Cybersecurity GRC Analyst
Listed on 2026-07-27
-
IT/Tech
Cybersecurity, Information Security & Data Protection
ESSENTIAL DUTIES AND RESPONSIBILITIES
- Conducts and facilitates internal and external audits against established compliance requirements and frameworks (e.g. HIPAA, Security Operations Center (SOC) 2, National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF)
- Assesses third-party vendors for security risks prior to and during business relationships
- Maintains internal risk register and tracks corrective action plans
- Performs targeted cybersecurity risk assessments to identify vulnerabilities, misconfigurations, and compliance deviations
- Conducts phishing attack simulations across the organization
- Coordinates between Information Technology (IT), Privacy, Legal and Compliance to enforce governance objectives
- Develops and maintains corporate security policies, procedures and standards aligned with business objectives
- Provides oversight for Disaster Recovery/Business Continuity programs
- Creates, updates and maintains cybersecurity metrics and awareness training materials
- Promotes awareness and understanding of security policies across the organization
Bachelor's degree in Computer Science, Information Security, Business Administration or related field
Preferred- 3+ years experience in IT compliance, internal auditing or cybersecurity risk management
- Prefer experience in a healthcare or other highly regulated industry with direct exposure to HIPAA compliance requirements
- Exposure to Identity and Access Management programs
- Exposure to Vulnerability Management programs
N/A
Preferred- Certified Information Systems Auditor (CISA)
- Certified Information Systems Security Professional (CISSP)
SKILLS AND ABILITIES
Technical Skills
- Audit experience using HIPAA, Health Information Trust Alliance (HITRUST), NIST or similar frameworks
- Experience with Governance, Risk and Compliance/ Integrated Risk Management (GRC/IRM) platforms (e.g. Apptega, Archer, Service Now)
- Experience with email security platforms (e.g. Knowbe4, Proofpoint Zen)
- Familiarity with vulnerability scanners and SOC solutions (Security Information and Event Management/Security Orchestration, Automation, and Response (SIEM/SOAR)
- Familiarity with cloud environments (e.g. Azure, Amazon Web Services (AWS)
- Excellent Microsoft Word, Excel and PowerPoint skills
- Strong communication skills, both written and verbal.
- Ability to follow instructions and procedures accurately.
- Demonstrated problem-solving and critical-thinking abilities.
- Ability to work independently and as part of a team.
- Commitment to maintaining confidentiality and ethical standards.
- Adaptability to changing priorities and environments.
- Customer service orientation and cultural sensitivity.
$85,657.09 - $
Mercyhealth is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identify, national origin, disability, or protected veteran status.
Mercyhealth offers competitive pay and a comprehensive benefits package including:
- Medical, Dental, Vision
- Life & Disability Insurance
- FSA/HSA Options
- Generous, accruing paid time off
- Paid Parental and caregiver leave
- Career advancement and educational opportunities
- Tuition and certification reimbursement
- Certification Reimbursement
- Well-being Programs
- Employee Discounts
- On-Demand Pay
- Financial Education
- Annual recognition/awards events
- Partner appreciation days
- Family entertainment/attractions discount
- Community service/improvement opportunities
At Mercyhealth, we don't simply hire people, we empower employee-partners who are passionate about making lives better. As an integrated health system, we deliver exceptional, coordinated across seven hospitals, 85 primary and specialty clinics, and a team of over 7,500 professionals serving northern Illinois and southern Wisconsin.
Mercyhealth has been nationally recognized for our commitment to our people and culture, including:
- #1 in the nation on AARP's Best Employers for Workers Over 50
- One of Working Mother magazine's 100 Best Companies for Working Mothers
- A Top 50 Company and Top 10 Nonprofit for Executive Women
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).