logo inner

Senior Cybersecurity Risk Governance Analyst

GHXOnsite

Job Summary:


Provide professional expertise and advise IT and senior leadership in matters relating to technology-related compliance with all applicable laws, regulations, industry standards and corporate compliance requirements. Assess changes in the regulatory, business and technology environment and recommend and implement or guide appropriate changes to IT policies, controls, and processes to address security and technology issues. Manage and coordinate IT audit activities by working with IT leaders, team members, external auditors, regulators, and other organizations that review and assess IT processes and controls.

Lead and execute cybersecurity risk management activities include internal compliance and risk management activities as well as third-party vendor security oversight and response to customer security inquiries.

Responsibilities:


  • Provide professional expertise and advise leadership in complying with all applicable laws, regulations, and accreditations, including Health Insurance Portability and Accountability Act (HIPAA), Payment Card Industry Data Security Standard (PCI-DSS), FedRAMP, HITRUST, ISO 27001, and EU General Data Protection Regulation (GDPR).
  • Facilitate, oversee, and provide point of contact for all IT audits, assessments, and other reviews of processes and technology. Work with teams to coordinate schedules for activity. Work with IT teams to deliver requested evidence, documentation, conduct interviews, walk through processes, test controls, and negotiate issues. Manage and monitor development and execution of action plans by reviewing and evaluating reports for trends, working with leadership to prioritize findings, and track progress toward agreed upon timeframes. Ensure issues are appropriately documented, relevant, and understood.
  • Perform IT risk and controls assurance assessments of internal and third-party technology-related processes and solutions, working with IT leaders, security architects, Procurement, and other subject matter experts.
  • Perform recurring assessments of information security and technology functions to measure maturity against industry standard baselines, identifying improvement areas, registering risks, and assisting with action plans to move processes to a higher level of maturity.
  • Develop and maintain operational metrics to ensure information security and technology risk and the performance of the IT risk and compliance program is measured sufficiently to enable success.
  • Mentor and coach team members through risk assessments, including scoping of an assessment, resolving conflict, and prioritization of issues. Perform peer review of work product and deliverables.
  • Continuously look to optimize processes, technology and capabilities through tactical and strategic development.
  • Other duties as assigned.

Knowledge and Skills:


  • Strong analytical skills;
  • Demonstration of ability to solve problems using best practices and systematic approach
  • Relationship builder; able to create and maintain a trusted network on all levels;
  • Good communication, influencing and negotiating skills;
  • Written and oral communication skills including the ability to communicate complex technical issues to non-technical staff;
  • Project management and organizational skills;
  • Tactful and diplomatic when engaging with all levels of management always maintaining aprofessional demeanor.

Required Experience:


  • 5-8 years direct experience with information security, IT controls assurance and IT audit facilitation
  • Working knowledge of industry standards such as NIST Cybersecurity Framework, FedRAMP, NIST SP 800-53, ISO 27001, Sarbanes-Oxley, SOC1, SOC2, HIPAA, HITRUST and other similar frameworks.

Preferred Experience:


  • Experience in cloud-based environments for production applications, including Amazon Web Services, Microsoft Azure, GCP or other large-scale cloud deployment.
  • Understanding of attack vectors and methodologies.
  • Ability to weigh business risks and enforce appropriate information security measures.
  • CISSP, CISM, CISA, CCSA or equivalent certification preferred.

Proficient in the use of Microsoft Office (Excel and PowerPoint), Power BI and Power Automate.

GHX: It's the way you do business in healthcare


Global Healthcare Exchange (GHX) enables better patient care and billions in savings for the healthcare community by maximizing automation, efficiency and accuracy of business processes.GHX is a healthcare business and data automation company, empowering healthcare organizations to enable better patient care and maximize industry savings using our world class cloud-based supply chain technology exchange platform, solutions, analytics and services. We bring together healthcare providers and manufacturers and distributors in North America and Europe - who rely on smart, secure healthcare-focused technology and comprehensive data to automate their business processes and make more informed decisions.It is our passion and vision for a more operationally efficient healthcare supply chain, helping organizations reduce - not shift - the cost of doing business, paving the way to delivering patient care more effectively.

Together we take more than a billion dollars out of the cost of delivering healthcare every year. GHX is privately owned, operates in the United States, Canada and Europe, and employs more than 1000 people worldwide. Our corporate headquarters is in Colorado, with additional offices in Europe.

Disclaimer


Global Healthcare Exchange, LLC and its North American subsidiaries (collectively, “GHX”) provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law. All qualified applicants will receive consideration for employment without regard to any status protected by applicable law.

This EEO policy applies to all terms, conditions, and privileges of employment, including hiring, training and development, promotion, transfer, compensation, benefits, educational assistance, termination, layoffs, social and recreational programs, and retirement.GHX believes that employees should be provided with a working environment which enables each employee to be productive and to work to the best of his or her ability. We do not condone or tolerate an atmosphere of intimidation or harassment based on race, color, national origin, sex, sexual orientation, gender identity, religion, age, genetic information, disability, veteran status or any other status protected by applicable law.

GHX expects and requires the cooperation of all employees in maintaining a discrimination and harassment-free atmosphere. Improper interference with the ability of GHX’s employees to perform their expected job duties is absolutely not tolerated.

Life at GHX

GHX is a software-as-a-service company that's reducing the cost of doing business in healthcare by automating supply chain processes and improving visibility into the products used in patient care. We've built the GHX Global Network, the world's largest community of healthcare trading partners, connecting supply chain, finance and clinical professionals with their suppliers. Our cloud-based technology makes it easier for customers to drive costs out of the healthcare supply chain. Since 2010, we've saved the healthcare industry $5+ billion. Today were expanding our solutions to further enhance data management and allow integration of clinical and business systems. The Industry We Serve Our focus is on the healthcare supply chain, through which hospitals and their suppliers buy and deliver the thousands of medical-surgical supplies that clinicians need to effectively care for patients. For most hospitals, supply chain costs are the second largest and fastest growing operational expense, so reining in these costs is imperative. Our Products and Services At the heart of GHX is the GHX Exchange, a platform that connects healthcare providers and suppliers so they can work together electronically. This helps lower costs and simplifies supply chain management by eliminating error-prone, manual order processes. GHX solutions include: An open and neutral electronic trading exchange Procurement and accounts payable automation Content, contract and inventory management Business intelligence and reporting Standards enablement and data synchronization
Thrive Here & What We Value- Fostering a diverse and inclusive workplace where everyone feels valued and supported- Committed to building a team that represents a variety of backgrounds, perspectives, and skills- Emphasis on maximizing automation, efficiency, and accuracy of business processes- Passion for a more operationally efficient healthcare supply chain- Belief in empowering healthcare organizations to enable better patient care and maximize industry savings using our world class cloud-based supply chain technology exchange platform, solutions, analytics, and services.- Dedicated to providing equal opportunities for qualified applicants- Believes in fostering a diverse and inclusive workplace where everyone feels valued and supported- GHX expects and requires the cooperation of all employees in maintaining a discrimination and harassment-free atmosphere.</s>
Your tracker settings

We use cookies and similar methods to recognize visitors and remember their preferences. We also use them to measure ad campaign effectiveness, target ads and analyze site traffic. To learn more about these methods, including how to disable them, view our Cookie Policy or Privacy Policy.

By tapping `Accept`, you consent to the use of these methods by us and third parties. You can always change your tracker preferences by visiting our Cookie Policy.

logo innerThatStartupJob
Discover the best startup and their job positions, all in one place.
Copyright © 2025