Risk and Compliance Analyst
Core
Internal Risk and Compliance Analyst supporting enterprise security, risk, and compliance initiatives for applications, infrastructure, and vendor third parties.
Role type
Mid-level IC Risk and Compliance Analyst
Builds
Risk assessments, audit responses, compliance documentation, and control frameworks
Domain
Healthcare IT Security & Compliance
Deliverable
dashboards & analysis
Required skills
IT risk assessment, audit activity management, regulatory compliance frameworks (HIPAA, SOC 2, HITRUST, PCI DSS), policy development, stakeholder collaboration, root cause analysis, project management, technical documentation, data analysis
Preferred skills
Security/Audit certifications (CISA, CCSFP, CISSP, CRISC), COSO/COBIT framework knowledge, healthcare industry experience
Technologies
Excel, Word, PowerPoint, flowcharting tools
Responsibilities
Identify, assess, document, test, and support remediation of IT risks; Plan and execute risk-based IT assessments and audit activities for industry certifications; Lead responses to client RFPs, inquiries, and security questionnaires; Prepare and present risk and compliance reports to management; Develop and manage review of policies, procedures, and compliance artifacts; Collaborate with SMEs to gather technical information and create documentation.
Seniority
Mid-level, hands-on IC