1 день назад
GRC/IT Compliance Analyst
108 000 - 130 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC/IT Compliance Analyst (Healthcare Security and Compliance): Building and operating enterprise risk, compliance, and control-monitoring processes for AI-driven medical software with an accent on GRC platforms, IT risk assessment, FDA submissions, and regulated product security. Focus on implementing risk workflows, evaluating internal controls, conducting access reviews, and aligning the software development lifecycle with ISO 27001, HITRUST, and SOC 2 requirements.
Location: Virtual US; the role is remote, with occasional travel for team meetings and cross-functional projects.
Base salary: $108,000–$130,000 annually. Total Target Compensation: $118,800–$143,000, plus stock options, paid benefits, and perks.
Company
is a healthcare technology company developing AI-driven precision diagnostic software to improve the diagnosis, treatment, and tracking of heart disease.
What you will do
- Build and implement an enterprise risk assessment platform to streamline compliance workflows.
- Monitor and update risk processes based on evolving threats and regulatory requirements.
- Perform risk analysis and support risk-focused feature development for regulated medical products.
- Evaluate internal controls, conduct user access reviews, and identify areas for improvement.
- Review policies and procedures against compliance frameworks and best practices.
- Draft and maintain documentation supporting FDA regulatory submissions.
Requirements
- 5–7 years of experience in security or compliance analysis, IT risk assessment, risk management, or IT/IS controls assurance.
- Bachelor’s degree in management information systems, computer science, accounting with ITGC experience, engineering, cybersecurity, biomedical engineering, or a related field.
- Experience implementing GRC software and applying enterprise risk management frameworks and qualitative or quantitative risk assessment methods.
- Experience with FDA regulatory submissions and Software as a Medical Device (SaMD) regulations.
- Strong understanding of internal controls and compliance frameworks including ISO 27001, HITRUST, and SOC 2.
- Experience with Agile/Scrum environments, security integration into the SDLC, and clear communication with internal stakeholders.
Nice to have
- CISA, CISM, CISSP, CRISC, or a related certification.
- Digital healthcare industry experience.
- Experience with open-source GRC tools such as CISO Advisor or Eramba.
- Previous startup experience.
Culture & Benefits
- Remote-first collaboration with access to offices in Denver, New York, Dallas, and Lisbon.
- Occasional travel for team meetings and cross-functional projects, typically monthly or quarterly.
- Annual target bonus and additional stock options, paid benefits, and employee perks.
- Values centered on humility, excellence, accountability, innovation, and teamwork.
- Equal-opportunity workplace committed to inclusion and workforce diversification.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Staff Security Engineer (GRC)
65 000 - 87 000€
2 дня назад
Governance, Risk & Compliance (GRC) Senior Analyst (Crypto Payments)
150 000 - 200 000$
5 дней назад
Senior GRC Manager (Cybersecurity)
2 дня назад
InfoSec Analyst II, Trust (AI Governance)
96 000 - 160 000$
4 дня назад
Senior Director of Information Risk & Governance (Healthcare)
231 300 - 272 100$
2 дня назад
Director, Cybersecurity (GRC)
148 000 - 267 840$