Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Boston, MA, United States
Posted
17 hours ago
Stakeholder Management
Job Description
Job description:
Security Risk Assessment & GRC
- Experience performing architecture-focused risk assessments of critical-infrastructure and operationally significant environments.
- 5+ Years of experience conducting enterprise IT security risk assessments, preferably within healthcare or other highly regulated environments.
- Demonstrated ability to identify, analyze, quantify, and document cybersecurity risks across applications, infrastructure, clinical systems, and third-party environments.
- Strong understanding of GRC processes, including risk registers, risk acceptance, remediation tracking, control assessments, exceptions, executive-level risk reporting.
Healthcare & Regulatory Risk Frameworks
- Working knowledge of HIPAA Security Rule, HITECH, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-30, and relevant healthcare security practices.
- Experience mapping security controls and assessment findings to regulatory, organizational, and contractual requirements.
Security Architecture
- Strong understanding of enterprise architecture, including network segmentation, zero trust, IAM/PAM, encryption, endpoint security, vulnerability management, cloud security, logging/SIEM, and secure system design.
- Ability to assess proposed and existing architectures against security requirements and identify architectural control gaps and compensating controls.
Threat, Vulnerability & Control Analysis
- Ability to correlate threat scenarios, vulnerabilities, attack paths, business/critical impacts, existing controls, and residual risk to produce defensible risk determinations.
- Experience evaluating technical evidence such as vulnerability assessments, penetration test results, architecture diagrams, configuration reviews, data flows, and security-control evidence.
Risk Treatment & Remediation
- Demonstrated experience translating assessment findings into actionable remediation plans.
- Ability to work with infrastructure, application, engineering, privacy, compliance, project, and business stakeholders to develop practical risk treatments.
Governance, Communication & Stakeholder Management
- Strong written and verbal communication skills, with the ability to translate technical security and architecture issues into business risk for executives and risk owners.
- Experience presenting assessment results, residual risks, exceptions, and remediation status to security leadership and key stakeholders.
Similar jobs
- OP
Corporate Security GSOC Operator
NewOpenai
San Francisco🇺🇸Hybrid1 hour agoBackground ChecksComplianceContinuous Improvement+2 - JT
Information Security Analyst Exposure Management Lead IV
NewJaven Technologies, Inc
Cincinnati, OH🇺🇸Hybrid17 hours agoTechnology - TA
IT Security Engineer II
NewTalentFish LLC
Chicago, IL🇺🇸Hybrid17 hours agoAzureHIPAAStakeholder ManagementTechnology - NI
Cyber security Engineer
NewNimbusAITech LLC
Richmond, VA🇺🇸On-site17 hours agoAWSSOC 2Splunk+3Technology - SA
Information Security Analyst
NewSapear Inc
San Antonio, TX🇺🇸Hybrid17 hours agoAgileJiraMicrosoft OfficeTechnology - TE
Cyber Security Engineer - Detroit, MI, Madison, WI, Columbus, OH, Chicago, IL, Minneapolis, MN.
NewTechniPros, LLC
Detroit, MI🇺🇸Hybrid17 hours agoAWSMFASAML+5Technology