Senior Information Security Analyst in Signant Health

FULL_TIME

  Remote (Chile) | Senior | Full time | Cybersecurity

3 applications
Last checked today
Apply now
Requires applying in English

Are you ready for the Most Impactful Work of Your Life?
Signant Health is a global evidence generation company. We’re helping our customers digitally enable their clinical trial programs, meeting patients where they are, driving change through technology and innovations and reimagining the path to proof.

­­­­­­­­­­­­Where do you fit in?
The Senior Information Security Compliance Analyst assists the Chief Information Security Officer in the execution of all assurance activities related to the availability, integrity and confidentiality of customer, business partner, employee, and business information in compliance with the organization's information security policies.

Job functions

As part of our team, your main responsibilities will be:

1. Assist the CISO in the development, implementation, and monitoring of enterprise information security program. Ensure policies and SOPs are written, approved, published, and kept up to date.

2. Serve as program lead for enterprise Information Security certification programs:

  • ISO 27001
  • SSAE-18 SOC2
  • HIPAA/HITRUST
  • Etc.

3. Serve as program lead for the following programs:

  • Enterprise Information Security Awareness program:
    1. Develop Biannual Global Information Security Awareness Trainings.
    2. Administer Biannual Phishing Simulation Campaigns.
    3. Develop and deliver role/function-specific security awareness training, as needed.
  • Enterprise Business Continuity Program:
    1. Create, update, and disseminate Enterprise Business Continuity Program Governance materials.
    2. Work with internal departments on the creation and testing of Departmental Business Continuity Plans
    3. Develop and execute necessary internal and external Business Continuity Alerting and Coordination activities.
  • Information Security Vendor Management Program:
    1. Implement and maintain Vendor Management Tracking
    2. Coordinate with the internal Procurement team on new vendor assessments, which include:
      1. Implementing, maintaining, and executing online vendor assessment questionnaires when needed.
      2. Obtaining and reviewing relevant vendor security attestations and other relevant information security materials
      3. Creating and disseminating the necessary assessment summary documentation.
    3. Ensure vendor periodic reassessments occurred within pre-defined timeframe

4. Serve as main POC for organization on Information Security assurance business-as-usual and customer audit activities. This includes, but is not limited to the following:

  • Completion of vendor/RFI(P) information security assessments.
  • Developing applicable Memos-To-File (MTFs) for sign-off by the Chief Information Security Officer
  • Representing Information Security in customer audits (both on-site and remote)

Qualifications and requirements

You’ll need to bring:

  1. Degree in business administration, project management, or a technology-related field required.
  2. Professional security management certification (preferred)
  3. Minimum of 3-5 years of experience in a combination of risk management, information security and IT jobs
  4. Experience in developing and administering the following:
    • Information Security Compliance Programs.
      • SSAE-18 SOC2
      • ISO 27001
    • Information Security Risk Assessment/Audit program.
    • Information Security Awareness Program
  5. Experience in writing Policies, Standard Operating Procedures, Working Instruction, etc.
  6. Excellent written and verbal communication skills and high level of personal integrity.
  7. Ability to function independently with minimal supervisory input.

Desirable skills

We’d be thrilled to hear that you also have:

  1. Experience in administering the following programs:
    • Enterprise Business Continuity Program
    • Information Security Vendor Assessment Program
  2. Experience with the development and administration of Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs).
  3. Prior participation in Customer Audits
  4. Information Security or IT Risk Management/Audit certification
  5. Ability to lead and motivate cross-functional, interdisciplinary teams.

Conditions

Computer provided Signant Health provides a computer for your work.
Informal dress code No dress code is enforced.

Remote work policy

Locally remote only

Position is 100% remote, but candidates must reside in Chile.

  1. Jobs
  2. Cybersecurity
  3. Signant Health
  4. Senior Information Security Analyst
Senior Information Security Analyst
Signant Health •   Remote (Chile)
Apply
Requires applying in English
Share this job Share