Job Description
The Security Analyst reflects the mission, vision, and values of NM, adheres to the organizations Code of Ethics and Corporate Compliance Program, and complies with all relevant policies, procedures, guidelines and all other regulatory and accreditation standards.
_ Responsibilities:_
Perform third party risk management including cybersecurity risk assessments to ensure third party partners meet NM requirements.
· Collaborate with third party partners and internal departments to ensure NM security requirements are being adhered to.
· Examine third party contracts to ensure the accuracy of cybersecurity language and provisions.
· Perform annual third party partner cybersecurity assessments and create accompanying reports and audits.
· Participate in HIPAA, PCI and security assessments.
· Analyze archectual diagrams and recommend security measures to safeguard valuable information assets including third party solution diagrams.
· Perform risk assessments on cloud services, applications, servers, mobile devices, medical devices and IT resources.
· Perform annul security policy reviews to keep policies up to date with the changing technologoies and services.
· Follow up with IS teams to ensure risk assessments are updated in the GRC tracking tool.
· Perform daily operational tasks required for the department to protect NM’s assets. Tasks range from (but are not limited to):
o Respond to daily security tickets / requests
o On call rotation
· AA/EOE.
COMPETENCIES / PERFORMANCE EXPECTATIONS
Third party risk management proficiency
·Famaliarity of HIPAA Security and Privacy Rules
·Understanding of cybersecurity contract language
·Security operations experience
PCI
QUA
Qualifications
_ Required:_
_ Preferred:_
Additional Information
Northwestern Medicine is an affirmative action/equal opportunity employer and does not discriminate in hiring or employment on the basis of age, sex, race, color, religion, national origin, gender identity, veteran status, disability, sexual orientation or any other protected status.