🌎
This job posting isn't available in all website languages

Information Security Risk Analyst (GRC) - Hybrid (PA/NJ/DE)

📁
Information Technology
📅
260187 Requisition #

IBX is seeking an experienced Information Security Risk Analyst to be the primary owner of cybersecurity risk assessments and our enterprise cyber risk register. You’ll collaborate with ISOGRC and Security Operations to identify, assess, and monitor risks; map them to controls; design and execute regular effectiveness testing; and provide clear, actionable reporting on our risk posture to leadership. You will also drive the project risk assessment process end-to-end, working closely with the Project Management Office to keep initiatives moving while ensuring risks are mitigated and documented.

This role is ideal for someone who thrives in a hands-on environment, can independently run a cyber risk management platform, and is comfortable partnering across audit, third-party risk, and security operations in a regulated healthcare environment.

What You’ll Do

  • Own Project Risk Assessments: Intake project requests from the PMO, facilitate stakeholder meetings, perform risk analysis, document findings, recommend mitigations, and publish deliverables (risk assessment report, control requirements, sign-offs) to enable go/no-go decisions.
  • Build & Manage the Risk Register: Establish and maintain an enterprise cyber risk register in LogicGate—define risk taxonomy, scoring methodology, control mapping, and treatment plans; track status and residual risk over time.
  • Controls Testing & Assurance: Coordinate and perform control effectiveness reviews, define test plans/criteria, and report test results; partner with SecOps to implement corrective actions and continuous improvement.
  • Risk Reporting & Governance: Produce dashboards and executive-level reporting on risk posture, trends, key risk indicators (KRIs), and control performance; prepare materials for governance forums and leadership briefings.
  • Cross-Functional Collaboration: Work with Audit (SOC 2, HITRUST, external audits), Third-Party Risk (annual vendor assessments), Privileged Access Certification (bi-annual), and Access/Data Monitoring teams to ensure risk linkage and consistent control coverage.
  • Methodology & Process Maturity: Define and refine risk assessment procedures, SLAs, and templates; contribute to NIST CSF maturity assessments and HIPAA Security Risk Assessments; support remediation tracking and verification.

Qualifications:

Required

  • 1-3 years in cybersecurity risk management or information security with direct experience performing project/initiative risk assessments and managing risk registers.
  • Strong knowledge of IT and security controls (identity/access, privileged access, change/configuration, vulnerability management, endpoint/network security, logging/monitoring, incident response).
  • Hands-on experience with a GRC or risk management platform (e.g., LogicGate, Archer, OneTrust, ServiceNow GRC) including workflow design, risk scoring, and reporting.
  • Familiarity with healthcare and regulated environments; practical understanding of frameworks and standards such as NIST CSF, HIPAA Security Rule, HITRUST, and SOC 2.
  • Proven ability to translate technical risk into business-impact narratives and clear mitigation plans; excellent writing and stakeholder facilitation skills.
  • Ability to operate independently, set priorities, and move multiple assessments to completion in a fast-paced environment.

Preferred

  • Experience implementing LogicGate (risk taxonomy, controls library, workflows, dashboards).
  • Exposure to third-party security risk assessments and integration of vendor risks into enterprise risk register.
  • Experience with privileged access governance/certification and evidence collection.
  • Certifications: CRISC, CISSP, CISM, CGEIT, HITRUST, CCSK (or equivalent).
  • Experience with control testing and audit readiness (SOC 2/HITRUST) and developing KRIs/KPIs.

Hybrid

Independence has implemented a “Hybrid” model which consists of Associates working in the office 3 days a week (Tuesday, Wednesday & Thursday) and remotely 2 days a week (Monday & Friday). This role is designated as a role that fits into the “Hybrid” model. While associates may work remotely on our designated remote days, the work must be performed in the Tri-State Area of Delaware, New Jersey or Pennsylvania.

 

 

IBX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to their age, race, color, religion, sex, national origin, sexual orientation, protected veteran status, or disability.

 

Must have an Android or iOS device which is compatible with the free Microsoft Authenticator app.

Inclusion and Belonging

At IBX, everyone can feel valued, supported, and comfortable to be themselves, and all associates have a fair opportunity to achieve their full potential.  We put these principles into action every day by acting with integrity and respect.  Celebrating and embracing diverse thoughts and perspectives that make up our workforce means our company is more vibrant, innovative, and better able to support the people and communities we serve.

About Our Company

Serving more than 8 million people nationwide, including 2.5 million in southeastern Pennsylvania, Independence Health Group — together with its subsidiaries — is the leading health insurance organization in the Philadelphia region. Our mission to build healthier lives for you, your family, and your employees shapes our actions and decisions every day.

 

At Independence, we see each of our members as an individual, with unique needs and concerns. We’re dedicated to harnessing the very latest ideas and technologies to deliver access to care that meets those needs and surpasses your expectations.  For more information about Independence access our website at www.ibx.com. We’re revolutionizing health care, and our focus is on you!

 

Equal Employment Opportunity

IBX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to their age, race, color, religion, sex, national origin, sexual orientation, protected veteran status, or disability.

 

Agency Disclaimer

All resumes submitted directly to an Independence Blue Cross employee from a vendor via email, the Internet or in any other form without a valid written search agreement in place for this position from the Independence Blue Cross Family of Companies Human Resources Department will be deemed the sole property of Independence Blue Cross and the Independence Blue Cross Family of Companies. Please note that no fee will be paid in the event the candidate is hired by Independence Blue Cross or the Independence Blue Cross Family of Companies as a result of the referral or through means other than our established process. 

Current Associates

Applying for a position? Click here to return to the internal career site.

Current Associates

My Profile

Create and manage profiles for future opportunities, and review prior submissions.

Go to Profile

Similar Listings

Philadelphia, Pennsylvania

📁 Information Technology

Philadelphia, Pennsylvania

📁 Information Technology

Philadelphia, Pennsylvania

📁 Information Technology

IBX is dedicated to safeguarding what matters most to you. Please protect yourself by staying vigilant against phishing scams involving fake IBX job postings and individuals posing as IBX representatives offering fraudulent job opportunities. What you should know:
• IBX will never request payment of any kind in connection with the hiring or onboarding process.
• IBX will never ask for sensitive personal information, such as your Social Security Number, over the phone or via email.
• Our recruitment process requires job applicants to apply directly through the official application on this site.