Job Description Summary
:
We are looking for a talented and experienced Security Risk Analyst to
assist in the growth of our Security Risk Program focused on ensuring the
security and integrity of Zelis data and assets.
The Security Risk Analyst is a member of the Cybersecurity team and is
responsible for ensuring Zelis is protecting data and assets from threats
utilizing Zelis control and policy as well as industry leading practices to
support the Zelis Third Party Risk, Risk Management, and Business Continuity
/ Disaster Recovery program. The Security Risk Analyst selected for this
role must have experience with risk management concepts and possess a
background evaluating and architecting secure solutions.
Job Description
:
-
Review current vendor application and infrastructure technology
solutions to understand proper adherence to security controls and make
security recommendations for remediation strategy, track remediation
efforts as appropriate
-
Provides guidance to vendor managers with respect to Zelis’ standards
and their application to specific vendor engagements, including
recommendations with respect to potential risk mitigation/remediation
plans. Support strategic projects to mature tools, operations, and
personnel education within Risk Management and Third-Party Risk
Management
-
Manage Zelis’ vendor relationships and in-depth security assessments
-
Collaborates with Zelis leadership and vendors in developing corrective
action plans for vendor information security, performance, financial or
business process risks
-
Conduct risk assessments across the enterprise to support the
identification and management of key risks
-
Perform business impact analysis and assess disaster recovery programs
to establish mature BCP operations
-
Participate in incident response program including preparation and
tabletop exercises, detection & analysis, recovery, and
post-incident activities
-
Corporate Compliance Responsibility - As an essential function,
responsible for complying with Zelis’ Corporate Compliance Program,
Standards of Business Conduct, applicable contracts, laws, rules and
regulations, policies, and procedures as it applies to individual job
duties, the department and the Company. This position must exercise due
diligence to prevent, detect, and report unlawful and/or unethical
conduct by fellow co-workers, professional affiliates and/or
agents
Professional Experience:
Required:
-
Five (5) + years’ experience in Vendor Management, Cyber Security and/or
Risk Management
-
Experience performing Information Security / Technology risk
assessments
-
Experience overseeing adherence to policies and remediation efforts by
third parties
-
Experience overseeing adherence to and architecting secure solutions
utilizing policy, control, and industry leading practices
-
Experience evaluating and supporting Business Continuity Planning and
Disaster Recovery Management
-
Experience with regulatory requirements such as HIPAA / HITRUST
-
Ability to manage multiple work streams simultaneously
-
Strong verbal and written communications skills
-
Strong relationship management experience and skills
-
Excellent research and analytical skills
-
Ability to effectively prioritize and execute tasks in a high-pressure
environment
Preferred:
-
GRC tools such as ServiceNow experience
-
Healthcare Industry experience
-
CISA, CISM, CISP or equivalent certification
-
Consulting experience
Education:
Bachelor’s degree (or) related degree and experience