×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Compliance Analyst

Job in West Des Moines, Polk County, Iowa, 50265, USA
Listing for: Yourcaptive
Full Time position
Listed on 2026-07-17
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 70000 - 100000 USD Yearly USD 70000.00 100000.00 YEAR
Job Description & How to Apply Below
## Information Security Compliance Analyst Apply locations:
West Des Moinestime type:
Full time posted on:
Posted Yesterday job requisition :
R0000885
*
* Job Description:

** We are looking to add an
** Information Security Compliance Analyst II
** to join our
** Information Security
** team in
** West Des Moines, Iowa**. Offering a forward-thinking, innovative, and vibrant company culture, along with the opportunity to share your unique potential, there really is no place like Holmes!
*
* Essential Responsibilities:

** The purpose of this position is to support the information security program, including initiatives related to strategy, policies, standards, risk management, awareness, and training. This role will also support the enhancement of the Enterprise’s overall governance program.
*
* Essential Responsibilities:

*** Conduct comprehensive risk assessments and provide detailed reports on findings and required mitigations.
* Lead the development and maintenance of policies, ensuring they address regulatory requirements.
* Oversee implementation of risk mitigation controls, risk management, and conduct follow-up audits.
* Manage vendor risk assessments, working with third parties to address any gaps.
* Review contractual agreements against compliance standards and in alignment with HMA contractual requirements
** Additional Responsibilities:
*** Develop and present compliance metrics and reports to senior management and auditors.
* Mentor junior analysts and oversee documentation quality.
* Take the lead on special compliance projects, ensuring alignment with strategic goals.
* Assist with the annual SOC2 audit and other audits or assessments as appropriate.
*
* Knowledge, Skills and Abilities:

*** Strong understanding and application of privacy policies, compliance standards and regulations such as NIST, HIPAA, NYDFS or GLBA.
* Solid knowledge of GRC tools such as Apptega, Archer, etc.
* Broad technical knowledge of network, cloud, and application security.
* Ability to conduct internal and external risk assessments and identify various types of risks, such as operational, cybersecurity, regulatory, and reputational risks, and recognize the implications of these risks on the organization.
* Proficient with mapping and analyzing workflows to identify points of inefficiency, risk, or non-compliance.
* Strong understanding of SDLC and experience in compliance integration.
* Ability to analyze complex issues and implement effective solutions.
* Experience using automation tools within the work environment.
* Ability and willingness to consistently participate in internal and external educational opportunities to enhance knowledge of current insurance topics or relevant system improvements.
* Ability to be available for work on a daily basis and extended hours as necessary.
* Ability and willingness to consistently participate in internal and external educational opportunities to enhance knowledge of current insurance topics or relevant system improvements.
* Ability and willingness to pursue relevant designations and/or continuing education, as appropriate.
* Ability to apply common sense understanding to carry out instructions furnished in written, oral or diagram form. Ability to deal with problems involving several concrete variables in standardized situations.
* Ability to exert up to 10 pounds of force occasionally, and/or negligible amount of force frequently or constantly to lift, carry, push, or pull objects.
* Must be knowledgeable of and comply with HMA's Client Privacy Policy, HIPAA regulations and E&O procedures and policies.
*
* Qualifications:

**
* Education:

Associate’s or Bachelor’s degree in cybersecurity, technology, information systems, or related area or an equivalent combination of education, training, and experience.

* Experience:

3-5 years of relevant experience in Information Security, compliance, governance, or other security-related fields. Relevant certifications preferred.
* Ability and willingness to pursue relevant designations and/or continuing education, as appropriate.
* Core Competencies*
* ** Trust:
** Build trust through honest and caring actions and consistently do the right thing.
* ** Communication:
**…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary