Назад
Company hidden
5 дней назад

Senior Governance & Risk Analyst

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Governance & Risk Analyst (Healthcare GRC): Building and maturing risk register, AI governance framework, TPRM, and HIPAA compliance programs with an accent on risk identification, control mapping, and regulatory alignment. Focus on establishing risk review cadences, assessing AI use cases, and supporting audits like SOC 2 and HITRUST.

Location: Hybrid - at least 3 days/week in Dallas, TX office (2100 Ross Avenue, Suite 1900)

Company

hirify.global is the specialty care platform connecting people with top specialists for surgery, cancer care, infusions and more, delivering excellent care with cost savings to employers and workforces nationwide.

What you will do

  • Build out risk register through workshops, taxonomy definition, ownership assignment, and likelihood/impact scoring
  • Map controls to NIST CSF, document gaps, and develop remediation roadmap
  • Establish recurring risk reviews with business owners and produce leadership reporting
  • Develop AI governance framework per NIST AI RMF, including model risk, bias, transparency, and inventory management
  • Monitor AI regulations and assess new use cases with Engineering and Product
  • Manage HIPAA compliance, gap assessments, training, and support SOC 2/HITRUST audits
  • Handle TPRM including vendor assessments and tiering

Requirements

  • Bachelor’s degree in Information Security, Healthcare Administration, Computer Science, or related
  • 5+ years in GRC, compliance, or information security
  • 3+ years in healthcare or health-tech
  • Hands-on experience building/maturing risk register, HITRUST/SOC 2 audits, HIPAA programs, NIST CSF/ISO 27001, NIST AI RMF or similar
  • Proficiency with GRC platforms (Vanta, Drata, ServiceNow GRC, OneTrust)
  • Knowledge of AI/ML risk and third-party risk tools

Nice to have

  • Certifications: CISA, CRISC, CISSP, CHC, CHPC, HITRUST CCSFP

Culture & Benefits

  • Embody LIGHT pillars: Logic, Inclusion, Grit, Humanity, Truth
  • Medical, Dental, Vision Insurance
  • Short & Long Term Disability, Life Insurance
  • 401k with company match
  • Flexible Time Off, Paid Parental Leave

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →