responding to third party audits (payers, research partners, vendors, etc.).
Assist in responding to internal audits (assist in managing and completing Management Action Plans (MAPs)).
Assist in developing cybersecurity training initiatives.
Prepare regular reports for executive review.
Maintain an in-depth knowledge of privacy/security-related regulatory frameworks such as HIPAA, GDPR and provide timely information regarding important regulatory changes to operational leaders.
PREFERRED QUALIFICATIONS:
Bachelor’s degree in related field or equivalent experience.
Experience writing/editing policies and procedures.
Experience managing compliance documentation, including but not limited to committee charters, confidentiality agreements and annual attestations.
Excellent organizational, analytical, and time management skills.
Effective interpersonal, writing, and communications skills required.
Experience with US and international privacy / security-related regulatory frameworks (HIPAA/HITECH, GDPR, etc…).
Ability to work independently with minimal supervision.
Experienced with business process development / improvement.
Ability to manage multiple competing priorities within the context of a complex, multi-faceted organization.
At least 3 years experience in cybersecurity.
Information Security Related Professional Qualification (e.g., CISSP, CISA, Security+, CEH, GSEC, etc.)
TECHNICAL CAPABILITIES:
PROGRAM MANAGEMENT (INTERMEDIATE): Planning, organizing, and managing resources to bring about the successful completion of specific program goals and objectives.
RISK AND COMPLIANCE ASSESSMENTS (INTERMEDIATE): Ensuring compliance with established foreign and domestic laws and regulations and VUMC institutional policies and procedures and recommending any necessary changes. This activity will include the independent review and examination of IT systems, architectures, data flows, etc., and the documentation and reporting of such assessments in support of VUMC programs.
PEER LEADERSHIP (INTERMEDIATE): The ability to show leadership and influence people of equal rank in an effort to accomplish team goals.
QUALITY MANAGEMENT (INTERMED
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s