CVS Health is a health solutions company that provides integrated healthcare services to its members. The Security Risk Management Analyst conducts security risk assessments and provides risk mitigation strategies to ensure compliance with information security standards while collaborating with various stakeholders.
Conducts thorough security risk assessments for new technologies before deployment and technologies post-deployment in the production environment
Identifies, assesses, analyzes security risks, scrutinizes potential vulnerabilities, and provides risk mitigation strategies to ensure compliance and adherence to information security standards for a seamless and secure integration
Engage project managers, project management team members including developers, architects, infrastructure engineers, and EIS stakeholders as applicable
Describe technical issues to business partners or senior leaders in risk terms that are clear and understandable while still having some subject matter expertise
Lead small teams, mentor junior team members, oversee third party contractors, and respond to critical requests
Qualification
Required
2+ years of information security experience
2+ years working knowledge of common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA/HITECH, HITRUST and PCI-DSS
2+ years working knowledge of Information Technology including Cloud, access management, architecture, infrastructure, operating systems, application/software development, and endpoint security
Bachelor’s degree or equivalent experience.
Preferred
Industry related certification such as CISSP, CISM, CRISC, etc.
Ability to comprehend implications of security risk (inherent risk, residual risks), compensating controls, etc.
Solid written and verbal communication skills
Ability to demonstrate critical thinking and knowledge of risk management basic processes, tools, and techniques
Experience operating in applications including Archer, Qualys, Checkmarx, and Prisma
Solid knowledge of Information Security policies and procedures
Solid knowledge of regulatory (including Audit frameworks) standards, including but not limited to NIST 800-53, SOX, SOC1/SOC2 Type II audits, HIPPA/HITECH, HITRUST, and PCI-DSS
Knowledge of current security threat and vulnerability trends
Understanding of cloud Security best practices and frameworks
Benefits
Affordable medical plan options
401(k) plan (including matching company contributions)
Employee stock purchase plan
No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching
Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility
CVS Health is a health solutions company that provides an integrated healthcare services to its members.
Glassdoor
3.1
Founded in 1963
Woonsocket, Rhode Island, USA
10001+ employees
https://www.cvshealth.com/
CVS Health is a health solutions company that provides an integrated healthcare services to its members.