CVS Health-logo
CVS Health
·
April 15, 2025
Apply Now
This job has closed.

Security Risk Management Analyst

Work At Home - Utah
Full-time
Hybrid
$65K/yr - $159K/yr
Entry, Mid Level
CVS Health is a health solutions company that provides integrated healthcare services to its members. The Security Risk Management Analyst conducts security risk assessments and provides risk mitigation strategies to ensure compliance with information security standards while collaborating with various stakeholders.
Apply Now

Responsibilities

  • Conducts thorough security risk assessments for new technologies before deployment and technologies post-deployment in the production environment
  • Identifies, assesses, analyzes security risks, scrutinizes potential vulnerabilities, and provides risk mitigation strategies to ensure compliance and adherence to information security standards for a seamless and secure integration
  • Engage project managers, project management team members including developers, architects, infrastructure engineers, and EIS stakeholders as applicable
  • Describe technical issues to business partners or senior leaders in risk terms that are clear and understandable while still having some subject matter expertise
  • Lead small teams, mentor junior team members, oversee third party contractors, and respond to critical requests

Qualification

Required

  • 2+ years of information security experience
  • 2+ years working knowledge of common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA/HITECH, HITRUST and PCI-DSS
  • 2+ years working knowledge of Information Technology including Cloud, access management, architecture, infrastructure, operating systems, application/software development, and endpoint security
  • Bachelor’s degree or equivalent experience.

Preferred

  • Industry related certification such as CISSP, CISM, CRISC, etc.
  • Ability to comprehend implications of security risk (inherent risk, residual risks), compensating controls, etc.
  • Solid written and verbal communication skills
  • Ability to demonstrate critical thinking and knowledge of risk management basic processes, tools, and techniques
  • Experience operating in applications including Archer, Qualys, Checkmarx, and Prisma
  • Solid knowledge of Information Security policies and procedures
  • Solid knowledge of regulatory (including Audit frameworks) standards, including but not limited to NIST 800-53, SOX, SOC1/SOC2 Type II audits, HIPPA/HITECH, HITRUST, and PCI-DSS
  • Knowledge of current security threat and vulnerability trends
  • Understanding of cloud Security best practices and frameworks

Benefits

  • Affordable medical plan options
  • 401(k) plan (including matching company contributions)
  • Employee stock purchase plan
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility
CVS Health is a health solutions company that provides an integrated healthcare services to its members.
Glassdoor
3.1
Founded in 1963
Woonsocket, Rhode Island, USA
10001+ employees
https://www.cvshealth.com/
CVS Health is a health solutions company that provides an integrated healthcare services to its members.
Glassdoor
3.1
Founded in 1963
Woonsocket, Rhode Island, USA
10001+ employees
https://www.cvshealth.com/