Senior Governance & Risk Analyst
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Governance & Risk Analyst (Healthcare GRC): Building and maturing risk register, AI governance framework, TPRM, and HIPAA compliance programs with an accent on risk identification, control mapping, and regulatory alignment. Focus on establishing risk review cadences, assessing AI use cases, and supporting audits like SOC 2 and HITRUST.
Location: Hybrid - at least 3 days/week in Dallas, TX office (2100 Ross Avenue, Suite 1900)
Company
is the specialty care platform connecting people with top specialists for surgery, cancer care, infusions and more, delivering excellent care with cost savings to employers and workforces nationwide.
What you will do
- Build out risk register through workshops, taxonomy definition, ownership assignment, and likelihood/impact scoring
- Map controls to NIST CSF, document gaps, and develop remediation roadmap
- Establish recurring risk reviews with business owners and produce leadership reporting
- Develop AI governance framework per NIST AI RMF, including model risk, bias, transparency, and inventory management
- Monitor AI regulations and assess new use cases with Engineering and Product
- Manage HIPAA compliance, gap assessments, training, and support SOC 2/HITRUST audits
- Handle TPRM including vendor assessments and tiering
Requirements
- Bachelor’s degree in Information Security, Healthcare Administration, Computer Science, or related
- 5+ years in GRC, compliance, or information security
- 3+ years in healthcare or health-tech
- Hands-on experience building/maturing risk register, HITRUST/SOC 2 audits, HIPAA programs, NIST CSF/ISO 27001, NIST AI RMF or similar
- Proficiency with GRC platforms (Vanta, Drata, ServiceNow GRC, OneTrust)
- Knowledge of AI/ML risk and third-party risk tools
Nice to have
- Certifications: CISA, CRISC, CISSP, CHC, CHPC, HITRUST CCSFP
Culture & Benefits
- Embody LIGHT pillars: Logic, Inclusion, Grit, Humanity, Truth
- Medical, Dental, Vision Insurance
- Short & Long Term Disability, Life Insurance
- 401k with company match
- Flexible Time Off, Paid Parental Leave
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →