IT Security Risk Management Analyst (Policy Reviewer & Policy Writer)- SOC or ISO or NIST + Audit
Job description
Company Description At EVERSANA, we are proud to be certified as a Great Place to Work across the globe. We’re fueled by our vision to create a healthier world. How? Our global team of more than 7,000 employees is committed to creating and delivering next-generation commercialization services to the life sciences industry. We are grounded in our cultural beliefs and serve more than 650 clients ranging from innovative biotech start-ups to established pharmaceutical companies. Our products, services and solutions help bring innovative therapies to market and support the patients who depend on them. Our jobs, skills and talents are unique, but together we make an impact every day. Join us!  Across our growing organization, we embrace diversity in backgrounds and experiences. Improving patient lives around the world is a priority, and we need people from all backgrounds and swaths of life to help build the future of the healthcare and the life sciences industry. We believe our people make all the difference in cultivating an inclusive culture that embraces our cultural beliefs.  We are deliberate and self-reflective about the kind of team and culture we are building. We look for team members that are not only strong in their own aptitudes but also who care deeply about EVERSANA, our people, clients and most importantly, the patients we serve.   We are EVERSANA.   THE POSITION: The IT Security Risk Management Analyst is a key contributor to EVERSANA’s IT Risk & Compliance team, placed within EVERSANA’s Information Security service line.  This person will be responsible for performing security focused evaluations of governance, risk, and compliance of EVERSANA’s Information Assets.  This rewarding position will also help with the continued development and operations of several IT governance and compliance activities. These are oriented towards objectively evaluating security control performance across the enterprise, and alignment of security controls with business objectives.  Further, this role will assist other team members on the IT Risk & Compliance team, and EVERSANA’s Security Operations team to evaluate risks, threats, and opportunities for mitigation strategies in support of sound security practices. Critical RESPONSIBILITIES: Business Partner Support –   40% Support internal business partners with information and responses in requests from EVERSANA clients exploring security and general IT capabilities. Perform security focused assessments on EVERSANA’s third party suppliers and vendors to assess potential risks and communicate impacts to IT and business leaders. Perform security focused assessments on EVERSANA’s clients to assess potential risks and communicate impacts to IT and business leaders.   Policy Governance and Review- 10% Review, analyze, and maintain Information Security policies, standards, procedures, and guidelines to ensure alignment with business objectives, regulatory requirements, and industry best practices. Conduct periodic reviews of existing security policies and recommend updates based on changes in regulations, emerging threats, technology implementations, and organizational requirements. Coordinate policy review cycles with stakeholders, control owners, and business leaders to ensure timely approval and implementation of policy updates. Evaluate policy exceptions and deviations, assess associated risks, and provide recommendations for risk treatment and management approval. Policy Development and Writing- 10% Draft, develop, and maintain Information Security policies, standards, procedures, and supporting documentation in accordance with frameworks such as ISO 27001, NIST, HIPAA, and applicable regulatory requirements. Collaborate with technical and business stakeholders to translate security, compliance, and operational requirements into clear and actionable policy documentation. Ensure policy documentation is written in a consistent format, understandable to both technical and non-technical audiences, and supports organizational compliance objectives. Monitor changes in regulatory, legal, and industry requirements and update policy documentation to address evolving compliance obligations.                                                                                Risk Management Operations – 10%     Support and perform various risk assessment processes to develop threat models for various EVERSANA business lines, as well as improving awareness of financial and operational impacts identified risks posed to EVERSANA. Develop, review, and maintain Information Security policies, standards, and procedures to ensure alignment with organizational risk management objectives, regulatory requirements, and industry best practices, while facilitating stakeholder review, approval, and compliance monitoring. Security Control Audit Support – 30% Monitor and facilitate audit activities for SOC 1, SOC 2, HIPAA risk assessments, and follow up activities of remediation for issues / findings identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place. Monitor and facilitate audit remediation activities identified during client or vendor assessments to ensure deficiencies are mitigated and proper controls are put in place. Work with IT Risk & Compliance team members to identify security controls applicable to various service lines. Support the draft and creation of reporting to senior leadership. Conduct periodic internal testing and auditing to support security control compliance. Support internal and external audits by providing policy documentation, evidence of policy reviews, approval records, and demonstrating compliance with applicable security frameworks and regulatory requirements. Four or more years of experience in an auditing role (Information Technology OR Compliance) OR two or more years of experience with risk management practices. Two or more years of experience with third party risk assessments. Experience in creating summary reports for a broad range of audiences, including senior leadership. Competent understanding of auditing practices (ex. SOC1 or SOC2, ISO27000) Understanding of Security Standards like ISO27001, PCI DSS, HIPAA, NIST 800-53 Experience with risk management methodology’s (quantitative assessments, FAIR, HIPAA security assessment) and their utilization. Excellent analytical, project management, and problem-solving skills Experience in drafting, reviewing, and maintaining Information Security policies, standards, procedures, and governance documentation. Strong understanding of policy lifecycle management, document governance, and regulatory compliance requirements. Excellent technical writing, documentation management, and stakeholder communication skills. Preferred qualifications: B.Tech/BE  Experience required- 2-5 Industry Certification such as CISA, CIA, CRISC, TPCRA, ISO 27000 Internal Auditor, or Open FAIR   All your information will be kept confidential according to EEO guidelines. Our team is aware of recent fraudulent job offers in the m
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar pharma jobs
Specialty Representative - University of Central Florida - United States Field Worker
Amgen — US - Florida - Orlando
Senior Manufacturing Systems Engineer: Building Automation Systems (BAS)
Amgen — US - North Carolina - Holly Springs
Senior Manufacturing Systems Engineer: Automation PLC
Amgen — US - North Carolina - Holly Springs
Adminstrative Coordinator
Amgen — US - California - Thousand Oaks
Senior Engineer (NPI & Glam)
Amgen — Singapore Manufacturing - Tuas
Biopharmaceutical Rep–Prolia–Guiyang
Amgen — China - Guiyang