Home   >   Careers   >   Opening


Senior Risk and Compliance Analyst

TRAVEL REQUIREMENT: No travel required
<p><strong>Overview:</strong> &nbsp;The Senior Risk and Compliance Analyst is internal to Inovalon and part of the Security, Risk and Compliance department that partners with Technology, business groups, and project teams to perform risk and compliance activities and audits for applications, infrastructure, and vendor/third parties.</p> <p>In addition, this position supports enterprise security, risk, and compliance initiatives that improve Inovalon’s security posture, management control systems, liaises with the company's external audit firms, and helps foster an appreciation for a strong control environment across the organization. The candidate must be able to build working relationships and drive change with various levels of management on an enterprise scale and be able to articulate how assessment results translate to business risk for the organization.</p> <p>&nbsp;</p> <p><strong>Duties and Responsibilities:</strong></p> <ul> <li>Lead, plan and manage the execution and delivery of risk-based IT assessment and compliance reviews, which may include IT general control, IT application control, IT infrastructure, and IT operational process reviews, IT governance &amp; strategy design assessments, and SOX compliance related activities;</li> </ul> <ul> <li>Lead the preparation and coordination of third-party audits and assessments, including client on-site visits, third party security/risk questionnaires and desktop reviews as well as in the preparation of regulatory external audits such as SSAE 16/18, HITRUST, PCI and Sarbanes-Oxley<strong>;</strong></li> </ul> <ul> <li>Capture and refine IT compliance and risk requirements and ensure that the requirements are integrated into Inovalon products and information systems through purposeful security architecting, design, development, and configuration;</li> <li>Prepare deliverables, reports, for review by the Risk and Compliance management and senior leadership that include issues, trends and other micro/macro level risks identified through the execution of IT internal control work and other assurance-related activities;</li> <li>Support Inovalon's HITRUST Enterprise Implementation Program;</li> <li>Contribute "best practices" in terms of findings, checklists, templates, testing methods, and techniques to support and advance the Technology Compliance Program;</li> <li>Serve as a trusted advisor and consultant between various groups such as Technology, Finance, and Operations;</li> </ul> <ul> <li>Support our department response to prospective client Request for Proposal (RFP), client inquiries and control assessments, and other third-party inquiries;</li> </ul> <ul> <li>Serve as a security, risk, and compliance consultant and expert to help enterprise wide project and tiger teams drive the effectiveness of our security and privacy programs;</li> <li>Ensure compliance with Inovalon’s IT policies and procedures, applicable laws and regulations, and keep current on compliance-related areas;</li> <li>Maintain compliance with Inovalon’s policies, procedures and mission statement;</li> <li>Adhere to all confidentiality and HIPAA requirements as outlined within Inovalon’s Operating Policies and Procedures in all ways and at all times with respect to any aspect of the data handled or services rendered in the undertaking of the position; and</li> <li>Fulfill those responsibilities and/or duties that may be reasonably provided by Inovalon for the purpose of achieving operational and financial success of Employer.</li> </ul> <p>&nbsp;</p> <p><strong>Job Requirements:</strong></p> <ul> <li>Minimum of five years of relevant experience working within the areas of: Internal Audit, Technology Governance, Risk Assurance, and/or Internal Controls. Health-care&nbsp;industry experience is a plus;</li> </ul> <ul> <li>In-depth experience with key regulations and standards such as HITRUST, HIPAA, NIST 800-53, NIST Cyber-Security Framework, Sarbanes-Oxley, and other compliance requirements;</li> <li>Articulate communicator, demonstrating mastery of both spoken and written English, with the ability to tailor deliverables appropriately for audiences ranging from technical to senior executive;</li> <li>Strong critical thinking skills; ability to quickly comprehend problems, develop hypotheses, draw logical conclusions, develop solutions, and respond accordingly;</li> <li>A self-starter: pro-actively&nbsp;identifying problems, determining pragmatic solutions, identifying and obtaining needed resources, and executing with little or no supervision;</li> <li>Demonstrated hands-on approach and success in working in a team-based environment and to partner with others to promote an environment of teamwork;</li> <li>Proven ability to manage multiple projects and work-streams concurrently and successfully; and</li> <li>In-depth understanding of core information technology processes and controls.</li> </ul> <p>&nbsp;</p> <p><strong>Education:</strong></p> <ul> <li>Bachelor’s degree (Master’s degree preferred) in Business or IT studies; and</li> <li>Security/Audit-related certifications preferred, such as: CISA, CISSP, CRISC.</li> </ul> <p>&nbsp;</p> <p><strong>Physical Demands and Work Environment:</strong></p> <ul> <li>Sedentary work (i.e. sitting for long periods of time);</li> <li>Exerting up to 10 pounds of force occasionally and/or negligible amount of force;</li> <li>Frequently or constantly to lift, carry push, pull or otherwise move objects and repetitive motions;</li> <li>Subject to inside environmental conditions; and</li> <li>Travel for this position will include less than 5% locally usually for training purposes.</li> </ul>

Apply for this Position

© 2021 Inovalon. All rights reserved.