Sr. Risk Analyst

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

Minimum of 5 years in security, audits, or risk assessments related to frameworks like SOC 2, HIPAA, and PCI., Proven experience in technical assessments and documentation of security processes., Strong analytical skills with attention to detail and ability to manage multiple priorities., Excellent communication skills for engaging with cross-functional teams and stakeholders..

Key responsabilities:

  • Lead the development and implementation of a Data Governance framework.
  • Manage risk exception processes and conduct vendor security assessments.
  • Develop and deliver training programs on data governance and compliance.
  • Provide support for compliance activities related to PCI, SOC 2, and HIPAA standards.

Datavant logo
Datavant Computer Software / SaaS Startup https://www.datavant.com/
5001 - 10000 Employees
See all jobs

Job description

Datavant is a data platform company and the world’s leader in health data exchange. Our vision is that every healthcare decision is powered by the right data, at the right time, in the right format.

Our platform is powered by the largest, most diverse health data network in the U.S., enabling data to be secure, accessible and usable to inform better health decisions. Datavant is trusted by the world’s leading life sciences companies, government agencies, and those who deliver and pay for care. 

By joining Datavant today, you’re stepping onto a high-performing, values-driven team. Together, we’re rising to the challenge of tackling some of healthcare’s most complex problems with technology-forward solutions. Datavanters bring a diversity of professional, educational and life experiences to realize our bold vision for healthcare.

What We’re Looking For

We are seeking a seasoned Senior Risk Analyst to spearhead the development and support of our Data Governance program in collaboration with our Privacy Office. This role encompasses managing risk exception processes, conducting vendor assessments, leading training and awareness initiatives, and providing comprehensive support for compliance activities related to PCI, SOC 2, and HIPAA standards. As a key member of the Information Security Governance, Risk, and Compliance (GRC) .

What You Will Do

  • Data Governance Program Development: Lead the creation and implementation of a robust Data Governance framework, ensuring alignment with organizational objectives and regulatory requirements.​
  • Collaboration with Privacy Office: Partner with the Privacy Office to ensure data governance strategies effectively address privacy concerns and comply with relevant regulations.​
  • Risk Management: Manage the risk exception process by evaluating, documenting, and tracking risk exceptions, and recommending appropriate mitigation strategies.​
  • Vendor Assessments: Conduct thorough security assessments of third-party vendors to evaluate their compliance with organizational security standards and regulatory requirements.​
  • Training and Awareness: Develop and deliver comprehensive training programs to enhance employee awareness of data governance policies, security protocols, and compliance obligations.​
  • Compliance Support: Provide expert support for compliance activities related to PCI, SOC 2, HIPAA, and other relevant frameworks, ensuring adherence to industry standards and regulations.​
  • Policy Development: Simplify complex security compliance requirements into clear technical control specifications and organizational policies.​
  • Continuous Improvement: Identify and communicate control gaps, contributing to the development and implementation of remediation plans to enhance the organization's security posture.​

What You Need to Succeed

  • Experience: A minimum of 5 years in security, audits, customer assurance, control assessments, or risk assessments based on security and privacy frameworks such as SOC 2, ISO 27001, HIPAA, PCI, HITRUST, NIST 800-53, or FedRAMP.​
  • Technical Proficiency: Proven experience in performing technical assessments and documentation of key controls and security processes, with a solid understanding of IT processes and industry best practices.​
  • Analytical Skills: Strong analytical and problem-solving abilities, with a keen attention to detail and the capacity to manage multiple priorities in a fast-paced environment.​
  • Communication Skills: Excellent communication and interpersonal skills, capable of effectively engaging with cross-functional teams, stakeholders, and customers.​
  • Adaptability: Ability to operate effectively in ambiguous situations, demonstrating flexibility and resilience.​

What Helps You Stand Out

  • Certifications: Possession of industry-recognized security, cloud, or audit professional certifications such as CISA, CISM, CISSP, or CCSP.​
  • Healthcare Industry Experience: Prior experience in IT security and audit within the healthcare sector.​
  • Cloud Security Knowledge: Familiarity with cloud services environments (e.g., AWS) and cloud security controls.

 

We are committed to building a diverse team of Datavanters who are all responsible for stewarding a high-performance culture in which all Datavanters belong and thrive. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status.

At Datavant our total rewards strategy powers a high-growth, high-performance, health technology company that rewards our employees for transforming health care through creating industry-defining data logistics products and services.

The range posted is for a given job title, which can include multiple levels. Individual rates for the same job title may differ based on their level, responsibilities, skills, and experience for a specific job.

The estimated total cash compensation range for this role is:
$136,000$170,000 USD

To ensure the safety of patients and staff, many of our clients require post-offer health screenings and proof and/or completion of various vaccinations such as the flu shot, Tdap, COVID-19, etc. Any requests to be exempted from these requirements will be reviewed by Datavant Human Resources and determined on a case-by-case basis. Depending on the state in which you will be working, exemptions may be available on the basis of disability, medical contraindications to the vaccine or any of its components, pregnancy or pregnancy-related medical conditions, and/or religion.

This job is not eligible for employment sponsorship.

Datavant is committed to a work environment free from job discrimination. We are proud to be an Equal Employment Opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, or other legally protected status. To learn more about our commitment, please review our EEO Commitment Statement here. Know Your Rights, explore the resources available through the EEOC for more information regarding your legal rights and protections. In addition, Datavant does not and will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay. 

At the end of this application, you will find a set of voluntary demographic questions. If you choose to respond, your answers will be anonymous and will help us identify areas for improvement in our recruitment process. (We can only see aggregate responses, not individual ones. In fact, we aren’t even able to see whether you’ve responded.) Responding is entirely optional and will not affect your application or hiring process in any way.

Datavant is committed to working with and providing reasonable accommodations to individuals with physical and mental disabilities. If you need an accommodation while seeking employment, please contact us at peopleteam@datavant.com. We will review your request for reasonable accommodation on a case-by-case basis.

For more information about how we collect and use your data, please review our Privacy Policy.

 

Required profile

Experience

Industry :
Computer Software / SaaS
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Analytical Skills
  • Verbal Communication Skills
  • Adaptability

Risk Management Specialist Related jobs