Назад
Company hidden
4 дня назад

Lead Security Analyst - GRC (Cybersecurity)

172 500 - 215 625$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Analyst - GRC (Cybersecurity): Building and implementing scalable security controls, governance processes, and risk management practices across a healthcare technology organization with an accent on SOC 2, HITRUST, NIST, CIS, and HIPAA compliance. Focus on leading audits, coordinating third-party risk assessments, driving remediation, and communicating security program risks to technical and executive stakeholders.

Location: Hybrid, based in the Plano, Texas or Lehi, Utah office; two days per week in the office. San Francisco, California is also listed as a role location.

Salary: $172,500–$215,625 USD annually for the San Francisco, California pay range. Includes 205,000 stock options and benefits.

Company

hirify.global provides technology and services that help employers and their employees manage and engage with health benefits.

What you will do

  • Evaluate and implement security controls aligned with NIST, CIS, HIPAA, SOC 2, and HITRUST.
  • Develop and maintain security policies, procedures, control narratives, matrices, and the security risk registry.
  • Lead SOC 2 and HITRUST audits from planning through remediation and support internal and external audit activities.
  • Coordinate third-party risk assessments, compliance reviews, business continuity planning, and business impact assessments.
  • Track remediation plans, manage policy exceptions, and guide control and risk owners.
  • Respond to security questionnaires and compliance inquiries, deliver security awareness training, and report program status and risks to executives.

Requirements

  • 8+ years of experience in cybersecurity, GRC, audit, risk, or compliance.
  • Experience managing SOC 2 and HITRUST audits, particularly in cloud-native environments.
  • Strong knowledge of security frameworks and regulatory requirements.
  • Demonstrated experience with policy development, data management, and risk mitigation.
  • Familiarity with GRC tools and audit processes.
  • Excellent communication and cross-functional collaboration skills.

Nice to have

  • Background at a Big Four accounting firm.
  • Professional certification such as CISSP, CISA, CRISC, CISM, or similar.

Culture & Benefits

  • Mission-driven environment focused on innovation, collaboration, excellence, and healthcare.
  • Flexible work arrangements and support for work-life balance.
  • Health insurance, 401(k), paid time off, and stock options.
  • Professional development through internal mobility, mentorship, and interest-based courses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →