Haystack
← Back to Jobs
Administrative
SW

Security Risk Assessor

Swanktek IncBoston, MA🇺🇸United StatesPosted Sep 25, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Boston, MA, United States
Posted
17 hours ago
Stakeholder Management

Job Description

Job description:
Security Risk Assessment & GRC
  • Experience performing architecture-focused risk assessments of critical-infrastructure and operationally significant environments.
  • 5+ Years of experience conducting enterprise IT security risk assessments, preferably within healthcare or other highly regulated environments.
  • Demonstrated ability to identify, analyze, quantify, and document cybersecurity risks across applications, infrastructure, clinical systems, and third-party environments.
  • Strong understanding of GRC processes, including risk registers, risk acceptance, remediation tracking, control assessments, exceptions, executive-level risk reporting.
Healthcare & Regulatory Risk Frameworks
    • Working knowledge of HIPAA Security Rule, HITECH, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-30, and relevant healthcare security practices.
    • Experience mapping security controls and assessment findings to regulatory, organizational, and contractual requirements.
Security Architecture
    • Strong understanding of enterprise architecture, including network segmentation, zero trust, IAM/PAM, encryption, endpoint security, vulnerability management, cloud security, logging/SIEM, and secure system design.
    • Ability to assess proposed and existing architectures against security requirements and identify architectural control gaps and compensating controls.
Threat, Vulnerability & Control Analysis
    • Ability to correlate threat scenarios, vulnerabilities, attack paths, business/critical impacts, existing controls, and residual risk to produce defensible risk determinations.
    • Experience evaluating technical evidence such as vulnerability assessments, penetration test results, architecture diagrams, configuration reviews, data flows, and security-control evidence.
Risk Treatment & Remediation
    • Demonstrated experience translating assessment findings into actionable remediation plans.
    • Ability to work with infrastructure, application, engineering, privacy, compliance, project, and business stakeholders to develop practical risk treatments.
Governance, Communication & Stakeholder Management
    • Strong written and verbal communication skills, with the ability to translate technical security and architecture issues into business risk for executives and risk owners.
    • Experience presenting assessment results, residual risks, exceptions, and remediation status to security leadership and key stakeholders.

Similar jobs