Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
CN
Care New England Health System
Senior Security Analyst
Career Insights for Cyber Security Manager / Administrator
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Rhode Island data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Manager or Administrator monitors, controls, and maintains systems that protect the security of large databases, including databases with customer information and patient files. Manages and administers the examination of client computer systems, identification of weak points in security, development and implementation of new systems, and monitoring and response to security issues.
$141,764 / year median in Rhode Island
+3% projected growth
Job Description
Senior Security Analyst Care New England Health System - 3.3 Warwick, RI Job Details Full-time $101,352 - $169,444 a year 12 hours ago Qualifications Vulnerability assessment PCI Security risk assessment investigation HIPAA Endpoint Detection and Response (EDR) Security data analysis Bachelor's degree Investigation evidence collection Healthcare privacy protection Log analysis tools Regulatory Frameworks (Architecture security) Vulnerability management Cross-functional collaboration Information security auditing Evidence collection Audit support
Full Job Description Job Summary:
As a member of the Information Security team, the Senior Security Analyst (GRC) is responsible for governance oversight, enterprise risk management, and compliance activities supporting the Care New England Health System. This role ensures security programs are aligned with regulatory requirements, industry standards, and organizational risk tolerance. Primary areas of responsibility include policy governance, enterprise risk register management, audit coordination, third-party risk oversight, security awareness program management, phishing simulation oversight, and governance-level performance monitoring of security controls and tools. The Senior Security Analyst does not perform direct engineering functions but provides oversight, performance validation, risk analysis, and executive-level reporting to ensure effective security control implementation and regulatory readiness.Duties & Responsibilities:
Develop, maintain, and manage lifecycle governance of enterprise security policies, standards, and procedures. Ensure alignment of administrative, technical, and physical controls with HIPAA and other regulatory frameworks. Support annual enterprise risk assessments and maintain required compliance documentation. Maintain and track the enterprise security risk register; coordinate remediation efforts with IT and business stakeholders. Serve as primary liaison for internal and external audits, coordinating evidence collection and corrective action plans. Support third-party risk reviews and Business Associate Agreement (BAA) evaluations. Oversee the security awareness and phishing simulation program; monitor user risk metrics and provide executive reporting. Monitor governance performance of key security tools (EDR, email security, vulnerability management, SIEM); review findings and validate remediation tracking. Support incident documentation, post-incident analysis, and governance-based corrective action tracking. Provide security governance consultation for IT initiatives and third-party engagements. Participate in professional development and maintain current industry knowledge. Perform other related duties as assigned.Requirements:
Education:
Bachelor's degree in Information Technology, Cybersecurity, Information Assurance, or related field required.Experience:
Minimum of five (5) to seven (7) years of IT and/or information security experience, including governance, risk, and compliance responsibilities. Experience in a highly regulated environment required; healthcare experience strongly preferred.Licenses:
N/A Certifications:
CISSP, CISM, IAM, or equivalent industry certification required.Knowledge, Skills, & Abilities:
Strong knowledge of HIPAA §§164.308, 164.310, and 164.312, HITECH, RI state data protection laws, and PCI DSS. Demonstrated experience managing governance frameworks and regulatory compliance initiatives. Strong analytical and problem-solving abilities. Ability to interpret technical security findings and translate them into business risk terms. Experience maintaining and tracking enterprise risk registers. Strong written and verbal communication skills with the ability to present to executive leadership. Ability to manage multiple priorities and adjust based on risk impact and regulatory deadlines. Familiarity with EDR, SIEM, vulnerability management, email security, and related platforms from a governance perspective. Ability to coordinate audit evidence collection and corrective action tracking. Strong collaboration skills across technical and non-technical teams.About Us:
Care New England Health System (CNE) and its member institutions, Butler Hospital, Women & Infants Hospital, Kent Hospital, VNA of Care New England, Integra, The Providence Center, and Care New England Medical Group, is a trusted, integrated health care organization that fuels the latest advances in medical research, attracts the nation's top specialty-trained doctors, hones renowned services and innovative programs, and engages in the important discussions people need to have about their health and end-of-life wishes. Care New England is helping to transform the future of health care, providing a leading voice in the ongoing effort to ensure the health of the individuals and communities we serve. : Americans withDisability Act Statement:
External and internal applicants, as well as position incumbents who become disabled must be able to perform the essential job-specific functions either unaided or with the assistance of a reasonable accommodation, to be determined by the organization on a case-by-case basis.EEOC Statement:
Care New England is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability statusEthics Statement:
Employee conducts himself/herself consistent with the ethical standards of the organization including, but not limited to hospital policy, mission, vision, and values.Benefits
- Professional Development
- Dental Insurance