Skip to main content

Search
Search Jobs
search magnifying iconSearch Jobs

Information Security Governance Analyst


Lexington, Massachusetts | Remote

Apply Now
Address: 32 Hartwell Ave Job ID R0151056
POSITION FEATURES:

This is a fully remote position with occasional travel depending on business need.


PURPOSE AND SCOPE:

The Governance, Risk, and Compliance Analyst will play a key role in facilitating the development and maintenance of the organization's global governance, risk management, and compliance programs. This position will support a broad range of activities across the organization.

INFORMATION SECURITY GOVERNANCE ANALYST ADDENDUM:

  • Facilitating the identification, implementation, monitoring, and enforcement of information security frameworks.
  • Conducting maturity assessments to continuously validate and enhance the global information security posture.
  • Advancing the enterprise-wide information security governance function by fostering a union of business risk and information security practices.
  • Establishing, measuring, and managing metrics to quantify and report the global security posture.
  • Collaborating with business and IT leaders to analyze key global processes and develop information security requirements.
  • Facilitating the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations.
  • Articulating information security governance in business terms and championing awareness around IT governance, risk, and compliance.
  • Performing other duties as assigned.

PRINCIPAL DUTIES AND RESPONSIBILITIES:

  • Facilitates the development, implementation, and maintenance of an information security framework aligned with industry best practices.
  • Facilitates the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations.
  • Provides advice & counsel as directed within IT and information security initiatives to ensure the delivery of compliant and risk-appropriate solutions following existing department policies, standards, and procedures.
  • Facilitate examinations by security assessors and auditors for compliance obligations, such as HIPAA and ISO 27001.
  • Facilitates security risk assessments and recommends controls to mitigate identified security risks.
  • Communicates risk findings and recommendations to business stakeholders.
  • Facilitates the development and deployment of workforce security training and awareness.
  • Facilitates the development and implementation of global cybersecurity policies, standards, and procedures aligned with industry best practices, including NIST CSF and 800-series publications.
  • Facilitates the lifecycle management of information security policies.

PHYSICAL DEMANDS AND WORKING CONDITIONS:

  • The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

SUPERVISION:

  • None

EDUCATION:

  • Bachelor's Degree or an equivalent combination of education and experience

EXPERIENCE AND REQUIRED SKILLS:         

  • 2+ years' related experience in cybersecurity governance, risk, compliance, information security, and/or other related roles.
  • Advanced knowledge of internal control structure, data, and technology
  • Advanced knowledge of NIST CSF, NIST SP 800-series, HIPAA, FIPS, and ISO 27001:2022, and other industry best standards and requirements.
  • Excellent verbal and written communication skills.
  • Excellent organizational skills.
  • CISSP, CRISC, CISA, CISM, or other related certifications are preferred.
  • Demonstrated experience with ServiceNow GRC or a similar tool is preferred.

EO/AA Employer: Minorities/Females/Veterans/Disability/Sexual Orientation/Gender Identity

Fresenius Medical Care North America maintains a drug-free workplace in accordance with applicable federal and state laws.

You do not have any recently viewed jobs

You do not have any saved jobs