Boston Medical Center (BMC) Logo

Boston Medical Center (BMC)

Senior Cybersecurity Analyst (GRC)

Reposted 12 Days Ago
Remote
Hiring Remotely in USA
90K-130K Annually
Senior level
Remote
Hiring Remotely in USA
90K-130K Annually
Senior level
Lead and mature the organization's GRC program by maintaining risk registers and control frameworks, driving compliance monitoring, coordinating third-party/vendor risk assessments, applying risk scoring and maturity tracking, managing GRC artifacts (Excel/SharePoint), translating findings for executives, and partnering with stakeholders to implement security policy and process improvements in a regulated healthcare environment.
The summary above was generated by AI

POSITION SUMMARY:

The Senior Cybersecurity Analyst (Governance, Risk, and Compliance) plays an important role in building and maturing Boston Medical Center Health System’s GRC program. This role will be key to developing and improving human-driven processes before enterprise tooling is in place, and will  make that work visible, auditable, and ready to scale.

Position: Senior Cybersecurity Analyst

Department: Information Security

Schedule: Full Time

ESSENTIAL RESPONSIBILITIES / DUTIES:

  • Lead execution of GRC program initiatives, contributing design input on processes, workflows, and work products as the program matures toward enterprise tooling adoption.

  • Maintain and operationalize risk registers, control frameworks, and maturity assessments aligned to NIST CSF 2.0, HIPAA/HITECH, and applicable federal and state security and privacy regulations.

  • Drive compliance monitoring activities and recommend updates to security policies, standards, and procedures that balance regulatory rigor with operational practicality.

  • Coordinate the third-party risk management process, including vendor risk assessments and ongoing vendor risk workflows.

  • Apply risk scoring methodologies to support framework maturity tracking and quantified risk metrics, incorporating business continuity and disaster recovery considerations.

  • Manage structured GRC work products in spreadsheet and document-based environments (e.g., Excel, SharePoint), keeping them accurate, accessible, and audit-ready on an ongoing basis.

  • Translate technical findings into clear, actionable written and verbal reporting for executive and non-technical audiences.

  • Partner with stakeholders across IT and non-IT business functions to advance new standards and workflows, influencing adoption without direct authority.

  • Prioritize multiple concurrent workstreams to deliver accurate results on schedule in a fast-paced, evolving environment.

(The above statements in this job description are intended to depict the general nature and level of work assigned to the employee(s) in this job. The above is not intended to represent an exhaustive list of accountable duties and responsibilities required)

JOB REQUIREMENTS

REQUIRED EDUCATION AND EXPERIENCE:

  • Bachelor's degree in Cybersecurity, Computer Science, Information Management, or a related field preferred

  • A minimum of six years of experience in information security or related discipline, with a strong focus on governance, risk, and compliance programs in complex or regulated environments.

  • Or equivalent combination of education and experience.

PREFERRED EDUCATION AND EXPERIENCE:

  • Demonstrated experience building or significantly maturing a GRC function, including the design of processes and workflows prior to enterprise tooling adoption.

CERTIFICATIONS, LICENSES, REGISTRATIONS PREFERRED:

  • Professional certifications such as CISA, CRISC, CISSP, or equivalent are highly desirable.

KNOWLEDGE, SKILLS & ABILITIES (KSAs):

  • Demonstrated experience in data mining, analysis and report development required.

  • Strong knowledge of information systems security concepts and current information security/privacy trends and practices.

  • Knowledge of Federal and State security and privacy-related regulatory requirements.

  • Excellent written and oral communication skills, interpersonal skills, and effective leadership skills to support privacy programs.

  • Must be able to prepare formal reports and presentations as needed.

  • Must be detailed oriented and possess the ability to prioritize tasks so work is completed in an accurate, timely manner.

  • Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management.

  • Self-starter with the ability to work independently, prioritize, multi-task, and maintain flexibility in fast-paced, changing environment.

  • Ability to confront conflict and difficult issues in a professional, assertive, and proactive manner.

  • Ability to build strong working relationships at all levels, internal and/or external to the organization.

  • Knowledge about medical records and other medical information, patient privacy and confidentiality, and release of information. Academic medical center and/or health care consulting experience preferred.

Compensation Range:

$89,500.00- $130,000.00

This range offers an estimate based on the minimum job qualifications. However, our approach to determining base pay is comprehensive, and a broad range of factors is considered when making an offer. This includes education, experience, skills, and certifications/licensures as they directly relate to position requirements; as well as business/organizational needs, internal equity, and market-competitiveness. In addition, BMCHS offers generous total compensation that includes, but is not limited to, benefits (medical, dental, vision, pharmacy), discretionary annual bonuses and merit increases, Flexible Spending Accounts, 403(b) savings matches, paid time off, career advancement opportunities, and resources to support employee and family well-being. 

NOTE: This range is based on Boston-area data, and is subject to modification based on geographic location.

Equal Opportunity Employer/Disabled/Veterans

According to the FTC, there has been a rise in employment offer scams. Our current job openings are listed on our website and applications are received only through our website. We do not ask or require downloads of any applications, or “apps” job offers are not extended over text messages or social media platforms. We do not ask individuals to purchase equipment for or prior to employment. 

Similar Jobs

11 Minutes Ago
Remote or Hybrid
United States
104K-130K Annually
Senior level
104K-130K Annually
Senior level
Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Own strategy and execution for DraftKings Exchange operations: manage day-to-day trading and market monitoring, lead incident resolution with Engineering, onboard and support participants, analyze market data to improve integrity and efficiency, and drive cross-functional initiatives to scale prediction market capabilities and regulatory readiness.
39 Minutes Ago
Remote or Hybrid
Texas, USA
146K-245K Annually
Senior level
146K-245K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead the strategic sales organization selling SailPoint's IGA SaaS to top accounts and partners in the region. Manage and coach sales teams, own pipeline, forecasting, hiring, and partner engagement. Build 12–36 month business plans, drive enablement milestones, and ensure rigorous sales processes to grow revenue and maintain pipeline coverage (3x quota).
Top Skills: Identity SecurityIgaSaaSSailpoint
2 Hours Ago
Remote or Hybrid
94K-197K Annually
Senior level
94K-197K Annually
Senior level
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Lead research and analysis for Coverage A (dwelling) product features, develop subject-matter expertise, run complex data analyses, manage cross-functional initiatives, synthesize insights into actionable product recommendations, present to leadership, and mentor junior analysts and interns.
Top Skills: EmblemExcelPowerPointSASSnowflake

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account