Principal Risk Analyst: Privacy-Third-Party Risk Management
Listed on 2026-08-05
-
Security
Information Security & Data Protection, Cybersecurity
Principal Risk Analyst
City:
Rochester
State: MN
Remote: NO
Department:
Information Security
Why Mayo Clinic:
Mayo Clinic is top-ranked in more specialties than any other care provider according to U.S. News & World Report. As we work together to put the needs of the patient first, we are also dedicated to our employees, investing in competitive compensation and comprehensive benefit plans – to take care of you and your family, now and in the future.
And with continuing education and advancement opportunities at every turn, you can build a long, successful career with Mayo Clinic. Benefits Highlights:
- Medical:
Multiple plan options. - Dental:
Delta Dental or reimbursement account for flexible coverage. - Vision:
Affordable plan with national network. - Pre-Tax Savings: HSA and FSAs for eligible expenses.
- Retirement:
Competitive retirement package to secure your future.
Responsibilities:
The Principal Risk Analyst will lead risk business operations, special projects, investigations, legal litigation, mitigation development, non-employee access and end user awareness/education. Incumbent will provide guidance to the RD unit for day-to-day operational support, including project management. Incumbent will demonstrate leadership and represent the RD on project teams, committees, strike teams and work groups.
Job Duties and Responsibilities:
Supports and develops RD initiatives. Responsible for the design of enterprise business operations, including operational growth and development. Leads multi-disciplinary work groups and projects. Responsible for development of policies and procedures to support the organization's risk tolerance. Gathers and organizes information from a cross-functional investigative team. Works directly with Legal and Human Resources on high risk internal and external investigations. Works directly with Legal and External Counsel on policy, regulatory and/or litigation matters (using eDiscovery protocols).
Completes documentation to support findings including legal reports, SBARs, and executive summaries. Responsible for peer review of work unit documentation. Develops and presents Risk training(s) geared towards Mayo Clinic leadership. Has extensive experience in regulatory compliance and investigations that includes:
• Deep subject matter expertise in relevant compliance laws and regulations such as privacy compliance, investigations, revenue cycle compliance, device manufacturing compliance, general compliance, conflict of interest;
• Understanding of and ability to apply the Seven Elements of an Effective Compliance Program;
• Ability to carry out audits, assessments and investigations; and
• Ability to use relevant compliance tools including GRC software, monitoring tools, and issue management software, Ability to follow and apply legal holds and execute proper preservation of evidence and chain of custody protocols. Depending on role this may include the ability to follow proper computer forensic evidence handling, advanced knowledge of data preservation, acquisition of computing and storage devices either fixed or mobile and more technical forensic investigations.
Must have technical and nontechnical communication skills (verbal and written), analytical aptitude and project management skills. Demonstrates high level integrity and ability to use discretion and maintain confidential information. Other functions and projects as assigned. Some travel may be required to other Mayo Clinic sites and/or training conferences. Mayo Clinic will not sponsor or transfer visas for this position including F1 OPT STEM.
Qualifications:
Bachelor's degree and 7 years' experience in business analysis, compliance, privacy, insider threat, information security, human resources, risk management, information science, business administration, law enforcement, health or science-related fields OR Master's degree and 5 years' experience in business analysis, compliance, privacy, insider threat, information security, human resources, risk management, information science, business administration, law enforcement, health or science-related fields. Masters of Healthcare Administration, Business Administration, or…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).