Security Risk Assessor

Boston, MA, US • Posted 1 day ago • Updated 1 day ago
Contract W2
12 Months
No Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Security Risk Assessor
  • GRC
  • Security Risk Analyst
  • healthcare
  • HIPAA Security
  • NIST 800-53
  • NIST 800-30
  • IAM
  • PAM

Summary

Job description:
Security Risk Assessment & GRC
  • Experience performing architecture-focused risk assessments of critical-infrastructure and operationally significant environments.
  • 5+ Years of experience conducting enterprise IT security risk assessments, preferably within healthcare or other highly regulated environments.
  • Demonstrated ability to identify, analyze, quantify, and document cybersecurity risks across applications, infrastructure, clinical systems, and third-party environments.
  • Strong understanding of GRC processes, including risk registers, risk acceptance, remediation tracking, control assessments, exceptions, executive-level risk reporting.
Healthcare & Regulatory Risk Frameworks
    • Working knowledge of HIPAA Security Rule, HITECH, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-30, and relevant healthcare security practices.
    • Experience mapping security controls and assessment findings to regulatory, organizational, and contractual requirements.
Security Architecture
    • Strong understanding of enterprise architecture, including network segmentation, zero trust, IAM/PAM, encryption, endpoint security, vulnerability management, cloud security, logging/SIEM, and secure system design.
    • Ability to assess proposed and existing architectures against security requirements and identify architectural control gaps and compensating controls.
Threat, Vulnerability & Control Analysis
    • Ability to correlate threat scenarios, vulnerabilities, attack paths, business/critical impacts, existing controls, and residual risk to produce defensible risk determinations.
    • Experience evaluating technical evidence such as vulnerability assessments, penetration test results, architecture diagrams, configuration reviews, data flows, and security-control evidence.
Risk Treatment & Remediation
    • Demonstrated experience translating assessment findings into actionable remediation plans.
    • Ability to work with infrastructure, application, engineering, privacy, compliance, project, and business stakeholders to develop practical risk treatments.
Governance, Communication & Stakeholder Management
    • Strong written and verbal communication skills, with the ability to translate technical security and architecture issues into business risk for executives and risk owners.
    • Experience presenting assessment results, residual risks, exceptions, and remediation status to security leadership and key stakeholders.
 
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90607521
  • Position Id: 9095506
  • Posted 1 day ago
Contact the job poster
PR

Poorimetla Ravi Teja

Recruiter @ Swanktek Inc
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Massachusetts

•

Today

Easy Apply

Contract, Third Party

Quincy, Massachusetts

•

4d ago

Full-time

USD 120,000.00 - 202,500.00 per year

Quincy, Massachusetts

•

21d ago

Full-time

USD 90,000.00 - 157,500.00 per year

Boston, Massachusetts

•

5d ago

Full-time

USD 120,000.00 - 202,500.00 per year

Search all similar jobs