Engineer III - Cybersecurity Risk Analyst
About the role
Overview:
What you can expect!
Find joy in serving others with IEHP! We welcome you to join us in “healing and inspiring the human spirit” and to pivot from a “job” opportunity to an authentic experience!
The Cybersecurity Risk Analyst is a cybersecurity program and control assessor and advisor in governance, risk, and compliance functions. This position is responsible for the assessing and advancing of IEHP’s cybersecurity posture and capability to safeguard its digital assets.
The purpose of this position is to provide highly skilled technical and cyber expertise for development and implementation of the enterprise information security program. Responsibilities require leadership and project management experience, as well as expertise to ensure effective system-wide security capability analysis; best practices and assurance testing; risk assessment; awareness and education; and development of security control portfolio.
Commitment to Quality: The IEHP Team is committed to incorporate IEHP’s Quality Program goals including, but not limited to, HEDIS, CAHPS, and NCQA Accreditation.
Additional Benefits:
Perks
IEHP is not only committed to healing and inspiring the human spirit of our Members, but we also aim to match our team members with the same energy by providing prime benefits and more.
Competitive salary
State of the art fitness center on-site
Medical Insurance with Dental and Vision
Life, short-term, and long-term disability options
Career advancement opportunities and professional development
Wellness programs that promote a healthy work-life balance
Flexible Spending Account – Health Care/Childcare
CalPERS retirement
457(b) option with a contribution match
Paid life insurance for employees
Pet care insurance
Key Responsibilities:
Lead the system-wide cybersecurity compliance program, ensuring IT activities, processes, and procedures meet regulatory and industrial requirements.
Develop and implement effective policies and practices to safeguard IEHP digital assets and prevent unauthorized access.
Recommend process improvement and technical directions in matters relating to program maturity, incident investigation, threat management, and control assessment.
Organize the collection of data from required security artifacts and questionnaires for industry framework and other related industrial and cybersecurity standards and mapping this to the company control portfolio.
Build and maintain cybersecurity metrics for all levels of management focused on trending and tracking reports to demonstrate compliance and improve resilience.
Analyze risk associated with technology stack and supply chain and work with business leaders to proactively manage exceptions.
Develop program strategies to improve cyber hygiene and address awareness and training for all stakeholders.
Perform security review in technology products and solutions (including security tools and systems), identify gaps in control design and operation, and develop remediation plan.
Provide advice and input for IT disaster recovery, contingency, and continuity of operations plans.
Define policy and standards for data protection and recovery.
Perform access & privilege review for both machine and human accounts.
Properly document all systems security implementation, operations, and maintenance activities and update as necessary.
Provide input to risk management process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
Qualifications:
Education & Requirements
Five (5) years in cybersecurity with focus on governance, compliance and risk management
Bachelor’s degree in Information Systems Security or in a computer related field or similar technical field from an accredited institution required
Certified Information Systems Security Professional (CISSP) or other industrial and vendor security certifications preferred
Key Qualifications
Knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy
Skilled in Cybersecurity, privacy principles and organizational requirements
Ability to apply cybersecurity and privacy principles to IEHP business and technical requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
Start your journey towards a thriving future with IEHP and apply TODAY!
Work Model Location:
This position is on a hybrid work schedule. (Mon & Fri - remote, Tues - Thurs onsite in Rancho Cucamonga, CA.)
Pay Range: USD $135,200.00 - USD $179,129.60 /Yr.
Compensation
This Risk Analyst role pays $135k-$179k/yr. Within typical range for risk analyst roles in United States.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.