Назад
Company hidden
1 день назад

GRC/IT Compliance Analyst

108 000 - 130 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC/IT Compliance Analyst (Healthcare Security and Compliance): Building and operating enterprise risk, compliance, and control-monitoring processes for AI-driven medical software with an accent on GRC platforms, IT risk assessment, FDA submissions, and regulated product security. Focus on implementing risk workflows, evaluating internal controls, conducting access reviews, and aligning the software development lifecycle with ISO 27001, HITRUST, and SOC 2 requirements.

Location: Virtual US; the role is remote, with occasional travel for team meetings and cross-functional projects.

Base salary: $108,000–$130,000 annually. Total Target Compensation: $118,800–$143,000, plus stock options, paid benefits, and perks.

Company

hirify.global is a healthcare technology company developing AI-driven precision diagnostic software to improve the diagnosis, treatment, and tracking of heart disease.

What you will do

  • Build and implement an enterprise risk assessment platform to streamline compliance workflows.
  • Monitor and update risk processes based on evolving threats and regulatory requirements.
  • Perform risk analysis and support risk-focused feature development for regulated medical products.
  • Evaluate internal controls, conduct user access reviews, and identify areas for improvement.
  • Review policies and procedures against compliance frameworks and best practices.
  • Draft and maintain documentation supporting FDA regulatory submissions.

Requirements

  • 5–7 years of experience in security or compliance analysis, IT risk assessment, risk management, or IT/IS controls assurance.
  • Bachelor’s degree in management information systems, computer science, accounting with ITGC experience, engineering, cybersecurity, biomedical engineering, or a related field.
  • Experience implementing GRC software and applying enterprise risk management frameworks and qualitative or quantitative risk assessment methods.
  • Experience with FDA regulatory submissions and Software as a Medical Device (SaMD) regulations.
  • Strong understanding of internal controls and compliance frameworks including ISO 27001, HITRUST, and SOC 2.
  • Experience with Agile/Scrum environments, security integration into the SDLC, and clear communication with internal stakeholders.

Nice to have

  • CISA, CISM, CISSP, CRISC, or a related certification.
  • Digital healthcare industry experience.
  • Experience with open-source GRC tools such as CISO Advisor or Eramba.
  • Previous startup experience.

Culture & Benefits

  • Remote-first collaboration with access to offices in Denver, New York, Dallas, and Lisbon.
  • Occasional travel for team meetings and cross-functional projects, typically monthly or quarterly.
  • Annual target bonus and additional stock options, paid benefits, and employee perks.
  • Values centered on humility, excellence, accountability, innovation, and teamwork.
  • Equal-opportunity workplace committed to inclusion and workforce diversification.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →