CVS Health-logo
CVS Health
·
April 18, 2025
Apply Now
This job has closed.

Security Risk Management Analyst

Boston, MA
Full-time
Hybrid
$65K/yr - $173K/yr
Entry, Mid Level
CVS Health is a health solutions company that provides integrated healthcare services to its members. The Security Risk Management Analyst will represent the company's information security practices, support clients, and manage complex security assurance relationships while collaborating with various teams.
Apply Now

Responsibilities

  • Represent CVS Health information security practices via our client facing Information Security Client Assurance function.
  • Provide extraordinary support to our clients and navigate complex client security assurance relationship issues.
  • Partner with other technology teams, business account teams, legal & privacy.
  • Delight our clients by providing Request For Information/Proposal (RFI/P) responses.
  • Respond to client third party risk management questionnaires.
  • Update client facing security materials based on the latest industry trends.
  • Leverage & maintain a current knowledge base for all information security policies, standards, procedures and practices to accurately represent CVS Health’s information security posture.

Qualification

Required

  • 2-5 years of Security Audit Management, Third Party Risk Management or information security related experience
  • 2+ years experience working with common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA/HITECH, HITRUST and the PCI-DSS
  • Ability to comprehend implications of security risk & technical control implementations
  • Worked independently
  • Take initiative; Be a self-starter
  • Execute on assigned tasks
  • Collaborate across many teams
  • Bachelor Degree or equivalent experience

Preferred

  • Knowledge of Enterprise level Information security policies and procedures
  • Working knowledge of regulatory (including audit frameworks) standards, including but not limited to NIST 800-53, SOX, SOC1/SOC2 Type II audits, HIPAA/HITECH, HITRUST, and the PCI-DSS
  • Previous experience in a client facing security role, third party risk management or controls assurance function
  • Cloud Security Control frameworks a bonus
  • Strong interpersonal and collaboration skills
  • Strong written and verbal communication skills

Benefits

  • Affordable medical plan options
  • 401(k) plan (including matching company contributions)
  • Employee stock purchase plan
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility
CVS Health is a health solutions company that provides an integrated healthcare services to its members.
Glassdoor
3.1
Founded in 1963
Woonsocket, Rhode Island, USA
10001+ employees
https://www.cvshealth.com/
CVS Health is a health solutions company that provides an integrated healthcare services to its members.
Glassdoor
3.1
Founded in 1963
Woonsocket, Rhode Island, USA
10001+ employees
https://www.cvshealth.com/