Назад
Company hidden
11 часов назад

Sr. Staff Risk Management Analyst (Cybersecurity)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Staff Risk Management Analyst (Cybersecurity): Building and operating an enterprise risk management and security GRC program for a telehealth company handling protected health information with an accent on risk registers, control frameworks, security portfolio governance, and executive reporting. Focus on running enterprise risk assessments, automating evidence and reporting workflows, and extending risk coverage across clinical, pharmacy, financial, and third-party domains.

Location: United States - Remote

Company

hirify.global is a pre-IPO telehealth company providing virtual care delivery and support solutions across all 50 states.

What you will do

  • Own and mature the enterprise risk register, risk appetite statement, ERM policy, and enterprise risk assessment methodology.
  • Run risk assessments, assign and monitor risk owners, and report enterprise risk posture to executives and the Enterprise Risk Committee.
  • Govern the security program portfolio, OKRs, dependencies, and multi-year risk-reduction roadmap.
  • Produce governance and risk-assessment evidence for SOC 2, HITRUST, HIPAA, NIST CSF 2.0, and related control frameworks.
  • Own the security awareness program and manage property and casualty insurance renewals, claims, certificates, audits, and customer contract requirements.
  • Extend second-line risk coverage across pharmacy, financial, clinical, and third-party risk, while automating register maintenance, assessment intake, evidence gathering, and reporting.

Requirements

  • 10+ years of experience in information security, risk management, or GRC.
  • Demonstrated ownership of a GRC or enterprise risk program, including registers, policies, and assessment methodology.
  • Hands-on experience with RCSA or comparable enterprise risk assessments, multi-year risk-reduction roadmaps, and executive or board-level risk reporting.
  • Experience working with SOC 2, HITRUST, HIPAA, NIST CSF, or comparable control frameworks.
  • Ability to hold owners across other teams accountable without direct authority.
  • Experience as the first full-time person dedicated to a function, operating without a team or dedicated budget.

Nice to have

  • CRISC, CISA, CISSP, or equivalent certification.
  • Healthcare experience involving sensitive data.
  • Agentic AI systems for governance intake, evidence gathering, or reporting.
  • Experience supporting SOC 2, HITRUST, or HIPAA assurance cycles.
  • Experience building a security awareness program or administering a GRC platform.

Culture & Benefits

  • Relatively flat organizational structure with autonomy to propose ideas and drive initiatives.
  • Medical, dental, and vision plans.
  • Flexible Spending Accounts and Health Savings Accounts.
  • Flexible paid time off.
  • 401(k) with company match, life insurance, pet insurance, and additional benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →