HealthPartners Logo

HealthPartners

Senior IT Risk and Compliance Analyst

Reposted 7 Hours Ago
In-Office or Remote
Hiring Remotely in United States
Senior level
In-Office or Remote
Hiring Remotely in United States
Senior level
The Senior IT Risk and Compliance Analyst manages vendor risk, ensures compliance with regulations, documents controls, and supports risk mitigation efforts across IT teams.
The summary above was generated by AI

HealthPartners is currently hiring a Senior IT Risk and Compliance Analyst. The Senior Analyst plays a key role in coordinating vendor risk and compliance activities, including interpreting and responding to compliance, third‑party, and audit evidence requests. While this position will have a primary focus on either Compliance or Risk Management as part of daily responsibilities, the individual is expected to support work across the full spectrum of Risk and Compliance Management.

In partnership with IT. teams across HealthPartners, the Senior Analyst ensures that appropriate evidence is available for control validation, controls are accurately documented, risk mitigation plans are actively managed, and IT risks are effectively identified and assessed. This role is critical to maintaining HealthPartners’ high standards for IT risk management and regulatory compliance and requires the ability to navigate complex regulatory frameworks while delivering thoughtful, strategic insights.

The ideal candidate brings a strong technical foundation in IT risk assessment, hands-on experience with ServiceNow IRM, and the ability to collaborate across teams to support enterprise-wide risk and compliance objectives.

Required Qualifications:

  • Bachelor’s degree or equivalent experience and knowledge
  • Five (5) years of work experience in information systems including a high degree of knowledge regarding technical infrastructure, systems, applications, and development and project methodologies.
  • One (1) year of system auditing experience
  • Certification in at least one related area of audit, governance, security, or service management by an accredited organization within six months of hire.
  • Understanding basic audits and the controls necessary for those audits (e.g., SSAE16, AT101, Enterprise Risk Assessments, Sarbanes Oxley, etc.)
  • Understanding of audit and security standards, e.g., CoBit, NIST, ISO27001, ISO27002, etc.
  • Strong understanding of Risk Management Practices, industry standards, and utilization
  • Strong understanding of controls and adequate evidence capture for controls.
  • Understanding of federal and state security related legislation including HIPAA, Joint Commission, and Sarbanes‑Oxley.
  • Proven experience coordinating and disseminating activities, responses, documentation, and meetings.
  • Effective communication skills; verbal and written on technical and non-technical topics.
  • Experience presenting concepts and training.
  • Strong people skills; consistent service orientation and delivery for internal and external customers
  • Analysis and problem-solving experience.
  • Understanding of Project Management, Software Development Lifecycles, Capacity, Availability, and Service Management
  • Understanding of Information Technology architectures, infrastructure components, and networks

Preferred Qualifications:

  • ITIL Foundations Certification
  • CISA Certification

Hours/Location:

  • M-F; core business hours
  • This is a hybrid position that is primarily remote, with occasional on‑site requirements for team meetings and collaborative work.

Responsibilities:

  • Addresses questions about evidence, interprets audit and third-party requests, and ensures the appropriate submission of evidence.
  • Documents, updates, and maintains the IT Control database.
  • Assists in the development of IT Controls.
  • Communications compliance and risk status ensuring timely delivery of compliance and risk deliverables.
  • Recommends remediation methods for audit deficiencies, tracking observation remediation through completion.
  • Partners within IT for the coordination and management of risk mitigation plans.
  • Documents and manages the risk repository and library; ensuring risk assessments meet IT defined standards and requirements.
  • Ensures risk policy, procedures and assessments are reviewed and updated timely.
  • Partners within IT Risk and Compliance to assess and document risks; assists business and/or IT owners with risk decisions and selecting mitigating activities.
  • Assists with IT Compliance Strategy development with an integrated approach to audit, risk, and security.
  • Maintains spot audit program, managing mitigations and control deficiencies.
  • Gathers, documents, and published security, risk, and compliance metrics.
  • Drafts policies, procedures, and standards in partnership with IT Management and leaders; ensuring policies are reviewed timely and up to date.
  • Facilitates business and IT risk mitigation and audit remediation decisions, providing options, cost/benefit analysis, and impact analysis for recommended solutions.
  • Proposes audit observation and remediation activities.
  • Maintains the Governance, Risk, and Compliance tools to support IT Risk and Compliance Service Delivery.
  • Provides compliance and risk management awareness, integrating compliance and risk into HealthPartners workforce daily activities.
  • Maintains awareness of the latest developments in the areas of system audits, industry standards (e.g., CoBit, ISACA Standards, ITIL, etc.), and regulatory and standard changes (e.g., HIPAA, PCI Standards, etc.).

Similar Jobs

31 Minutes Ago
Remote or Hybrid
199K-348K Annually
Expert/Leader
199K-348K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead and deliver large, cross-functional technical programs for APEX Strategic Programs. Translate business strategy into execution, design governance, drive accountability, implement scalable processes, and use AI tools to synthesize intelligence, surface risks, and accelerate delivery while engaging senior stakeholders and ensuring smooth handoffs to operations.
Top Skills: AIAi AgentsAi ToolsEnterprise SoftwareSaaSServicenowWorkflow Automation
32 Minutes Ago
Remote or Hybrid
167K-291K Annually
Senior level
167K-291K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead the Software Asset Management engineering team, set technical direction, manage product development and release cycles, drive AI/ML and telemetry initiatives, improve test automation and performance, mentor engineers, coordinate cross-functional and global teams, and ensure scalable, high-quality enterprise solutions with 24x7 support alignment.
Top Skills: AgileAIAutomation FrameworksC++JavaJavaScriptMachine LearningOpen Source ToolsPerformance TestingRubyShellTelemetryTest Automation
32 Minutes Ago
Remote or Hybrid
166K-290K Annually
Senior level
166K-290K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Lead product marketing for ServiceNow's telecommunications portfolio: craft messaging, drive releases and sales enablement, support deals with positioning and competitive insight, and embed AI-first workflows for scalable content and research.
Top Skills: Ai ToolsBssOssServicenow

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account