Security Risk Management Analyst

  • CVS Health
  • Augusta, Maine
  • Full Time

at CVS Health in Augusta, Maine, United States

Job Description

At CVS Health, were building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.

As the nations leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.

Job Purpose and Summary:

Represent CVS Health information security practices via our client facing Information Security Client Assurance function. This role will provide extraordinary support to our clients and will navigate complex client security assurance relationship issues. You will do this by partnering with other technology teams, business account teams, legal & privacy. Delight our clients by providing Request For Information/Proposal ( RFI /P) responses, responding to client third party risk management questionnaires and updating our client facing security materials based on the latest industry trends. Leverage & maintain a current knowledge base for all information security policies, standards, procedures and practices to accurately represent CVS Healths information security posture.

Required Qualifications

+ 2-5 years of Security Audit Management, Third Party Risk Management or information security related experience

+ 2+ years experience working with common security frameworks and regulations, including but not limited to NIST 800-53, ISO 27001/2, HIPAA / HITECH , HITRUST and the PCI - DSS

Preferred Qualifications

Knowledge of:

+ Enterprise level Information security policies and procedures

+ Working knowledge of regulatory (including audit frameworks) standards, including but not limited to NIST 800-53, SOX , SOC1/SOC2 Type II audits, HIPAA / HITECH , HITRUST , and the PCI - DSS

+ Previous experience in a client facing security role, third party risk management or controls assurance function

+ Cloud Security Control frameworks a bonus

Skill in:

+ Control evaluation, audit, and testing

+ Understanding security schedule legal terminology

+ Technical control negotiations

+ Strong interpersonal and collaboration skills

+ Strong written and verbal communication skills

Ability To:

+ Ability to comprehend implications of security risk & technical control implementations

+ Worked independently

+ T

Job ID: 474069179
Originally Posted on: 4/20/2025

Want to find more Banking opportunities?

Check out the 40,223 verified Banking jobs on iHireBanking