Healthcare Security Analyst

Overview

Remote
Depends on Experience
Accepts corp to corp applications
Contract - Independent
Contract - W2
Contract - 12 Month(s)
No Travel Required

Skills

Healthcare Security Analyst
NIST RA
AC
SC
IR
FAIR
HIPAA
HITRUST CSF certification
Health Exchange
Risk Assessment
Risk Management
SAS Display Manager
NIST SP 800 Series
Intellectual Property
International Relations
Microsoft Exchange
Health Care
IP
ISO 9000
IT Risk Management
Incident Management
Privacy
RTR
Regulatory Affairs
Regulatory Compliance
Software Engineering
Information Retrieval
Information Security
Information Security Governance
Cyber Security
Dashboard
Dialog Manager
Dimensional Modeling
Access Control
Affinity Propagation
Augmented Reality
Collaboration
Communication
Documentation
Investor Relations

Job Details

Job ID: NC-762829

Remote/Local Healthcare Security Analyst with NIST RA/AC/SC/IR, FAIR, HIPAA, HITRUST CSF certification, and Health Exchange experience

Location: Raleigh, NC (NCDIT)
Duration: 12 Months
Position: 2(2)

Skills:
Experience in IT risk management, cybersecurity, or information security assessment. Highly desired 5 Years
Demonstrated knowledge of NIST SP 800-30, NIST SP 800-53 Rev. 5, and NIST Privacy Framework. Highly desired 5 Years
Experience performing security and privacy risk assessments with documentation aligned to federal and state standards. Highly desired 5 Years
Familiarity with HIPAA Security and Privacy Rules, and healthcare-specific risk domains. Highly desired 5 Years
Experience with HITRUST CSF alignment or certification preparation. Highly desired 5 Years
Strong written and verbal communication skills for technical and executive audiences. Highly desired 5 Years

Description:
This engagement ensures compliance with industry-standard frameworks, supports proactive risk mitigation, & positions NC HIEA for future HITRUST certification.Plan and conduct NC HIEA s annual enterprise security risk assessment using NIST SP 800-30, ISO 27005, or FAIR methodologies.
2. Ensure full alignment with NIST SP 800-53 Revision 5, including: RA (Risk Assessment), AC (Access Control), SC (System Communications Protection), IR (Incident Response), and more.
3. Incorporate NIST Privacy Framework and NIST SP 800-53 Rev. 5 privacy control families (AP, AR, DI, DM, IP, SE, TR, UL).
4. Build and maintain a comprehensive risk register, with treatment plans for mitigation, transfer, acceptance, or avoidance.
5. Map risks and mitigation efforts to HITRUST CSF control domains to support future certification
6. Develop and deliver documentation, dashboards, and executive summaries.
7. Collaborate with internal stakeholders to validate findings and support security governance efforts.

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.