Senior Security Analyst

Care New England Health System
  • Warwick, Rhode Island
  • Full-time
4 days ago

Job Description

Job Summary:

 

 

As a member of the Information Security team, the Senior Security Analyst (GRC) is responsible for governance oversight, enterprise risk management, and compliance activities supporting the Care New England Health System.

 

This role ensures security programs are aligned with regulatory requirements, industry standards, and organizational risk tolerance. Primary areas of responsibility include policy governance, enterprise risk register management, audit coordination, third-party risk oversight, security awareness program management, phishing simulation oversight, and governance-level performance monitoring of security controls and tools.

 

The Senior Security Analyst does not perform direct engineering functions but provides oversight, performance validation, risk analysis, and executive-level reporting to ensure effective security control implementation and regulatory readiness.

 

 

 

 

 

 

Duties & Responsibilities:
  • Develop, maintain, and manage lifecycle governance of enterprise security policies, standards, and procedures.
  • Ensure alignment of administrative, technical, and physical controls with HIPAA and other regulatory frameworks.
  • Support annual enterprise risk assessments and maintain required compliance documentation.
  • Maintain and track the enterprise security risk register; coordinate remediation efforts with IT and business stakeholders.
  • Serve as primary liaison for internal and external audits, coordinating evidence collection and corrective action plans.
  • Support third-party risk reviews and Business Associate Agreement (BAA) evaluations.
  • Oversee the security awareness and phishing simulation program; monitor user risk metrics and provide executive reporting.
  • Monitor governance performance of key security tools (EDR, email security, vulnerability management, SIEM); review findings and validate remediation tracking.
  • Support incident documentation, post-incident analysis, and governance-based corrective action tracking.
  • Provide security governance consultation for IT initiatives and third-party engagements.
  • Participate in professional development and maintain current industry knowledge.
  • Perform other related duties as assigned.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Requirements:

Education:

Bachelor’s degree in Information Technology, Cybersecurity, Information Assurance, or related field required.

 

Experience:

Minimum of five (5) to seven (7) years of IT and/or information security experience, including governance, risk, and compliance responsibilities. Experience in a highly regulated environment required; healthcare experience strongly preferred.

Licenses:N/A

 

Certifications:CISSP, CISM, IAM, or equivalent industry certification required.

 

Knowledge, Skills, & Abilities:

Strong knowledge of HIPAA §§164.308, 164.310, and 164.312, HITECH, RI state data protection laws, and PCI DSS.

Demonstrated experience managing governance frameworks and regulatory compliance initiatives.

Strong analytical and problem-solving abilities.

Ability to interpret technical security findings and translate them into business risk terms.

Experience maintaining and tracking enterprise risk registers.

Strong written and verbal communication skills with the ability to present to executive leadership.

Ability to manage multiple priorities and adjust based on risk impact and regulatory deadlines.

Familiarity with EDR, SIEM, vulnerability management, email security, and related platforms from a governance perspective.

Ability to coordinate audit evidence collection and corrective action tracking.

Strong collaboration skills across technical and non-technical teams.

 

 

 

About Us:

Care New England Health System (CNE) and its member institutions, Butler Hospital, Women & Infants Hospital, Kent Hospital, VNA of Care New England, Integra, The Providence Center, and Care New England Medical Group, is a trusted, integrated health care organization that fuels the latest advances in medical research, attracts the nation’s top specialty-trained doctors, hones renowned services and innovative programs, and engages in the important discussions people need to have about their health and end-of-life wishes. Care New England is helping to transform the future of health care, providing a leading voice in the ongoing effort to ensure the health of the individuals and communities we serve.

:

Americans with Disability Act Statement: External and internal applicants, as well as position incumbents who become disabled must be able to perform the essential job-specific functions either unaided or with the assistance of a reasonable accommodation, to be determined by the organization on a case-by-case basis.

 

EEOC Statement: Care New England is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status

 

Ethics Statement: Employee conducts himself/herself consistent with the ethical standards of the organization including, but not limited to hospital policy, mission, vision, and values.

Numbers & Facts

LocationWarwick, Rhode Island
Job TypeFull-time

Skills

  • Americans with Disabilities Act (ADA)unmatched
  • Analysis Skillsunmatched
  • Auditingunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Corrective Actionunmatched
  • Documentationunmatched
  • Email Securityunmatched
  • Enterprise Protectionunmatched
  • Establish Prioritiesunmatched
  • External Auditunmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Healthcareunmatched
  • Hospitalunmatched
  • IT Governanceunmatched
  • Industry Standardsunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology Consultingunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Medical Researchunmatched
  • Metricsunmatched
  • Multitaskingunmatched
  • Organizational Skillsunmatched
  • PCI-DSSunmatched
  • Performance Analysisunmatched
  • Phishingunmatched
  • Policy Implementationunmatched
  • Presentation/Verbal Skillsunmatched
  • Problem Solving Skillsunmatched
  • Product Lifecycleunmatched
  • Project/Program Managementunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Reporting Skillsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Simulationunmatched
  • State Laws and Regulationsunmatched
  • Support Documentationunmatched
  • Team Playerunmatched
  • Time Managementunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder