Sr. Analyst, IT Security Governance Risk and Compliance
hace 1 semana
Vantive is a vital organ therapy company on a mission to extend lives and expand possibilities for patients and care teams everywhere. For 70 years, our team has driven meaningful innovations in kidney care. As we build on our legacy, we are deepening our commitment to elevating the dialysis experience through digital solutions and advanced services, while looking beyond kidney care and investing in transforming vital organ therapies. Greater flexibility and efficiency in therapy administration for care teams, and longer, fuller lives for patients— that is what Vantive aspires to deliver.
We believe Vantive will not only build our leadership in the kidney care space, it will also offer meaningful work to those who join us. At Vantive, you will become part of a community of people who are focused, courageous and don’t settle for the mediocre. Each of us is driven to help improve patients’ lives worldwide. Join us in advancing our mission to extend lives and expand possibilities.
**Your role at Vantive**
**What you'll be doing**
- Demonstrate solid technical knowledge of industry security practices, attain solid business knowledge, handle complex problems, possess strong knowledge of the organizational policies, standards and procedures, alongside security frameworks and benchmarking, have strong communication and interpersonal skills.
- Ensure familiarity with relevant laws, regulations, and industry standards, such as HIPAA, GDPR, NIST, and ISO 27001.
- Collaborate within a team environment to create and lead training and awareness programs to educate employees on security best practices and the importance of compliance.
- Maintain knowledge of emerging trends and technologies in cybersecurity and risk management, and recommend improvements to existing security risk and compliance processes.
- Manage and report on key performance indicators (KPIs) to measure the effectiveness of security risk and compliance programs.
- Support and engage in third party risk management, including collaboration with key stakeholders such as Procurement, IT, and Global Business Units that engage with external vendors.
- Responsible for providing guidance, and supporting the development of company internal control guidelines and standard security documents in alignment with critical security frameworks.
- Must be well versed in industry standard security frameworks such as NIST 800-53, NIST CSF, ISO 27001, Cyber Essentials, etc.
- 3 to 5 years of experience with audit, controls, security awareness, and third party supplier management programs, or equivalent work experience with security governance, risk and compliance.
- Determine and manage priorities, timelines, and schedules.
- Interact regularly with customers and vendors to understand their business and to anticipate compliant IT solutions needed.
- Participate in the research, analysis, selection, and implementation of new governance and compliance tools, technologies and/or services.
- Strong verbal and written communication skills used to execute training and awareness objectives. Experience with successful phishing solutions and routine awareness campaigns is preferred.
**What you'll bring**
- Strong communication and interpersonal skills. Project management and team leadership experience required.
- Strong sense of business knowledge, including healthcare and technology.
- Ability to organize and analyze data effectively.
- Effective and impactful action through collaboration and communication.
- Bachelor’s degree in computer science, information assurance, cybersecurity, or a related field.
- At least 5 years of experience in a security risk and compliance role, preferably in the healthcare or finance industries.
- In-depth knowledge of relevant laws, regulations, and industry standards, such as HIPAA, PCI, GDPR, ISO 27001 and NIST.
- Strong understanding of security risk assessment and mitigation techniques, including vulnerability management and penetration testing.
- Experience with GRC platforms, process engineering, and other security technologies.
- Excellent communication and interpersonal skills, with the ability to collaborate with cross-functional teams and stakeholders.
- Strong analytical and problem-solving skills, with the ability to identify and mitigate potential security risks.
- Certifications such as CISSP, CISM, or CISA preferred.
**Reasonable Accommodation**
**Recruitment Fraud Notice**
Vantive has discovered incidents of employment scams, where fraudulent parties pose as Vantive employees, recruiters, or other agents, and engage with online job seekers in an attempt to steal personal and/or financial information. To learn how you can protect yourself, review our Recruitment Fraud Notice.
-
System Security and Compliance Specialist
hace 5 días
Guadalajara, México beBeeGovernance A tiempo completoJob Title A System Security and Compliance Specialist is sought to join a dynamic organization. This key role involves the design and implementation of SAP Security and Governance, Risk, and Compliance (GRC) solutions to ensure compliance with regulatory requirements.
-
Application Security Engineer
hace 2 semanas
Guadalajara, México Western governance university A tiempo completoApplication Security EngineerThe Application Security Engineer is a position of technical expertise, influence, and leadership in the security technology realm. The Application Security Engineer is highly passionate and is a deeply technical security.Expert to help the University and its employees develop sound security practices. WGU The Application...
-
Security and Compliance Analyst
hace 2 semanas
Guadalajara, México Espressive A tiempo completo_Espressive_ redefines how employees get help by delivering exceptional employee experiences. We were founded on the belief that getting help at work shouldn’t be so hard. While others have focused on solving the problems faced by help desk analysts, _Espressive_ shifted the focus to the employee — because you can’t have self-service if employees are...
-
Cloud Compliance and Governance Architect
hace 1 semana
Guadalajara, México Capgemini Engineering A tiempo completoLocation: Remote - México At Capgemini Engineering, the world leader in engineering services, we bring together a global team of engineers, scientists, and architects to help the world’s most innovative companies unleash their potential. From autonomous cars to life-saving robots, our digital and software technology. **YOUR ROLE** As Cloud Compliance...
-
Risk and Compliance Analyst
hace 6 días
Guadalajara, México Diligent Corporation A tiempo completo**About Us** Diligent is the global leader in modern governance, providing SaaS solutions across governance, risk, compliance, audit and ESG. Empowering more than 1 million users and 700,000 board members and leaders with a holistic view of their organization's GRC practices so they can make better decisions, faster. No matter the challenge. At Diligent,...
-
Cloud Architect
hace 4 días
Guadalajara, México Capgemini Engineering A tiempo completo**Capgemini Engineering is a world leader, we provide innovative and unique R&D and engineering services across all industries. Join us for a career full of opportunities, where you can make a difference.**About the role:**You will participate in ambitious projects of a top US client in the Telecom industry as a Cloud Architect focused on governance,...
-
Data Governance Analyst
hace 1 semana
Guadalajara, México AstraZeneca A tiempo completo**Data Governance Analyst**:Positions are open to Mexican Citizens and official residents of Mexico.Location: Guadalajara (hybrid)Strong English communication skills required**Must Submit Resume in English****About the AstraZeneca**AstraZeneca is a global, science-led, patient-focused pharmaceutical company that focuses on the discovery, development, and...
-
Information Security
hace 2 semanas
Guadalajara, México HireRight A tiempo completoAbout HireRight: Overview: This role is based in Mexico as an Information Security - Third Party Risk Management Analyst (SECGRC), reporting to the InfoSec TPRM Lead Analyst on the Governance Risk & Compliance (GRC) Team. This person will assist in the management and reporting of all aspects of vendor/ Third Party Risk Management (TPRM) operational...
-
Cloud Architect
hace 4 días
Guadalajara, México Capgemini Engineering A tiempo completoCapgemini Engineering is a world leader, we provide innovative and unique R&D and engineering services across all industries. Join us for a career full of opportunities, where you can make a difference. **About the role**: You will participate in ambitious projects of a top US client in the Telecom industry as a Cloud Architect focused on governance,...
-
Senior Enterprise Risk Analyst
hace 4 semanas
Guadalajara, México Finastra A tiempo completo**Who are we?**:Finastra is recruiting for a **Senior Enterprise Risk Analyst**who will be responsible for all aspects of Risk Management and will evaluate, plan, and implement improvements in processes, practices, and organizational effectiveness across ERM.Finastra is a rapidly growing private equity owned company that has evolved through a combination of...