Senior Governance, Risk, Compliance (GRC) Analyst (Healthtech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Governance, Risk, Compliance (GRC) Analyst (Cybersecurity/Healthtech): Building and maturing a modern, AI-enabled security and compliance program for a mental healthcare platform with an accent on audit readiness, vendor risk management, and technical risk tracking. Focus on automating evidence collection for HITRUST, SOC 2, and HIPAA while embedding compliance into engineering workflows.
Location: Must be based in New York, San Francisco, or Seattle
Salary: $161,600 – $202,000
Company
is building a new mental healthcare system to make therapy accessible by automating insurance and administrative barriers for providers.
What you will do
- Support audit readiness for HITRUST, SOC 2, PCI-DSS, and HIPAA by collecting evidence and coordinating with assessors.
- Manage the vendor security assessment lifecycle, including questionnaires, risk scoring, and policy enforcement.
- Implement and operate a security awareness training program, including onboarding modules and phishing simulations.
- Operate the centralized risk register to identify, assess, and track technical security risks.
- Partner with Privacy, Legal, IT, and Engineering teams to integrate compliance into operational workflows.
Requirements
- 5+ years of experience in GRC, compliance, or security risk roles.
- Working knowledge of at least two frameworks: HITRUST, SOC 2, PCI-DSS, or HIPAA.
- Experience using GRC platforms such as Vanta, Drata, or OneTrust to automate controls.
- Ability to communicate complex compliance requirements to both technical and non-technical audiences.
- Must be based in one of the specified US locations (New York, San Francisco, or Seattle).
Nice to have
- Experience working in healthcare or healthtech with a practical understanding of HIPAA.
Culture & Benefits
- Competitive total rewards including base salary and equity grants.
- Comprehensive medical, dental, and vision coverage with HSA/FSA options.
- Retirement savings through a 401K plan.
- Practical perks including a work-from-home stipend and therapy reimbursement.
- Flexible PTO and 13 paid holidays, including a dedicated year-end holiday break.
- Family support via 16-week parental leave and Carrot Fertility membership.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →