Senior GRC Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior GRC Engineer (Cybersecurity): Managing risk by assessing operations against compliance frameworks and automating evidence collection with an accent on SOC 2, HIPAA, and HITRUST standards. Focus on building custom automation workflows, maintaining risk registers, and developing data-driven reporting to ensure continuous compliance acss a distributed healthcare platform.
Location:
Salary: $148,000–$175,000
Company
is a vertically integrated direct-to-patient healthcare company offering nationwide telehealth, labs, and pharmacy services.
What you will do
- Own and maintain the compliance platform including contl mapping and continuous monitoring
- Perform risk assessments and contl gap analyses acss multiple frameworks
- Partner with Security, IT, and Engineering teams to align contls with compliance requirements
- Support internal and external audits for SOC 2, HIPAA, and HITRUST
- Develop and maintain cyber risk reporting and executive metrics using BI tools
- Automate data ingestion and compliance workflows using scripting and APIs
Requirements
hirify.globalng>Must be based in the United States hirify.globalng>- 5+ years of experience in GRC, security engineering, or technical risk les
- Expertise in compliance frameworks such as SOC 2, HIPAA, HITRUST, NIST, and PCI
- 3+ years of experience with automated evidence collection and compliance operations
- 2+ years of hands-on experience administering platforms like Vanta, Drata, or SecureFrame
- Pficiency with BI tools like Looker or Hex for data visualization and reporting
- Experience with scripting (Python, JavaScript) to automate workflows
Culture & Benefits
- Comprehensive medical, dental, and vision insurance plus OneMedical membership
- 401(k) with company match
- Flexible PTO and paid parental leave
- Wellbeing, learning, and gwth reimbursements
- Student loan refinancing and pet insurance
- Virtual resources for mindfulness, counseling, and fitness
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →