Skip to main contentA logo with &quat;the muse&quat; in dark blue text.

Analyst, IT Governance, Risk & Compliance

AT CVS Health
CVS Health

Analyst, IT Governance, Risk & Compliance

Hartford, CT

At CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care.As the nation's leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues - caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.Position SummaryAs an Analyst in the Governance, Risk, and Compliance (GRC) team within the Infrastructure Engineering organization, you will be focused on the success of audit, compliance and other GRC activities. The Infrastructure Engineering (IE) organization at CVS Health delivers public and private cloud capabilities to the enterprise.You will bring your knowledge of GRC principles and real-world application of those principles in an enterprise infrastructure ecosystem to help our colleagues confidently implement practices that comply with CVS GRC and security frameworks and standards. You will be responsible for analyzing GRC related data and coordinating remediation activities to maintain a secure and compliant IT environment.You will directly interact with members of engineering, enterprise GRC and Cloud Security teams, serving as a bridge and guide between intention and implementation. You will leverage your strong knowledge of public and private cloud and middleware platforms to implement GRC practices within a hybrid cloud technology ecosystem. Your excellent collaboration and communication skills and deep understanding of NIST and other cloud security frameworks will enable you to facilitate progress in strengthening our overall security posture. Your demonstrated bias for action coupled with a strong sense of ownership will drive progress on an aggressive timeline.Candidates will primarily work remotely or in a hybrid office model. This is a hands-on position that works across the Cloud and Platform Engineering teams. This role will lead some activities that may be outside of regular working hours.Responsibilities Include:

Want more jobs like this?

Get Computer and IT jobs in Hartford, CT delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.
  • Analyzing data from integrated risk management platforms for risk assessment, threat detection, compliance monitoring, and systems that enable the management of security posture, vulnerabilities, audits and policies
  • Assemble plans with timelines, resource assignments and milestones to remediate issues and risks on an enterprise-wide scale
  • Facilitate remediation efforts by assembling engineers, testers and other key contributors to complete the remediation activities
  • Lead audit evidence collection and serve as the central coordinator between the Engineering, Product, and CVS Audit teams
  • Ensure that all necessary audit evidence is collected, organized, and presented effectively, while minimizing disruptions to core engineering and product development activities
  • Assist application developers and infrastructure/cloud engineers in the implementation and remediation of technical solutions that meet specific GRC requirements
  • Collaborate with teams across the company (e.g., Network, Security, Operations) as needed to ensure compliance with required GRC frameworks
  • Collaborate closely with application development, engineering and other infrastructure teams to ensure compliance with frameworks as selected by enterprise GRC and Security teams
  • Educate and guide engineers and leaders across Cloud and Platform Engineering teams, providing information and advice on GRC activities, including rationale, recommended practices, and implementation strategies
  • Stay up-to-date with the latest developments in Cloud technology and broader technology trends and applicability to GRC responsibilities, sharing valuable insights with your team
  • Prepare reports for senior leaders to summarize GRC status and initiatives
Required Qualifications
  • 4+ years of experience with public & private cloud infrastructure and middleware
  • 4+ years of experience collaborating with enterprise-wide teams implementing GRC practices
  • 4+ years of experience facilitating the remediation of IT issues and risks
  • 2+ years of experience gathering evidence and forming audit responses in a regulated environment
Preferred Qualifications
  • Experience working in a highly regulated company
  • Excellent analytical and problem-solving skills
  • Strong organizational skills that enable you to assemble and execute viable plans
  • Experience working with integrated risk management platforms for risk assessment, threat detection, compliance monitoring, and systems that enable the management of security posture, vulnerabilities, audits and policies
  • Ability to influence and collaborate with stakeholders at all levels
  • Excellent communications skills and proven ability to communicate effectively with senior management and business leaders
  • Experience evaluating and recommending new solutions to meet enterprise GRC requirements
  • Demonstrated teamwork, positive attitude and good rapport with peers and customers
  • Ability to multitask in a fast paced and continually changing environment
Education
Bachelor's degree or equivalent experience (HS diploma + 4 years relevant experience) Anticipated Weekly Hours
40Time Type
Full timePay Range

The typical pay range for this role is:$101,970.00 - $203,940.00This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above.Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.Great benefits for great peopleWe take pride in our comprehensive and competitive mix of pay and benefits - investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:
  • Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan.
  • No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
  • Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.
For more information, visit https://jobs.cvshealth.com/us/en/benefitsWe anticipate the application window for this opening will close on: 08/31/2025Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.

Client-provided location(s): Hartford, CT, USA
Job ID: CVS-R0583664
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • HSA
    • HSA With Employer Contribution
    • Pet Insurance
    • Mental Health Benefits
  • Parental Benefits

    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
  • Work Flexibility

    • Flexible Work Hours
    • Remote Work Opportunities
    • Hybrid Work Opportunities
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
  • Financial and Retirement

    • 401(K) With Company Matching
  • Professional Development

    • Tuition Reimbursement
  • Diversity and Inclusion

    • Employee Resource Groups (ERG)
    • Diversity, Equity, and Inclusion Program