The Cyber Security Analyst will support the risk management program by assessing security controls, identifying gaps, and managing mitigation strategies. They will also collaborate with cross-functional teams to ensure regulatory compliance and develop security metrics.
Job Title: Cyber Security Analyst (GRC)
Location: 100% Remote (EST/CST/MST)
Company Overview:
Glint Tech Solutions is a women-owned, global IT staffing and recruiting firm serving enterprise clients across the USA and Canada. We are currently hiring on behalf of a leading healthcare insurance client.
Project Description:
Our client is seeking a Cyber Security Risk Analyst to ensure organizational data remains protected from inappropriate access, disclosure, and damage by assessing, documenting, and socializing risk. This role reports to the Manager, Cybersecurity Risk and Compliance.
Key Responsibilities:
- Support the Cybersecurity Risk Management program, guiding a diverse technical team and collaborating across risk-related teams
- Partner with TPRM, Procurement, Legal, and business stakeholders on continuous monitoring efforts
- Assess cybersecurity controls, identify gaps, and manage mitigation strategies to closure
- Conduct risk assessments evaluating security practices, data handling procedures, and regulatory compliance (HIPAA, PCI, GDPR)
- Prepare detailed risk assessment reports and maintain a comprehensive repository of documentation
- Design, implement, and integrate security solutions to address enterprise risks
- Develop Information Security Risk Metrics (KPIs/KRIs) to support the analytics team
- Support NIST, FedRAMP, and HIPAA compliance efforts including assessment readiness, POA&M management, and continuous monitoring
Mandatory Skills:
- One or more certifications: CISSP, CEH, CTIA, CAP, or EnCase Certified Examiner
- Bachelor's Degree in Computer Science, Cyber Security, IT, or related field (or 4 additional years of experience in lieu of degree)
- 5+ years of cybersecurity experience, specifically in Risk Management, with 3rd party/supplier risk assessment knowledge
- Experience with eGRC platforms (HyperProof, Archer, or ServiceNow GRC)
- Strong understanding of NIST Risk Management Framework and FAIR quantitative model
- Ability to develop and socialize security policies, standards, and procedures
- Knowledge of HIPAA/PHI security standards and network/firewall architecture
Nice-to-Have Skills:
- SOC Reporting / HITRUST knowledge
- Diverse background in cloud (off-prem) platforms
- Experience within the healthcare insurance/payor industry