Information Security GRC Anyls
- Job Ref:
- 65295
- Talent Area:
- Information Technology
- Job Shift:
- 1st - Day
- Job Type:
- Full-Time
- Posted Date:
- Dec. 30, 2024
At Houston Methodist, the Information Security Governance, Risk, and Compliance (GRC) Analyst is responsible for managing risks related to information security, privacy, and regulatory compliance within an organization. This role involves developing and implementing policies, assessing risks, ensuring compliance with industry standards and regulations, and implementing control measures to mitigate risks. Key responsibilities include conducting risk assessments, developing risk mitigation strategies, monitoring compliance with frameworks such as ISO 27001, GDPR, NIST, and SOX, conducting vendor risk assessments, and collaborating with different departments to manage risks and ensure compliance. The GRC Analyst also creates and maintains information security standards, conducts gap analyses, and prepares for regulatory examinations.
Requirements:
- Gathers feedback for continuous improvements on established employee and technology policies from IT and business partners.
- Communicates risk findings and recommendations that are clear and actionable to all stakeholders.
SERVICE ESSENTIAL FUNCTIONS
- Creates, maintains, and communicates information security standards.
- Facilitates the remediation of control gaps and escalates critical issues to leadership.
- Prepares for and facilitates examinations by security assessors for regulations.
QUALITY/SAFETY ESSENTIAL FUNCTIONS
- Assesses and reports on the risks and benefits for the business, as well as the mandates for the supplier compliance.
- Evaluates the effectiveness of the information security program by developing and analyzing compliance metrics.
FINANCE ESSENTIAL FUNCTIONS
- Advises leadership on risk management strategies, including risk mitigation and risk transfer.
- Maintains and registers relevant suppliers/vendors, controls, and risks for ongoing vendor risk management activities.
GROWTH/INNOVATION ESSENTIAL FUNCTIONS
- Identifies, analyzes, evaluates, and documents information security risks and controls based on established risk criteria.
- Conducts third-party risk assessments and recommends control to mitigate identified risks.
- Coordinates architecture reviews as part of third-party risk assessments.
- Designs and documents technical, administrative, and physical controls to ensure compliance.
- Assists with the review of information security sections within supplier contract and recommends necessary changes.
- Takes a best practice approach to information security to balance secure operations with innovation.
This job description is not intended to be all-inclusive; the employee will also perform other reasonably related business/job duties as assigned. Houston Methodist reserves the right to revise job duties and responsibilities as the need arises.
Qualifications:
- Bachelor's degree in information security, information technology, computer science or other related technology degree
WORK EXPERIENCE
- Five years of Risk and/or Governance, Risk & Compliance experience. An additional three years of experience required in lieu of level 2 certification in assigned area of concentration
- CISSP - Certified Information Systems Security Professional (IISSCC) OR
- CRISC - Certified Risk and Information Systems Control (ISACA)
KNOWLEDGE, SKILLS, AND ABILITIES
- Demonstrates the skills and competencies necessary to safely perform the assigned job, determined through on-going skills, competency assessments, and performance evaluations
- Sufficient proficiency in speaking, reading, and writing the English language necessary to perform the essential functions of this job, especially with regard to activities impacting patient or employee safety or security
- Ability to effectively communicate with patients, physicians, family members and co-workers in a manner consistent with a customer service focus and application of positive language principles
- Understanding of relevant laws, regulations, and standards
- Knowledge of best practices for developing and implementing compliance programs
- Ability to analyze complex data and identify trends or discrepancies related to compliance and risk
- Proficient in both written and verbal communication to convey compliance issues and policies clearly
SUPPLEMENTAL REQUIREMENTS
WORK ATTIRE
- Uniform No
- Scrubs No
- Business professional Yes
- Other (department approved) No
ON-CALL*
*Note that employees may be required to be on-call during emergencies (ie. DIsaster, Severe Weather Events, etc) regardless of selection below.
- On Call* No
TRAVEL**
**Travel specifications may vary by department**
- May require travel within the Houston Metropolitan area Yes
- May require travel outside Houston Metropolitan area Yes
Company Profile:
Houston Methodist is one of the nation’s leading health systems and academic medical centers. Houston Methodist consists of eight hospitals: Houston Methodist Hospital, its flagship academic hospital in the heart of the Texas Medical Center, and seven community hospitals throughout the greater Houston area. Houston Methodist also includes an academic institute, a comprehensive residency program, a global business division, numerous physician practices and several free-standing emergency rooms and outpatient facilities. Overall, Houston Methodist employs more than 27,000 employees and is supported by a wide variety of business functions that operate at the system level to help enable clinical departments to provide high quality patient care.
Houston Methodist is an Equal Opportunity Employer.
Equal employment opportunity is a sound and just concept to which Houston Methodist is firmly bound. Houston Methodist will not engage in discrimination against or harassment of any person employed or seeking employment with Houston Methodist on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, status as a protected veteran or other characteristics protected by law. VEVRAA Federal Contractor – priority referral Protected Veterans requested.
-
Patient Access Center Representative - Central Scheduling (Imaging)
Location:
Corporate, Houston, TXAt Houston Methodist, the Patient Access Center Representative position is responsible for assuring that patients referred between employed and aligned physicians are scheduled to receive services in their assigned location and are financially cleared prior to their scheduled appointment through accurate and timely scheduling, registration, and verification of eligibility and …
-
Vascular Sonographer II - CV Surgery (Cypress)
Location:
Houston Methodist Specialty Physician Group, Houston, TXAt Houston Methodist, the Vascular Sonographer II position is an experienced sonographer who completes a variety of routine to advanced non-invasive vascular sonograms to include, where applicable, transcranial Doppler (TCD). A member of the direct patient care team, this position is fully competent in all aspects of ultrasound exams, vascular …
-
Environmental Services Technician - Days - Full-Time
Location:
Houston Methodist Cypress Hospital, Cypress, TXAt Houston Methodist, the Environmental Services (EVS) Technician position performs a variety of general as well as moderately complex cleaning tasks in assigned specialty areas to provide a safe and attractive environment for patients, guests, and staff. This position maintains environmental and infection control standards within established policies and procedures. …