Join PatientPoint to be part of a dynamic team committed to empower better health. As a leading digital health company, we innovate to positively impact patient behaviors. Our purpose-driven approach offers an inspirational career opportunity where you can contribute to improving health outcomes for millions of patients nationwide.
Location: Cincinnati OR Remote
Travel Requirements: Less than 10%
Job Summary
PatientPoint is seeking a highly skilled Cybersecurity Analyst to own our Risk Management and Compliance (GRC) programs. This mission-critical role will involve performing IT risk assessments, managing risk register items, overseeing the lifecycle of risk acceptances and policy exceptions, and supporting third-party/vendor risk management. The ideal candidate will play a pivotal role in enhancing our GRC processes, ensuring adherence to security frameworks, and protecting PatientPoint’s information technology environment.
What You’ll Do
Risk Management:
- Perform IT risk assessments and audits, articulating technical risks in terms of business impact.
- Identify critical risks and issues, develop contingency plans, and escalate unresolved matters to senior management.
- Manage risk register items by assigning ownership, tracking progress, and driving remediation efforts.
- Manage the lifecycle of all risk acceptances and policy exceptions.
- Facilitate planning, execution, and reporting of risk assessments and audits to support compliance with security frameworks (CIS, HIPAA, NIST, ISO).
Compliance and GRC Program Management:
- Assist in the day-to-day management of the IT GRC program, identifying opportunities for improvement in existing processes and controls.
- Build and manage GRC frameworks and processes.
- Develop vendor assessment standards and processes for third-party technology vendors.
Incident Response:
- Participate in cybersecurity incident response activities.
- Assess the impact of incidents and initiate appropriate remediation measures.
Audits and Assessments:
- Conduct internal and external audits and assessments to verify adherence to security controls.
- Participate in compliance-related initiatives for HIPAA, NIST, ISO, and similar standards.
- Generate regular reports on the organization’s risk posture and security status.
- Present findings and recommendations to management and stakeholders.
What We Need
- 3+ years of professional experience in information technology.
- 1+ years in an IT security role with oversight of GRC processes.
- Strong, practical experience working in a HIPAA environment.
- Hands-on experience with the implementation and management of security frameworks such as ISO 27001, NIST, or CSF.
- Experience with Agile Project Management methodologies.
- Proficiency with ticketing systems such as JIRA or ServiceNow.
- Familiarity with conducting Business Impact Assessments.
Desired Qualifications
- Knowledge of GDPR, CCPA, VCDPA, or related privacy laws.
- Security certifications such as CISA, CIA, CISSP, CISM, CEH, or GISP.
- Experience with GRC tools like LogicGate, Lockpath, or OneTrust.
What You'll Need to Succeed
- Strong analytical and problem-solving skills.
- Excellent communication and presentation abilities.
- Proven ability to collaborate effectively across teams and manage multiple priorities.
About PatientPoint:
PatientPoint is a leading digital health company that connects patients, healthcare providers and life sciences companies with the right information in the moments care decisions are made. Our solutions are proven to influence patient behavior and improve health outcomes, driving value for all stakeholders. Across the nation’s largest network of connected digital devices in 35,000 physician offices, PatientPoint solutions empower better health for more than 750 million patient visits each year.
Latest News & Innovations:
- Named A Best Place to Work Across Multiple Prestigious Platforms! Read More
- Featured on Built In's article "Companies That Pay Well". Read More
- Now Culture Content Certified by VentureFizz. Read More
What We Offer:
We know you bring your whole self to work every day, and we are committed to supporting our full-time teammates with a comprehensive range of modernized benefits and cultural perks. We offer competitive compensation, flexible time off to recharge, hybrid work options, mental and emotional wellness resources, a 401K plan, and more. While these benefits are available to full-time team members, we strive to create a positive and supportive environment for all teammates.
PatientPoint recognizes that privacy is important to you. Please read the PatientPoint privacy policy, we want you to be familiar with how we may collect, use, and disclose your information. Employer is EOE/M/F/D/V
Top Skills
Similar Jobs at PatientPoint
What you need to know about the Charlotte Tech Scene
Key Facts About Charlotte Tech
- Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
- Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
- Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
- Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
- Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus