JOB SUMMARY:
Baylor Genetics is seeking a dedicated Governance, Risk and Compliance Security Analyst to lead the organization's efforts in maintaining and enhancing our security compliance programs. This role involves establishing and managing the SOC 2/HITRUST/ISO compliance program, conducting security assessments, and ensuring adherence to industry standards and regulatory requirements. The ideal candidate will be responsible for identifying and mitigating security risks, coordinating with stakeholders to provide compliance evidence, and guiding the organization in implementing cybersecurity frameworks.
Additionally, this position requires the establishment of a vendor assessment program, promoting security awareness within the organization, and staying informed about emerging security threats and technologies. The GRC Security Analyst will play a critical role in safeguarding our information systems and ensuring our security practices are aligned with best practices and regulatory expectations.
MAJOR RESPONSIBILITIES:
- Develop and maintain organizational compliance programs (e.g. SOC 2/HITRUST/ISO 27001).
- Participate in security assessments and audits and ensure timely responses to inquiries.
- Perform assessments and gap analysis to identify and evaluate security risks and threats.
- Coordinate with internal and external stakeholders to provide evidence of security compliance.
- Conduct periodic reviews of security policies, procedures, standards, and guidelines and ensure alignment with regulatory requirements and industry best practices.
- Establish a third-party vendor assessment program to evaluate vendors to comply with company security requirements.
- Maintain compliance with cybersecurity frameworks in areas where applicable (e.g. NIST, CIS, and HIPAA).
- Promote a culture of security awareness across the organization.
- Stay up-to-date with the latest security threats, trends, and technologies.
REQUIRED JOB QUALIFICATIONS:
Education:
- Bachelor’s degree in cybersecurity or computer information systems.
- Minimum of 5 years of related work experience.
- Relevant industry certifications such as CISA or similar.
Experience:
- Responding to client/customer security inquiries.
- Strong familiarity with industry frameworks such as SOC, ISO, HITRUST, NIST, and FDA part 11.
- Working knowledge of common audit and compliance tools.
- Demonstrable knowledge in the assessment of third-party vendors.
- Communication and interpersonal skills, with the ability to collaborate effectively with diverse teams.