IS Security GRC Platform Engineer - Remote
We've made a lot of progress since opening the doors in 1942, but one thing has never changed - our commitment to serve, heal, lead, educate, and innovate. We believe that every award earned, every record broken and every patient helped is because of the dedicated employees who fill our hallways.
At Ochsner, whether you work with patients every day or support those who do, you are making a difference and that matters. Come make a difference at Ochsner Health and discover your future today!
The Cybersecurity GRC Engineer supports Ochsner Health’s Cybersecurity Governance, Risk, and Compliance program by serving as a technical and functional resource for the organization’s GRC application, Onspring, and related GRC functions. This role is responsible for administering, maintaining, and improving Onspring workflows, forms, dashboards, reports, risk records, findings, control mappings, assessment processes, evidence repositories, security exception workflows, and user support activities.The Cybersecurity GRC Engineer supports integration and coordination between Onspring and related enterprise applications, reporting tools, workflow systems, and business processes. This position works closely with Information Services, Cybersecurity, Compliance, Privacy, Audit, Legal, third-party risk, and business stakeholders to support audit readiness, risk management, compliance tracking, remediation management, executive reporting, and continuous improvement of the Cybersecurity GRC program.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential duties.
This job description is a summary of the primary duties and responsibilities of the job and position. It is not intended to be a comprehensive or all-inclusive listing of duties and responsibilities. Contents are subject to change at the company's discretion.
Education
Required - High school diploma or equivalent.
Preferred - Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business Administration, Healthcare Administration or a related field.
Work Experience
Required - 2 years information technology experience with master’s degree;
OR
4 years information technology experience with bachelor’s degree;
OR
6 years information technology experience with associate’s degree;
OR
8 years of information technology experience.
Preferred – 5 to 10 years of related information technology, cybersecurity, governance, risk, compliance, audit, security operations, application administration, or platform administration experience in a regulated industry.
Preferred – Experience supporting cybersecurity GRC functions in healthcare, federal, government, commercial, or other highly regulated environments. Experience should include GRC platform administration, audit readiness, control assessments, evidence management, findings management, corrective action plans, remediation tracking, third-party risk management, policy and standards support, risk registers, security exception workflows, executive reporting, and compliance monitoring.
Preferred – Experience with GRC and workflow platforms such as Onspring, Archer, MetricStream, Xacta, CSAM, ServiceNow, JIRA, Confluence, Remedy, or similar platforms. Experience supporting workflow design, dashboard development, reporting, data quality, integrations, process documentation, and user enablement is preferred.
Knowledge Skills and Abilities (KSAs)
- Working knowledge of GRC platform administration, preferably Onspring, including workflow configuration, form design, dashboards, reporting, data quality management, user support, control mapping, risk tracking, findings management, evidence management, and integration with related enterprise applications.
- Experience with GRC platforms and related workflow tools such as Onspring, Archer, MetricStream, Xacta, CSAM, ServiceNow, JIRA, Confluence, Remedy, or similar systems.
- Strong knowledge of cybersecurity and compliance frameworks and standards, including NIST CSF, NIST RMF, NIST SP 800-53, NIST SP 800-171, HIPAA, ISO/IEC 27001, SOC 2, HITRUST, FedRAMP, FISMA, DFARS, PCI DSS, and CIS Controls.
- Experience supporting audit readiness, evidence collection, control testing, corrective action plans, POA&Ms, remediation tracking, executive reporting, and continuous monitoring activities.
- Ability to translate regulatory, audit, technical, and business requirements into repeatable GRC workflows, clear documentation, measurable control activities, and actionable reporting.
- Experience coordinating with auditors, vendors, technology teams, business owners, compliance teams, privacy teams, legal teams, and leadership to support timely evidence delivery, issue resolution, remediation tracking, and risk reporting.
- Ability to support third-party risk management activities, including vendor assessments, inherited risk reviews, control validation, remediation monitoring, and compliance documentation.
- Working knowledge of identity and access management, privileged access management, account lifecycle management, access certification reviews, authentication technologies, and related security controls within regulated environments.
- Strong verbal, written, diagrammatic, and executive communication skills, including the ability to prepare dashboards, metrics, summaries, process documentation, playbooks, templates, and leadership-level reporting.
- Strong organization, documentation, follow-through, analytical, and continuous service improvement skills with the ability to manage multiple priorities and maintain audit-ready records.
- Ability to work independently and as part of a cross-functional team in a fast-paced healthcare environment.
- Ability to work a flexible schedule, including occasional after-hours, weekends, holidays, on-call support, or urgent compliance and cybersecurity activities as required by business needs.
Job Duties
- Serves as a technical and functional administrator for the Cybersecurity GRC application, Onspring.
- Maintains and enhances Onspring workflows, forms, dashboards, reports, data fields, notifications, user access, control libraries, risk records, finding records, evidence repositories, and security exception processes.
- Supports integration and coordination between Onspring and related applications, workflow tools, reporting tools, ticketing platforms, and enterprise data sources.
- Designs, configures, tests, documents, and deploys new or enhanced GRC workflows to support cybersecurity risk management, compliance tracking, audit readiness, control assessments, third-party risk, remediation management, and executive reporting.
- Maintains cybersecurity framework mappings and control documentation aligned with NIST, HIPAA, ISO/IEC 27001, HITRUST, PCI DSS, SOC 2, FedRAMP, FISMA, DFARS, CIS Controls, and other applicable requirements.
- Supports audit readiness activities by coordinating evidence collection, validating control documentation, tracking findings, supporting corrective action plans, and monitoring remediation activities.
- Supports POA&M, corrective action, findings, issues, exceptions, and remediation tracking to ensure assigned actions are documented, monitored, escalated, and reported appropriately.
- Partners with Cybersecurity, Information Services, Audit, Compliance, Privacy, Legal, third-party risk, and business stakeholders to improve GRC processes and strengthen control visibility.
- Develops and maintains executive-level reports, dashboards, metrics, and status updates for risk posture, remediation progress, audit readiness, control performance, and GRC program health.
- Creates and maintains process documentation, workflow diagrams, job aids, templates, user guides, playbooks, and training materials for Onspring and related GRC processes.
- Coordinates with vendors or internal application teams to troubleshoot platform issues, evaluate enhancement requests, resolve workflow problems, and support platform improvements.
- Supports third-party risk management, policy and standard lifecycle activities, privileged access reviews, security exception management, audit response, compliance monitoring, and other Cybersecurity GRC program activities as assigned.
- Identifies continuous improvement opportunities to standardize data quality, improve workflow adherence, increase platform adoption, automate manual processes, and improve reporting reliability.
- Remains knowledgeable on current federal, state, and local laws, accreditation standards, regulatory agency requirements, cybersecurity practices, and GRC technology trends that apply to the assigned area of responsibility.
The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this description amended at any time.
The employer is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status.
Physical and Environmental Demands
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Light Work - Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly (Constantly: activity or condition exists 2/3 or more of the time) to move objects. Physical demand requirements are in excess of those for Sedentary Work. Even though the weight lifted may be only a negligible amount, a job should be rated.
Light Work: (1) when it requires walking or standing to a significant degree; or (2) when it requires sitting most of the time but entails pushing and/or pulling of arm or leg controls; and/or (3) when the job requires working at a production rate pace entailing the constant pushing and/or pulling of materials even though the weight of those materials is negligible.
NOTE: The constant stress and strain of maintaining a production rate pace, especially in an industrial setting, can be and is physically demanding of a worker even though the amount of force exerted is negligible.
Are you ready to make a difference? Apply Today!
Ochsner Health does not consider an individual an applicant until they have formally applied to the open position on this careers website.
Please refer to the job description to determine whether the position you are interested in is remote or on-site.Individuals who reside in and will work from the following areas are not eligible for remote work position: Colorado, California, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington, and Washington D.C.
Ochsner Health endeavors to make our site accessible to all users. If you would like to contact us regarding the accessibility of our website, or if you need an accommodation to complete the application process, please contact our HR Employee Solution Center at 504-842-4748 (select option 1) or careers@ochsner.org. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications.
Ochsner is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to any legally protected class, including protected veterans and individuals with disabilities.
Similar Listings
- Rehab Tech - OLG St. Martin Hospital Rehabilitation Services Breaux Bridge, Louisiana, United States
- LPN- BRACC Cancer Center- Full Time Licensed Practical Nurse (LPN) Lafayette, Louisiana, United States
- IS Security GRC Platform Engineer - Remote Information Systems New Orleans, Louisiana, United States