Senior GRC Analyst (Medtech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior GRC Analyst (Compliance): Managing and auditing security frameworks (ISO 27001, SOC 2, HITRUST, HIPAA) for a healthcare technology platform with an accent on internal audits, risk management, and regulatory compliance. Focus on automating GRC functions using AI/LLMs and scaling the control environment in a cloud-native infrastructure.
Location: Remote across the U.S. (For candidates in New York City, a hybrid schedule is required: Tuesday, Wednesday, and Thursday in-office)
Salary: $132,000 - $165,000
Company
is a healthcare technology company redesigning healthcare benefits using data-driven insights to improve care quality and affordability.
What you will do
- Manage and support compliance certifications, including SOC 2, HITRUST, and ISO 27001 audits.
- Serve as the primary point of contact for external auditors and as the internal subject matter expert on compliance frameworks.
- Maintain the risk register and drive risk identification, scoring, and reporting.
- Manage the Security and Privacy trust center, as well as compliance policies, standards, and procedures.
- Report on the overall compliance posture to senior leadership.
- Scale GRC functions through AI and automation, scoping requirements for Engineering to automate manual tasks.
Requirements
- 5+ years of experience in GRC, IT audit, or information security compliance.
- Prior experience with HITRUST, SOC 2, and ISO 27001 audits.
- Hands-on experience with control design, evidence collection, and remediation in cloud-native environments.
- Proven ability to communicate effectively with engineers, operators, and executives.
- Must be based in the U.S.
Nice to have
- Industry certifications such as CISA, CISM, CISSP, CRISC, or ISO 27001 Lead Auditor.
- Experience using scripting and LLMs to automate repetitive GRC tasks.
Culture & Benefits
- Equity incentive plans and competitive benefits.
- Flexible PTO and comprehensive Medical, Dental, and Vision insurance.
- 401(k) retirement plan and Teladoc Health access.
- High-performing, mission-driven environment with a commitment to authentic feedback and individual accountability.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →