PURPOSE AND SCOPE:
The Lead Governance, Risk, and Compliance Analyst will play a key role in leading the development and maintenance of the organization's global governance, risk management, and compliance programs. This position will support a broad range of activities across the organization.
LEAD INFORMATION SECURITY POLICY ANALYST ADDENDUM
Leads the development and implementation of global cybersecurity policies, standards, and procedures aligned with industry best practices, including NIST CSF and 800-series publications.
Advances the enterprise-wide cybersecurity governance function by fostering a union of business risk and information security practices.
Collaborates with business and IT leaders to analyze key global processes and develop new or adjusted information security requirements.
Works closely with security operations, engineering, and architecture teams to continuously align and improve information security practices.
Articulates information security governance in business terms and champion awareness of requirements and best practices.
Facilitate examinations by security assessors and auditors for compliance obligations, such as HIPAA and ISO 27001.
Establishes, measures, and manages metrics to quantify and report global security posture.
Other duties as assigned.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
Leads the development, implementation, and maintenance of an information security framework aligned with industry leading practices.
Leads the design and documentation of technical, administrative, and physical controls to ensure the business demonstrates compliance with its regulatory and compliance obligations.
Provides strategic direction within IT and information security initiatives to ensure the delivery of compliant and risk-appropriate solutions.
Facilitate examinations by security assessors and auditors for compliance obligations, such as HIPAA and ISO 27001.
Leads security risk assessments and recommends controls to mitigate identified security risks.
Communicates risk findings and recommendations to business stakeholders.
Leads the development and deployment of workforce security training and awareness.
Leads the development and implementation of global cybersecurity policies, standards, and procedures aligned with industry best practices, including NIST CSF and 800-series publications.
Leads the lifecycle management of information security policies.
Provides mentoring and quality reviews for other analysts.
PHYSICAL DEMANDS AND WORKING CONDITIONS:
SUPERVISION:
EDUCATION:
Bachelor's Degree or an equivalent combination of education and experience
EXPERIENCE AND REQUIRED SKILLS:
7+ years' related experience in cybersecurity governance, risk, compliance, information security, and/or other related roles.
Advanced knowledge of internal control structure, data, and technology
Advanced knowledge of NIST CSF, NIST SP 800-series, HIPAA, FIPS, and ISO 27001:2022, and other industry-leading standards and requirements.
Excellent verbal and written communication skills.
Excellent organizational skills.
CISSP, CRISC, CISA, CISM, or other related certifications are preferred.
Demonstrated experience with ServiceNow GRC or a similar tool is preferred.
EO/AA Employer: Minorities/Females/Veterans/Disability/Sexual Orientation/Gender Identity
Fresenius Medical Care North America maintains a drug-free workplace in accordance with applicable federal and state laws.
Fully remote position with occasional travel depending on business need.
As long as the job advertisement is displayed, you can apply quickly and easily.
We care about sharing information and experiences as this helps us learn from our mistakes and each other. We tackle challenges together by reaching out to colleagues both near and far. We communicate openly.
We challenge the status quo and show interest in what happens around us. We ask questions to clearly understand what needs to be done and take ownership of the results.
We live up to our own expectations, show respect and lead by example. We act with integrity and in line with our standards every day.
We make things better today than they were yesterday. We pitch ideas on how to improve and innovate.
Empowering people. Advancing care. Inspiring with our purpose and values.
Everything we do here is about making people’s lives better, simpler and longer. Our teams work cross-functionally to reproduce the complex function of kidneys with treatments that meet high quality standards, improve clinical outcomes, and are sustainable and compliant. Internally, we promote diversity and inclusion as key elements of a positive, supportive work environment. Our values support our mission to develop high quality products and services, to have a positive impact on the health and wellbeing of patients, and to lead Fresenius Medical Care towards a successful, sustainable future.