At a Glance
- Tasks: Oversee security governance, manage risk assessments, and ensure compliance with regulations.
- Company: Join Care New England, a leader in healthcare security and compliance.
- Benefits: Competitive salary, health benefits, and opportunities for professional growth.
- Why this job: Make a real impact in healthcare security while developing your career.
- Qualifications: 5-7 years in IT/security, with relevant certifications and strong analytical skills.
- Other info: Collaborative environment with a focus on continuous learning and development.
The predicted salary is between 36000 - 60000 £ per year.
As a member of the Information Security team, the Senior Security Analyst (GRC) is responsible for governance oversight, enterprise risk management, and compliance activities supporting the Care New England Health System. This role ensures security programs are aligned with regulatory requirements, industry standards, and organizational risk tolerance.
Primary areas of responsibility include:
- Policy governance
- Enterprise risk register management
- Audit coordination
- Third-party risk oversight
- Security awareness program management
- Phishing simulation oversight
- Governance-level performance monitoring of security controls and tools
The Senior Security Analyst does not perform direct engineering functions but provides oversight, performance validation, risk analysis, and executive-level reporting to ensure effective security control implementation and regulatory readiness.
Requirements:
- Bachelor’s degree in Information Technology, Cybersecurity, Information Assurance, or related field required.
- Minimum of five (5) to seven (7) years of IT and/or information security experience, including governance, risk, and compliance responsibilities.
- CISSP, CISM, IAM, or equivalent industry certification required.
- Experience in a highly regulated environment required; healthcare experience strongly preferred.
- Strong knowledge of HIPAA §§164.308, 164.310, and 164.312, HITECH, RI state data protection laws, and PCI DSS.
- Demonstrated experience managing governance frameworks and regulatory compliance initiatives.
- Strong analytical and problem-solving abilities.
- Ability to interpret technical security findings and translate them into business risk terms.
- Experience maintaining and tracking enterprise risk registers.
- Strong written and verbal communication skills with the ability to present to executive leadership.
- Ability to manage multiple priorities and adjust based on risk impact and regulatory deadlines.
- Familiarity with EDR, SIEM, vulnerability management, email security, and related platforms from a governance perspective.
- Ability to coordinate audit evidence collection and corrective action tracking.
- Strong collaboration skills across technical and non-technical teams.
Duties and Responsibilities:
- Develop, maintain, and manage lifecycle governance of enterprise security policies, standards, and procedures.
- Ensure alignment of administrative, technical, and physical controls with HIPAA and other regulatory frameworks.
- Support annual enterprise risk assessments and maintain required compliance documentation.
- Maintain and track the enterprise security risk register; coordinate remediation efforts with IT and business stakeholders.
- Serve as primary liaison for internal and external audits, coordinating evidence collection and corrective action plans.
- Support third-party risk reviews and Business Associate Agreement (BAA) evaluations.
- Oversee the security awareness and phishing simulation program; monitor user risk metrics and provide executive reporting.
- Monitor governance performance of key security tools (EDR, email security, vulnerability management, SIEM); review findings and validate remediation tracking.
- Support incident documentation, post-incident analysis, and governance-based corrective action tracking.
- Provide security governance consultation for IT initiatives and third-party engagements.
- Participate in professional development and maintain current industry knowledge.
- Perform other related duties as assigned.
Senior Security Analyst - Governance, Risk & Compliance (GRC) in Warwick employer: Care New England
Contact Detail:
Care New England Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Senior Security Analyst - Governance, Risk & Compliance (GRC) in Warwick
✨Tip Number 1
Network like a pro! Reach out to your connections in the cybersecurity field, especially those who work in governance, risk, and compliance. A friendly chat can lead to insider info about job openings or even a referral.
✨Tip Number 2
Prepare for interviews by brushing up on your knowledge of HIPAA and other relevant regulations. Be ready to discuss how you've managed compliance initiatives in the past, as this will show you're the right fit for the role.
✨Tip Number 3
Showcase your analytical skills during interviews. Use real-life examples to demonstrate how you've interpreted technical security findings and translated them into business risks. This will highlight your problem-solving abilities.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, we love seeing candidates who are proactive about their job search.
We think you need these skills to ace Senior Security Analyst - Governance, Risk & Compliance (GRC) in Warwick
Some tips for your application 🫡
Tailor Your Application: Make sure to customise your CV and cover letter to highlight your experience in governance, risk, and compliance. We want to see how your skills align with the specific requirements of the Senior Security Analyst role.
Showcase Relevant Experience: When detailing your work history, focus on your experience in highly regulated environments, especially in healthcare. We love seeing candidates who can demonstrate their understanding of HIPAA and other relevant regulations.
Be Clear and Concise: Use straightforward language and avoid jargon when explaining your past roles and responsibilities. We appreciate clarity, especially when it comes to complex topics like risk management and security controls.
Apply Through Our Website: Don’t forget to submit your application through our website! It’s the best way for us to receive your details and ensure you’re considered for the position. Plus, it shows you’re keen on joining our team!
How to prepare for a job interview at Care New England
✨Know Your Regulations
Make sure you brush up on HIPAA, HITECH, and any relevant state data protection laws. Being able to discuss these regulations confidently will show that you understand the compliance landscape and can navigate it effectively.
✨Showcase Your Experience
Prepare specific examples from your past roles where you've managed governance frameworks or compliance initiatives. Highlighting your experience in a highly regulated environment, especially healthcare, will set you apart from other candidates.
✨Communicate Clearly
Practice explaining technical security findings in business terms. The ability to translate complex information into understandable language for executive leadership is crucial, so be ready to demonstrate this skill during the interview.
✨Demonstrate Collaboration Skills
Be prepared to discuss how you've worked with both technical and non-technical teams in the past. Sharing examples of successful collaboration will illustrate your ability to bridge gaps and ensure effective communication across departments.