IT Specialty Analyst - Cybersecurity Risk
Job
Sentara Health
Norfolk, VA (In Person)
Full-Time
Review key factors to help you decide if the role fits your goals.
Pay Growth
?
out of 5
Not enough data
Not enough info to score pay or growth
Job Security
?
out of 5
Not enough data
Calculating job security score...
Total Score
74
out of 100
Average of individual scores
Skill Insights
Compare your current skills to what this opportunity needs—we'll show you what you already have and what could strengthen your application.
Job Description
IT Specialty Analyst - Cybersecurity Risk Sentara Health - 3.7 Norfolk, VA Job Details Full-time 1 day ago Qualifications Stakeholder engagement Achieving HIPAA compliance Procedural guides Technical documentation ISO standards Regulatory compliance HIPAA Security assessment Policy & process development System risk assessment (security system operation) NIST standards Risk management ServiceNow Cross-functional collaboration Cross-functional communication Stakeholder management Full Job Description Overview A highly motivated and experienced Cybersecurity Risk Analyst is sought with a strong background in assessing and managing cybersecurity risks at both the application and enterprise levels. The ideal candidate will be comfortable engaging with stakeholders across various business units, capable of independently guiding teams through risk rating and remediation processes and experienced in handling policy exceptions and drafting procedural documentation. Familiarity with platforms like ServiceNow for risk management and program building, and a solid understanding of regulations such as HIPAA—including experience with HIPAA Security Assessments or Health Industry Cybersecurity Practices (HICP) assessments—is preferred. Responsibilities Conduct comprehensive risk assessments across applications, systems, and enterprise-wide initiatives to identify potential threats, vulnerabilities, and their impact on confidentiality, integrity, and availability of data. Lead or support the execution of HIPAA Security Risk Assessments (SRA) and/or HICP assessments, including documenting findings, recommending corrective actions, and ensuring ongoing compliance. Independently conduct risk rating for issues using
ISO, COBIT, NIST
frameworks in partnership with other stakeholders. Additionally, guide and facilitate diverse business units in performing their own risk ratings to help them understand risk implications and remediation priorities. Collaborate with the stakeholders in developing and implementing risk mitigation strategies aligned with industry standards and best practices such asNIST, ISO
27001, and HIPAA. Utilize Governance, Risk, and Compliance (GRC) tools—specifically ServiceNow—to manage risk registers, track remediation plans, automate workflows, and generate reports on risk status and compliance metrics. Manage and oversee policy exception processes, including documentation, risk analysis, and tracking. Stay current with the evolving threat landscape, regulatory changes, and emerging cybersecurity technologies to proactively identify and address potential risks. Contribute to the continuous improvement of the organization's risk management program and cybersecurity posture. Draft clear and actionable procedure documents and other risk-related documentation to support policy implementation and operational consistency. Develop and deliver training and awareness programs to educate employees on cybersecurity risks, policies, and best practices. Participate in incident response activities, providing risk analysis and remediation support as needed. . Education Bachelor's Degree (Preferred) Experience in lieu of Bachelor's Degree - 5+ years of relevant experience without a degree Certification/Licensure No specific certification or licensure requirements Experience 3-5 years of experience in cybersecurity risk management, including performing risk assessments at both application and enterprise levels. Hands-on experience with GRC platforms, particularly ServiceNow, including modules related to risk, compliance, and policy management. Demonstrated expertise in conducting risk assessments and developing mitigation strategies aligned with HIPAA, NIST, andISO 27001.
Experience with HIPAA Security Risk Assessments and/or HICP assessments. Proven ability to work independently, manage multiple projects, and collaborate with cross-functional teams. Experience managing policy exceptions, including evaluating risks and ensuring proper documentation and approvals. Skilled in drafting procedures and operational documentation related to cybersecurity risk and compliance processes. Strong understanding of security principles, technical controls, and common attack vectors. Excellent communication, interpersonal, and presentation skills with the ability to effectively engage technical and non-technical stakeholders across all levels. Strong analytical, problem-solving, and critical thinking abilities.Similar remote jobs
Wells Fargo
Chandler, AZ
Posted2 days ago
Updated4 hours ago
Similar jobs in Norfolk, VA
Virginia Zoological Society
Norfolk, VA
Posted2 days ago
Updated4 hours ago
Compass Group, North America
Norfolk, VA
Posted2 days ago
Updated4 hours ago
Websters Rural
Norfolk, VA
Posted2 days ago
Updated4 hours ago
Similar jobs in Virginia
DNI Delaware Nation Industries
Alexandria, VA
Posted2 days ago
Updated4 hours ago
Virginia Zoological Society
Norfolk, VA
Posted2 days ago
Updated4 hours ago