Smith+Nephew
InformationSecurityComplianceAnalyst
Neural analysis suggests this role is
optimal for Mid candidates.
“Information Security Compliance Analyst at Smith+Nephew. Skills: HIPAA Program, Security Compliance, Program Management. Manage annual program activities. Complete annual risk assessments”
What You'll Achieve.
Safeguarding patient data; Strengthening global compliance posture; Deliver the annual program; Maintain the highest standards of security and compliance
Industry & Context.
Sound judgement
Work from Office – 3 days in a week, UK Shift (12:30 PM IST to 9:30 PM IST)
What They're Looking For.
Must Have
5 years in Information Security, at least 3 years working on Security Compliance programs, At least 2 years in Program or Project Management, Prior experience in deploying and assessing Information Security controls is essential, Prior experience in Program or Project Management is essential
Nice to Have
Bachelor´s degree in Computer Science or related subject preferred, Privacy or Security certifications would be advantageous but are not essential, any HIPAA certification (CHPS, CHSE, CHPSE, CIPP/US), CISA, CISSP, ISO27001 or equivalent, Prior experience of Privacy Law related Security Controls compliance would be very well received, Prior experience using OneTrust, experience in IT Risk Management are optional
What You'll Do.
Manage annual program activities
Complete annual risk assessments
Maintain records in OneTrust
Deliver annual program
Plan program schedule
Manage execution against schedule
Organize stakeholders and external resources
Create and present materials
Organize cadences and report metrics
Plan and scope annual HIPAA Security Risk Assessment
Develop HIPAA SRA testing templates
Support execution of HIPAA SRA
Manage remedial actions from SRA
Perform HIPAA Security Assessments on IT Systems
Track remedial actions
Monitor HIPAA Law for changes
Propose changes to HIPAA Policy
Track and report HIPAA risks
Manage HIPAA records and workflow
How You'll Work.
Team & Collaboration
Work closely with Senior Director of Governance Risk and Compliance; Work with HIPAA Security Officer; Work with HIPAA Privacy Officer; Work with Head of Compliance; Organise stakeholders and external resources; Collaborate with leadership on SRA scope
Communication Scope
Clear communication; Presenting materials to SteerCo
Process & Methodology
Program Management, Project Management
Full Job Description
**Role: Information Security Compliance Analyst** **Location:** Kharadi, Pune **Life Unlimited.** At Smith+Nephew, we design and manufacture technology that takes the limits off living. Are you ready to play a key role in safeguarding patient data and strengthening our global compliance posture. We are looking for an experienced compliance analyst to run the company's annual HIPAA Program, reporting to the Senior Director Governance Risk & Compliance. HIPAA training will be provided for any candidates without direct experience. **What will you be doing?** * In this role you will be supported by the HIPAA Security Officer, HIPAA Privacy Officer and GRC Senior Director, who can provide guidance, additional direction and act as points of escalation HIPAA Program is owned by the Head of Compliance, with strategy directed by a cross-functional Steering Committee. * You will work closely with our Senior Director of Governance Risk and Compliance, the HIPAA Security Officer and the HIPAA Privacy Officer, as well as the Head of Compliance who owns the programme. * You will be managing activities and stakeholders to deliver the annual program. Managing annual program activities, competing annual risk assessments, assessing IT systems, maintaining records in OneTrust and reporting to Leadership. * Through clear communication, structured management and sound judgement, you will help maintain the highest standards of security and compliance across our systems and processes. **What will you need to be successful?** * Bachelor´s degree in Computer Science or related subject preferred. * Certifications: Privacy or Security certifications would be advantageous but are not essential e.g. any HIPAA certification (CHPS, CHSE, CHPSE, CIPP/US), CISA, CISSP, ISO27001 or equivalent. * Work from Office – 3 days in a week in UK Shift (12:30 PM IST to 9:30 PM IST) * Experience: 5 years in Information Security, at least 3 years working on working on Security Compliance programs. * At least 2
Applying for this Information Security Compliance Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about Smith+Nephew?
Real rants from real employees. Read before you apply.