HomeJob SearchInformation Security …
Lexington, Massachusetts, USAPermanent positionFull time

Information Security Governance Analyst

Add job to watchlist

PURPOSE AND SCOPE:

The Governance, Risk, and Compliance Analyst will play a key role in facilitating the development and maintenance of the organization's global governance, risk management, and compliance programs. This position will support a broad range of activities across the organization.

INFORMATION SECURITY GOVERNANCE ANALYST ADDENDUM:

  • Facilitating the identification, implementation, monitoring, and enforcement of information security frameworks.
  • Conducting maturity assessments to continuously validate and enhance the global information security posture.
  • Advancing the enterprise-wide information security governance function by fostering a union of business risk and information security practices.
  • Establishing, measuring, and managing metrics to quantify and report the global security posture.
  • Collaborating with business and IT leaders to analyze key global processes and develop information security requirements.
  • Facilitating the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations.
  • Articulating information security governance in business terms and championing awareness around IT governance, risk, and compliance.
  • Performing other duties as assigned.

PRINCIPAL DUTIES AND RESPONSIBILITIES:

  • Facilitates the development, implementation, and maintenance of an information security framework aligned with industry best practices.
  • Facilitates the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations.
  • Provides advice & counsel as directed within IT and information security initiatives to ensure the delivery of compliant and risk-appropriate solutions following existing department policies, standards, and procedures.
  • Facilitate examinations by security assessors and auditors for compliance obligations, such as HIPAA and ISO 27001.
  • Facilitates security risk assessments and recommends controls to mitigate identified security risks.
  • Communicates risk findings and recommendations to business stakeholders.
  • Facilitates the development and deployment of workforce security training and awareness.
  • Facilitates the development and implementation of global cybersecurity policies, standards, and procedures aligned with industry best practices, including NIST CSF and 800-series publications.
  • Facilitates the lifecycle management of information security policies.

PHYSICAL DEMANDS AND WORKING CONDITIONS:

  • The physical demands and work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

SUPERVISION:

  • None

EDUCATION:

  • Bachelor's Degree or an equivalent combination of education and experience

EXPERIENCE AND REQUIRED SKILLS:         

  • 2+ years' related experience in cybersecurity governance, risk, compliance, information security, and/or other related roles.
  • Advanced knowledge of internal control structure, data, and technology
  • Advanced knowledge of NIST CSF, NIST SP 800-series, HIPAA, FIPS, and ISO 27001:2022, and other industry best standards and requirements.
  • Excellent verbal and written communication skills.
  • Excellent organizational skills.
  • CISSP, CRISC, CISA, CISM, or other related certifications are preferred.
  • Demonstrated experience with ServiceNow GRC or a similar tool is preferred.

EO/AA Employer: Minorities/Females/Veterans/Disability/Sexual Orientation/Gender Identity

Fresenius Medical Care North America maintains a drug-free workplace in accordance with applicable federal and state laws.

This is a fully remote position with occasional travel depending on business need.

Career with a purpose

Career with a purpose

We offer an opportunity to create and deliver treatments that save and change lives for the better. We’ll support your ongoing development. And you’ll be part of a dedicated team of people who inspire each other to create the best possible healthcare outcomes each and every day.
Inclusion and diversity

Inclusion and diversity

Joining Fresenius Medical Care means becoming part of a team that values diversity. We embrace the wealth of different backgrounds, cultures, experiences and opinions that make up our workforce and strive to create an inclusive atmosphere in which all our employees feel valued.
Stability

Stability

Developing innovative products and continuously improving our renal therapies made us the clear market leader in the production of hemodialysis machines, with sustainable, profitable growth . This position provides our 125000 employees with the stability and security they need to help improve the lives of our patients.
Learning and development

Learning and development

We offer participation in programs at world-class business schools, leadership development, regular training for our nurses, health care professionals and manufacturing staff and digital access to high-quality educational content for all employees worldwide 24/7. 
Local benefits

Local benefits

Our employees enjoy both local and global opportunities for growth and personal fulfilment. We offer local benefits designed to suit the requirements of the respective country and place of work to create ideal conditions everywhere.
Work-life balance

Work-life balance

We want to empower people to deliver better care. Therefore, we promote a better work-life balance through flexible working hours, part-time models, the possibility to work from home, and more.
Show all 6 services

At a glance

Earliest possible start:

As from now

Contract type:

Permanent position

Company:

Fresenius Medical Care

Region / Business Unit:

North America

Location:

Lexington, Massachusetts, USA

Working condition:

Full time

Job function:

Information TechnologyInformation Security & Risk Management

Reference number:

R0151056

Publishing Date:

04/24/2024

As long as the job advertisement is displayed, you can apply quickly and easily.

Add job to watchlist
Print Job Ad
Recommend this job
Collaborative

We care about sharing information and experiences as this helps us learn from our mistakes and each other. We tackle challenges together by reaching out to colleagues both near and far. We communicate openly.

Proactive

We challenge the status quo and show interest in what happens around us. We ask questions to clearly understand what needs to be done and take ownership of the results.

Reliable

We live up to our own expectations, show respect and lead by example. We act with integrity and in line with our standards every day.

Excellent

We make things better today than they were yesterday. We pitch ideas on how to improve and innovate.

What we stand for

Empowering people. Advancing care. Inspiring with our purpose and values.

Everything we do here is about making people’s lives better, simpler and longer. Our teams work cross-functionally to reproduce the complex function of kidneys with treatments that meet high quality standards, improve clinical outcomes, and are sustainable and compliant. Internally, we promote diversity and inclusion as key elements of a positive, supportive work environment. Our values support our mission to develop high quality products and services, to have a positive impact on the health and wellbeing of patients, and to lead Fresenius Medical Care towards a successful, sustainable future.