Senior Manager - Security GRC

About Providence

Providence, one of the US’s largest not-for-profit healthcare systems, is committed to high quality, compassionate healthcare for all. Driven by the belief that health is a human right and the vision, ‘Health for a better world’, Providence and its 121,000 caregivers strive to provide everyone access to affordable quality care and services.

Providence has a network of 51 hospitals, 1,000+ care clinics, senior services, supportive housing, and other health and educational services in the US.

Providence India is bringing to fruition the transformational shift of the healthcare ecosystem to Health 2.0. The India center will have focused efforts around healthcare technology and innovation, and play a vital role in driving digital transformation of health systems for improved patient outcomes and experiences, caregiver efficiency, and running the business of Providence at scale.


Why Us?

  • Best In-class Benefits
  • Inclusive Leadership
  • Reimagining Healthcare
  • Competitive Pay
  • Supportive Reporting Relation

Senior Manager-Security GRC – CYBR|GRC

  • Cyber Security is committed to appropriately protecting all information relating to its caregivers and affiliates, as well as protecting its confidential business information (including information relating to its caregivers, affiliates, and patients).

     

    What will you be responsible for?

  • Develop, implement, and support improvement of organization's information security Governance, Risk and Compliance management strategy.
  • Design and implement a coordinated Risk Management approach that applies operating controls to manage information security risks.
  • Develop policies, procedures, processes, standards, and guidelines for the IT Governance Program. This will include development of an Internal Controls framework and control lifecycle management.
  • Assist with driving Risk Management and Governance strategies for emerging technology areas.
  • Address information security related issues and findings, ensuring that remedial actions as well as long term solutions are performed to mitigate the underlying risks.
  • Collaborate with stakeholders (e. g. Senior Leadership, Strategic Business Units, IT, Legal) to ensure a consistent process for identifying, assessing, responding and reporting on IT risks.
  • Provide and support the implementation of IT GRC initiatives globally.
  • Influence decisions in partnership with program leadership to ensure work toward common objectives.
  • Lead proactively to identify projects & collaborate with multiple pillars to enhance standardization, efficiency & maturity of GRC function.
  • Provide responsive leadership to delegate, coordinate, and motivate staff; evaluate performance for direct reports and for contractors/other peoples’ direct reports; work with individuals and HR to improve performance as needed.
  • Assume responsibility for GRC teams of up to 10 caregivers.
  • Maintain updated knowledge in the field of Risk Management and Compliance to efficiently work on frameworks including NIST CSF, CIS Controls, GDPR, SOX 404, ITIL, etc.
  • Remain current with industry best practices and monitor the legal and regulatory environment for developments.

What would your work week look like?

  • Regularly collaborate with business leaders, application, and product owners to evaluate security needs and impacts of security decisions on business processes as well as to communicate risks.
  • Drive implementation of framework, policies, standards, and other security requirements.
  • Conduct gap analysis and implement Standards Frameworks like ISO 27001, Privacy, GDPR, NIST CSF, HIPAA, PCIDSS, SOX etc.
  • Develop and revise Policies, Standards, Processes, and guidelines for the enterprise through change management.
  • Complete security reviews, attestations requested by regulatory/business partners.
  • Perform security reviews, attestations, assessments and serve as a Liaison between various teams within Cybersecurity.
  • E2E implementation of Integrated control framework program.
  • Prioritize work, delegate tasks and effectively address difficult situations.
  • Manage expectations and effectively communicate to colleagues, project team members, sponsors, stakeholders, business leaders, as well as internal and external security stakeholders and leaders.
  • Promote and raise awareness of Cyber-Security programs and posture, driving change and influencing proper Cyber Security hygiene within the organization.

 

Who are we looking for?

  • 4-year University (Bachelor’s) degree in Computer Science, Information Security, Cyber Security or related field.
  • Minimum 10 years of experience in an Information Security/GRC role.
  • Minimum 5 years of experience in IT Risk Management Role.
  • Preferred 3 years of experience in Healthcare, Pharma or Bio-Technology organization.
  • Preferred people management experience.
  • Strong project management skills to simultaneously work on multiple projects concurrently.
  • Experience with managing a GRC tool support life cycle.
  • Strong written and oral communication skills with the ability to explain technical ideas to non-technical individuals at any level.
  • Adaptable to shifting priorities, demands, and timelines through analytical and problem-solving capabilities. Able to react to project adjustments and alterations promptly and efficiently.
  • Ability to lead a team and collaborate with other leaders throughout the organization.
  • Ability to effectively prioritize and execute tasks in a high-pressure environment.

Preferred knowledge of Information Security standards (ISO/IEC 27001, 27002, NIST CSF, NIST SP 800-53, CIS Controls).

Providence’s vision to create ‘Health for a Better World’ aids us to provide a fair and equitable workplace for all in our employment, whether temporary, part-time or full time, and to promote individuality and diversity of thought and background, and acknowledge its role in the organization’s success. This makes us committed towards equal employment opportunities, regardless of race, religion or belief, color, ancestry, disability, marital status, gender, sexual orientation, age, nationality, ethnic origin, pregnancy, or related needs, mental or sensory disability, HIV Status, or any other category protected by applicable law. In furtherance to our mission in building a more inclusive and equitable environment, we shall, from time to time, undertake programs to assist, uplift and empower underrepresented groups including but not limited to Women, PWD (Persons with Disabilities), LGTBQ+ (Lesbian, Gay, Transgender, Bisexual or Queer), Veterans and others. We strive to address all forms of discrimination or harassment and provide a safe and confidential process to report any misconduct.

Contact our Integrity hotline also, read our Code of Conduct.