$ cat jobs/sr-engineer-governance-risk-compliance-tprm-nextgen-healthcare-666451ecafd0.json
Sr. Engineer, Governance, Risk & Compliance (TPRM)
Job Description: The Sr. Security Engineer will develop solutions leveraging tools and technology. The ideal candidate is one who has a security engineering background with experience in both cybersecurity and information security. Develop solutions using tools and technology to support Information Security and GRC work, project, and initiatives. Act as system administrator for certain security or GRC tools such as phishing and training platform, Data Loss Prevention (DLP) solution, Third Party Risk Management (TPRM) platform, Risk Register, privacy management, etc. Integrate related tools with other systems as needed. Engage with security vendors on design sessions, and help configure GRC solutions for use. Work with IT partners in Application Security, Security Engineering and Operations, Enterprise Applications, Desktop Support, Help Desk, Networking and Infrastructure Operations, to get data and information needed to support GRC work. Work with IT teams and partners to extrapolate SIEM related data from source system logs such as security, application, system, and network logs to assess risks and help the GRC team determine compliance. Work with IT teams and partners to bridge technology between GRC goals and cybersecurity / technology solutions such as IAM, PAM, MFA, RBAC, SSO, DLP, IDS/IPD, XDR, MDM, SIEM, etc. Support data analysis and metrics by pulling data from source systems. Stay current with threat intelligence and make recommendation for improvements. Participate in security incidents as needed. Support security assessment requests for customers, HITRUST, SOC 2, etc. by pulling appropriate data as needed. Work with IT partners to integrate GRC value-add into their secured software development life cycle, software engineering, infrastructure, network, and operation needs. Maximize the utilization of Security tools and technology. Assist with the development of policies and procedures. Stay current with changes in information security and cybersecurity r