IS Security GRC Analyst Job at Brown University Health, Providence, RI

YWtYNW5KR1RTNytGOUtuRVllcTJOZ2twRnc9PQ==
  • Brown University Health
  • Providence, RI

Job Description

SUMMARY:

The IS Security Governance, Risk & Compliance (GRC) Analyst is a critical member of the Chief Information Security Officer's (CISO's) team and reports to the Director of Information Security. The IS Security GRC Analyst plays a pivotal role in the Information Security team, driving the development and implementation of the organization’s security governance framework. This position is responsible for creating and managing security metrics, facilitating exception requests, conducting vendor security risk assessments, and maintaining key documentation such as information security policies and the risk register. The role ensures that the healthcare organization maintains compliance with regulatory requirements, industry standards, and internal policies while proactively managing security risks.

PRINCIPAL DUTIES AND RESPONSIBILITIES:

Brown University Health employees are expected to successfully role model the organization’s values of Compassion, Accountability, Respect, and Excellence as these guide our everyday actions with patients, customers and one another.

Develop, review, and update information security policies, procedures, and standards to reflect best practices, regulatory requirements, and evolving threats. Monitor regulatory changes and industry trends to ensure ongoing compliance and policy relevance. Maintain crosswalks between organization policies and regulatory standards.

Assist in ensuring compliance with relevant regulatory standards, including HIPAA, HITECH, PCI-DSS, NIST, and other applicable frameworks.

Design and implement metrics to measure the effectiveness of the information security program, including incident trends, security stack deployment, and risk levels. Develop dashboards and reports for senior management, detailing the status of the information security program and highlighting areas for improvement. Continuously refine metrics to provide meaningful insights into the organization’s security posture.

Facilitate the process for security policy exceptions, including reviewing requests, meeting with business owners, assessing risk, and documenting approvals. Ensure that exception requests are properly tracked, periodically reviewed, and managed according to organizational policies.

Conduct and/or oversee vendor security risk assessments, evaluating third-party practices for alignment with the organization’s security requirements. Monitor and reassess vendor risks regularly to account for changes in services, technology, or vendor practices.

Identify opportunities for improvement in governance, risk, and compliance practices, recommending updates to processes and controls. Stay current with emerging security risks, regulatory requirements, and best practices to ensure the ongoing effectiveness of the GRC program.

Provides expert level guidance to IT staff and the business regarding all Information Security policies, standards, processes, and procedures.

Works with various infrastructure teams and business units to ensure policy compliance and adherence to security best practices.

Participates in security projects and provides expert guidance on security policy, process, and procedures for other IT projects.

Attends various IT meetings that require an IS Security representative.

Participates in compliance / audit activities as requested by internal and external auditors.

Supports Brown University Health’s Legal e-discovery processes to include identification, collection, preservation and processing of relevant data.

Manages Governance, Risk and Compliance platform.

Maintains work effort status within SLA’s on Brown University Health’s Service Desk and Task Management Platforms.

Performs other duties as assigned.

EXPERIENCE:

A minimum of 10 years of IS experience, with 5 years in an information security role.

A bachelor's degree in information systems or equivalent work experience; an M.B.A. or M.S. in information security is preferred.

Certifications Required (3 or more – Security+, CCSP, CISA, CISM, CRISC, CISSP, GIAC, Network+, ITIL, Project+)

Strong understanding of regulatory requirements, security frameworks, and risk management methodologies (e.g., HIPAA, HITECH, NIST, ISO 27001).

Experience with security metrics development, policy management, vendor risk assessments, and risk register maintenance.

Excellent written and verbal communication skills, with the ability to present complex security concepts to diverse audiences.

Working knowledge of IT/network and cloud architectures sufficient to map controls, evidence, and risks.

Proficiency with O365; advanced Excel and Power BI for dashboards; Visio for process & control maps.

Strong written and verbal communication skills.

Ability to communicate security guidance to a non-technical audience.

Experience in developing, documenting, and maintaining security policies, processes, procedures, and standards.

INDEPENDENT ACTION:

Functions independently within departmental policies and practices. Must be able to work independently in a manner to achieve goals, objectives and productivity requirements. Refers unresolved complex issues to director where clarification of department policies and procedures may be required.

SUPERVISORY RESPONSIBILITIES:

None.

Pay Range:

$113,519.22-$187,305.66

EEO Statement:

Brown University Health is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, ethnicity, sexual orientation, ancestry, genetics, gender identity or expression, disability, protected veteran, or marital status. Brown University Health is a VEVRAA Federal Contractor.

Location:

BHCS 15 LaSalle Square - 15 LaSalle Square Providence, Rhode Island 02903

Work Type:

M-F 8:00am-4:30pm

Work Shift:

Day

Daily Hours:  

8 hours

Driving Required:

Yes

Job Tags

Full time, For contractors, Work experience placement, Shift work,

Similar Jobs

Paragon Architecture

Architectural Project Administrator Job at Paragon Architecture

 ...ADMINISTRATOR POSITION: Paragon Architecture is looking for an entry-level team member with 0-1 years of experience to assist Project...  ...architectural process. This full-time position requires a bachelors degree in architecture, licensure not required. REQUIREMENTS:... 

QPS Employment Group

Assembler - 1st Job at QPS Employment Group

 ...Position Title: Assembler Wage: $17.27 - $20.00/hour Shift: 1st, 2nd or 3rd Hours: 6:00am - 2:30pm, 2:30pm - 12:00am or 10:00pm - 6:00am Looking to work for a manufacturing company that cares about you? Join a great team with a leading manufacturer in Mayville... 

Unifi Aviation, LLC

Airport Wheelchair Agent (AA) - STL Job at Unifi Aviation, LLC

 ...General information Job Title Airport Wheelchair Agent (AA) - STL Date Monday, October 20, 2025 Entity...  ...Summary: Responsible for providing wheelchair assistance to international passengers requiring assistance at the airport at all stages... 

SynergisticIT

Junior/Entry Level Data Engineer Job at SynergisticIT

Synergisticit Job Opportunity Since 2010 Synergisticit has helped jobseekers get employed in the tech job market by providing candidates the requisite skills, experience and technical competence to outperform at interviews and at clients. Here at SynergisticIT we just...

Health Advocates Network - Allied

Travel CVOR First Assist Job at Health Advocates Network - Allied

 ...Job Description Health Advocates Network - Allied is seeking a travel CVOR First Assist for a travel job in Atlanta, Georgia. Job Description & Requirements ~ Specialty: CVOR First Assist ~ Discipline: Allied Health Professional ~ Start Date: 02/16/2026...