Security Compliance Analyst in ROCHESTER, New York at Rochester Regional Health
Explore Related Opportunities
Job Description
Description
Job Title: Security Compliance Analyst
Department: Information Security
Location: Remote, United States
Schedule: Days, Monday - Friday
SUMMARY
The Security Compliance Analyst at ACM Global Laboratories is responsible for the delivery of information security training and guiding various departments and personnel in the activities necessary to assure that the organization remains compliant with ISO-27001 certification standards and applicable international regulations.
RESPONSIBILITIES
Oversee rollout of cybersecurity awareness campaigns and required annual training and policy attestations.
Monitor the participation of the cybersecurity awareness campaigns, ensure compliance, and support content preparation aligned with company and regulatory requirements.
Conduct in-person staff training and promote security awareness to educate employees on security protocols to reduce human error.
Monitor user training completions and work with user's manager to assure completion in a timely manner.
Maintain data classification and data retention documentation.
Manage and communicate processes for data labeling.
Act on findings related to data mishandling as determined by DLP systems, with direct user interaction.
Work closely with business units and individuals to help them navigate the complexities of applying ISMS requirements.
Liaison with end users and department leads to implement risk remediations and security controls.
Assure the appropriate use of data in relation to data security.
Assure data masking is in use where practicable.
Assure that device, application, and data inventories remain updated.
Collects, documents, and files evidence that various security processes are functioning as intended.
Other duties as assigned.
REQUIRED QUALIFICATIONS
Minimum of 1 year experience in information security or a related field.
PREFERRED QUALIFICATIONS
Strong critical thinking skills.
Basic computer skills.
Strong written and verbal communication skills.
Strong ability to drive task and organizing/maintaining records.
Ability to think creatively and strategically.
Passion for learning new and emerging technology.
Technology education or certifications, experience with enterprise IT environments, experience working with security regulatory requirements, and knowledge of security frameworks such as NIST CFS, NIST 800-53, ISO, PCI-DSS a plus
PHYSICAL REQUIREMENTS: L - Light Work - Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly; requires occasional walking, standing or squatting.
PAY RANGE: $63,000.00 - $83,000.00
The listed base pay range is a good faith representation of current potential base pay for successful applicants. It may be modified in the future. Pay is determined by factors including experience, clinical licensure date, relevant qualifications, specialty, internal equity, location, and contracts.